CWE-79
46,318 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (46,318)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Sap 1Businessobjects Business Intelligence Platform Jun 17, 2026 Oct 8, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface), before version 4.2, does not sufficiently encode user-controlled inputs and allows an attacker to store malicious scripts in the file...Show more |
1Sap 1Businessobjects Business Intelligence Platform Jun 17, 2026 Oct 8, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface), before versions 4.2, does not sufficiently encode user-controlled inputs and allows an attacker to store malicious scripts in the inpu...Show more |
1Sap 1Businessobjects Business Intelligence Platform Jun 17, 2026 Oct 8, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface), before versions 4.2 and 4.3, does not sufficiently encode user-controlled inputs and allows an attacker to save malicious scripts in t...Show more |
1Sap 1Businessobjects Business Intelligence Platform Jun 17, 2026 Oct 8, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface), before versions 4.2 and 4.3, does not sufficiently encode user-controlled inputs and allows execution of scripts in the export dialog...Show more |
1Sap 1Businessobjects Business Intelligence Platform Jun 17, 2026 Oct 8, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface), before versions 4.2 and 4.3, does not sufficiently encode user-controlled inputs and allows execution of scripts in the chart title re...Show more |
SAP Financial Consolidation, before versions 10.0 and 10.1, does not sufficiently encode user-controlled inputs, which allows an attacker to execute scripts by uploading files containing malicious scripts, leading to ref...Show more |
1Sap 2Customer Relationship Management Bbpcrm Customer Relationship Management S4crmJun 17, 2026 Oct 8, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 SAP Customer Relationship Management (Email Management), versions: S4CRM before 1.0 and 2.0, BBPCRM before 7.0, 7.01, 7.02, 7.12, 7.13 and 7.14, does not sufficiently encode user-controlled inputs within the mail client...Show more |
It is possible to inject JavaScript within node-red-dashboard versions prior to version 2.17.0 due to the ui_notification node accepting raw HTML by default. |
1Bootstrap 3 Typeahead Project 1Bootstrap 3 Typeahead Jun 17, 2026 Oct 8, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Bootstrap-3-Typeahead after version 4.0.2 is vulnerable to a cross-site scripting flaw in the highlighter() function. An attacker could exploit this via user interaction to execute code in the user's browser. |
Local file inclusion in brokerPerformance.php in Centreon Web before 2.8.28 allows attackers to disclose information or perform a stored XSS attack on a user. |
HRworks FLOW 3.36.9 allows XSS via the purpose of a travel-expense report. |
HRworks 3.36.9 allows XSS via the purpose of a travel-expense report. |
1Etoilewebdesign 1Ultimate Faq Jun 17, 2026 Oct 7, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Functions/EWD_UFAQ_Import.php in the ultimate-faqs plugin through 1.8.24 for WordPress allows HTML content injection. |
1Wpfactory 1Download Plugins And Themes From Dashboard Jun 17, 2026 Oct 7, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 includes/settings/class-alg-download-plugins-settings.php in the download-plugins-dashboard plugin through 1.5.0 for WordPress has multiple unauthenticated stored XSS issues. |
The broken-link-manager plugin before 0.6.0 for WordPress has XSS via the HTTP Referer or User-Agent header to a URL that does not exist. |
A Cross-Site Scripting (XSS) vulnerability in the blog function in SITOS six Build v6.2.1 allows remote attackers to inject arbitrary web script or HTML via the id parameter. |
1Elementor 1Elementor Page Builder Nov 21, 2024 Oct 7, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The elementor-edit-template class in wp-admin/customize.php in the Elementor Pro plugin before 2.0.10 for WordPress has XSS. |
CMS Made Simple (CMSMS) 2.2.11 allows XSS via the Site Admin > Module Manager > Search Term field. |
Subrion 4.2.1 allows XSS via the panel/members/ Username, Full Name, or Email field, aka an "Admin Member JSON Update" issue. |
The WebARX plugin 1.3.0 for WordPress allows firewall bypass by appending &cc=1 to a URI. |