← Back
CWE-79

46,318 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (46,318)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Sap
1Businessobjects Business Intelligence Platform
Jun 17, 2026
Oct 8, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface), before version 4.2, does not sufficiently encode user-controlled inputs and allows an attacker to store malicious scripts in the file...Show more
SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface), before version 4.2, does not sufficiently encode user-controlled inputs and allows an attacker to store malicious scripts in the file name of the background image resulting in Stored Cross-Site Scripting.Show less
1Sap
1Businessobjects Business Intelligence Platform
Jun 17, 2026
Oct 8, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface), before versions 4.2, does not sufficiently encode user-controlled inputs and allows an attacker to store malicious scripts in the inpu...Show more
SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface), before versions 4.2, does not sufficiently encode user-controlled inputs and allows an attacker to store malicious scripts in the input controls, resulting in Stored Cross-Site Scripting.Show less
1Sap
1Businessobjects Business Intelligence Platform
Jun 17, 2026
Oct 8, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface), before versions 4.2 and 4.3, does not sufficiently encode user-controlled inputs and allows an attacker to save malicious scripts in t...Show more
SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface), before versions 4.2 and 4.3, does not sufficiently encode user-controlled inputs and allows an attacker to save malicious scripts in the publication name, which can be executed later by the victim, resulting in Stored Cross-Site Scripting.Show less
1Sap
1Businessobjects Business Intelligence Platform
Jun 17, 2026
Oct 8, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface), before versions 4.2 and 4.3, does not sufficiently encode user-controlled inputs and allows execution of scripts in the export dialog...Show more
SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface), before versions 4.2 and 4.3, does not sufficiently encode user-controlled inputs and allows execution of scripts in the export dialog box of the report name resulting in reflected Cross-Site Scripting.Show less
1Sap
1Businessobjects Business Intelligence Platform
Jun 17, 2026
Oct 8, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface), before versions 4.2 and 4.3, does not sufficiently encode user-controlled inputs and allows execution of scripts in the chart title re...Show more
SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface), before versions 4.2 and 4.3, does not sufficiently encode user-controlled inputs and allows execution of scripts in the chart title resulting in reflected Cross-Site ScriptingShow less
1Sap
1Financial Consolidation
Jun 17, 2026
Oct 8, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
SAP Financial Consolidation, before versions 10.0 and 10.1, does not sufficiently encode user-controlled inputs, which allows an attacker to execute scripts by uploading files containing malicious scripts, leading to ref...Show more
SAP Financial Consolidation, before versions 10.0 and 10.1, does not sufficiently encode user-controlled inputs, which allows an attacker to execute scripts by uploading files containing malicious scripts, leading to reflected cross site scripting vulnerability.Show less
1Sap
2Customer Relationship Management Bbpcrm
Customer Relationship Management S4crm
Jun 17, 2026
Oct 8, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
SAP Customer Relationship Management (Email Management), versions: S4CRM before 1.0 and 2.0, BBPCRM before 7.0, 7.01, 7.02, 7.12, 7.13 and 7.14, does not sufficiently encode user-controlled inputs within the mail client...Show more
SAP Customer Relationship Management (Email Management), versions: S4CRM before 1.0 and 2.0, BBPCRM before 7.0, 7.01, 7.02, 7.12, 7.13 and 7.14, does not sufficiently encode user-controlled inputs within the mail client resulting in Cross-Site Scripting vulnerability.Show less
1Nodered
1Node Red Dashboard
Jun 17, 2026
Oct 8, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
It is possible to inject JavaScript within node-red-dashboard versions prior to version 2.17.0 due to the ui_notification node accepting raw HTML by default.
1Bootstrap 3 Typeahead Project
1Bootstrap 3 Typeahead
Jun 17, 2026
Oct 8, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Bootstrap-3-Typeahead after version 4.0.2 is vulnerable to a cross-site scripting flaw in the highlighter() function. An attacker could exploit this via user interaction to execute code in the user's browser.
1Centreon
1Centreon Web
Jun 17, 2026
Oct 8, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Local file inclusion in brokerPerformance.php in Centreon Web before 2.8.28 allows attackers to disclose information or perform a stored XSS attack on a user.
1Hrworks
1Hrworks
Jun 17, 2026
Oct 8, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
HRworks FLOW 3.36.9 allows XSS via the purpose of a travel-expense report.
1Hrworks
1Hrworks
Jun 17, 2026
Oct 8, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
HRworks 3.36.9 allows XSS via the purpose of a travel-expense report.
1Etoilewebdesign
1Ultimate Faq
Jun 17, 2026
Oct 7, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Functions/EWD_UFAQ_Import.php in the ultimate-faqs plugin through 1.8.24 for WordPress allows HTML content injection.
1Wpfactory
1Download Plugins And Themes From Dashboard
Jun 17, 2026
Oct 7, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
includes/settings/class-alg-download-plugins-settings.php in the download-plugins-dashboard plugin through 1.5.0 for WordPress has multiple unauthenticated stored XSS issues.
1K 78
1Broken Link Manager
Nov 21, 2024
Oct 7, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The broken-link-manager plugin before 0.6.0 for WordPress has XSS via the HTTP Referer or User-Agent header to a URL that does not exist.
1Sitos
1Sitos Six
Jun 17, 2026
Oct 7, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A Cross-Site Scripting (XSS) vulnerability in the blog function in SITOS six Build v6.2.1 allows remote attackers to inject arbitrary web script or HTML via the id parameter.
1Elementor
1Elementor Page Builder
Nov 21, 2024
Oct 7, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The elementor-edit-template class in wp-admin/customize.php in the Elementor Pro plugin before 2.0.10 for WordPress has XSS.
1Cmsmadesimple
1Cms Made Simple
Jun 17, 2026
Oct 6, 2019
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
CMS Made Simple (CMSMS) 2.2.11 allows XSS via the Site Admin > Module Manager > Search Term field.
1Intelliants
1Subrion
Jun 17, 2026
Oct 6, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Subrion 4.2.1 allows XSS via the panel/members/ Username, Full Name, or Email field, aka an "Admin Member JSON Update" issue.
1Webarxsecurity
1Webarx
Jun 17, 2026
Oct 6, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The WebARX plugin 1.3.0 for WordPress allows firewall bypass by appending &cc=1 to a URI.