← Back
CWE-79

46,318 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (46,318)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Eclipse
Oracle
23Application Testing Suite
Banking Enterprise Product ManufacturingCommunications Diameter Signaling Router+20 more
Jun 17, 2026
Oct 2, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
faces/context/PartialViewContextImpl.java in Eclipse Mojarra, as used in Mojarra for Eclipse EE4J before 2.3.10 and Mojarra JavaServer Faces before 2.2.20, allows Reflected XSS because a client window field is mishandled...Show more
faces/context/PartialViewContextImpl.java in Eclipse Mojarra, as used in Mojarra for Eclipse EE4J before 2.3.10 and Mojarra JavaServer Faces before 2.2.20, allows Reflected XSS because a client window field is mishandled.Show less
1Online Store System Project
1Online Store System
Jun 17, 2026
Oct 1, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Vulnerability in Online Store v1.0, The registration form requirements for the member email format can be bypassed by posting directly to sent_register.php allowing special characters to be included and an XSS payload to...Show more
Vulnerability in Online Store v1.0, The registration form requirements for the member email format can be bypassed by posting directly to sent_register.php allowing special characters to be included and an XSS payload to be injected.Show less
1Online Store System Project
1Online Store System
Jun 17, 2026
Oct 1, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Vulnerability in Online Store v1.0, stored XSS in admin/user_view.php adidas_member_email variable
1Online Store System Project
1Online Store System
Jun 17, 2026
Oct 1, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Vulnerability in Online Store v1.0, Stored XSS in user_view.php where adidas_member_user variable is not sanitized.
1Xunruicms
1Xunruicms
Jun 17, 2026
Oct 1, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
An issue was discovered in XunRuiCMS 4.3.1. There is a stored XSS in the module_category area.
1Jetbrains
1Upsource
Jun 17, 2026
Oct 1, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
JetBrains Upsource before 2019.1.1412 was not properly escaping HTML tags in a code block comments, leading to XSS.
1Jetbrains
1Youtrack
Jun 17, 2026
Oct 1, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
JetBrains YouTrack versions before 2019.2.53938 had a possible XSS through issue attachments when using the Firefox browser.
1Ibm
1Jazz Reporting Service
Jun 17, 2026
Oct 1, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM Jazz Reporting Service (JRS) 6.0, 6.0.1, 6.0.2, 6.0.3, 6.0.4, 6.0.5, 6.0.6, and 6.0.6.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus alt...Show more
IBM Jazz Reporting Service (JRS) 6.0, 6.0.1, 6.0.2, 6.0.3, 6.0.4, 6.0.5, 6.0.6, and 6.0.6.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 164118.Show less
1Ibm
1Jazz Reporting Service
Jun 17, 2026
Oct 1, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM Jazz Reporting Service (JRS) 6.0, 6.0.1, 6.0.2, 6.0.3, 6.0.4, 6.0.5, 6.0.6, and 6.0.6.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus alt...Show more
IBM Jazz Reporting Service (JRS) 6.0, 6.0.1, 6.0.2, 6.0.3, 6.0.4, 6.0.5, 6.0.6, and 6.0.6.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 164116.Show less
1Ibm
1Jazz Reporting Service
Jun 17, 2026
Oct 1, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM Jazz Reporting Service (JRS) 6.0, 6.0.1, 6.0.2, 6.0.3, 6.0.4, 6.0.5, 6.0.6, and 6.0.6.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus alt...Show more
IBM Jazz Reporting Service (JRS) 6.0, 6.0.1, 6.0.2, 6.0.3, 6.0.4, 6.0.5, 6.0.6, and 6.0.6.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 164115.Show less
1Jetbrains
1Youtrack
Jun 17, 2026
Oct 1, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
JetBrains YouTrack versions before 2019.1.52584 had a possible XSS in the issue titles.
1Jenkins
1Html Publisher
Jun 17, 2026
Oct 1, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Jenkins HTML Publisher Plugin 1.20 and earlier did not escape the project and build display names in the HTML report frame, resulting in a cross-site scripting vulnerability exploitable by users able to change those.
1Netdisco
1Netdisco
Jun 17, 2026
Sep 30, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Insufficient sanitization during device search in Netdisco 2.042010 allows for reflected XSS via manipulation of a URL parameter.
1Ibm
1Websphere Extreme Scale
Jun 17, 2026
Sep 30, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM WebSphere eXtreme Scale 8.6 Admin API is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leadi...Show more
IBM WebSphere eXtreme Scale 8.6 Admin API is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 158113.Show less
1Ibm
1Websphere Extreme Scale
Jun 17, 2026
Sep 30, 2019
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
IBM WebSphere eXtreme Scale 8.6 Admin Console is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially l...Show more
IBM WebSphere eXtreme Scale 8.6 Admin Console is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 158099.Show less
1Xoops
1Xoops
Jun 17, 2026
Sep 30, 2019
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
An issue was discovered in the image-manager in Xoops 2.5.10. When any image with a JavaScript payload as its name is hovered over in the list or in the Edit page, the payload executes.
1Xoops
1Xoops
Jun 17, 2026
Sep 30, 2019
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
An issue was discovered in the image-manager in Xoops 2.5.10. When the breadcrumb showing the category name is hovered over while editing any image, a JavaScript payload executes.
1Ilch
1Ilch Cms
Jun 17, 2026
Sep 30, 2019
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Ilch 2.1.22 allows stored XSS via the title, text, or email id to the Jobs Tab.
1Gfi
1Kerio Control
Jun 17, 2026
Sep 30, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A DOM based XSS in GFI Kerio Control v9.3.0 allows embedding of malicious code and manipulating the login page to send back a victim's cleartext credentials to an attacker via a login/?reason=failure&NTLM= URI.
1Salesagility
1Suitecrm
Jun 17, 2026
Sep 30, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
SuiteCRM 7.10.x and 7.11.x before 7.10.20 and 7.11.8 has XSS.