← Back
CWE-79

46,318 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (46,318)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
3Canonical
DebianPython
3Debian Linux
PythonUbuntu Linux
Jun 17, 2026
Sep 28, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The documentation XML-RPC server in Python through 2.7.16, 3.x through 3.6.9, and 3.7.x through 3.7.4 has XSS via the server_title field. This occurs in Lib/DocXMLRPCServer.py in Python 2.x, and in Lib/xmlrpc/server.py i...Show more
The documentation XML-RPC server in Python through 2.7.16, 3.x through 3.6.9, and 3.7.x through 3.7.4 has XSS via the server_title field. This occurs in Lib/DocXMLRPCServer.py in Python 2.x, and in Lib/xmlrpc/server.py in Python 3.x. If set_server_title is called with untrusted input, arbitrary JavaScript can be delivered to clients that visit the http URL for this server.Show less
1Flower Project
1Flower
Jun 17, 2026
Sep 28, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Flower 0.9.3 has XSS via a crafted worker name. NOTE: The project author stated that he doesn't think this is a valid vulnerability. Worker name and task name aren’t user facing configuration options. They are internal b...Show more
Flower 0.9.3 has XSS via a crafted worker name. NOTE: The project author stated that he doesn't think this is a valid vulnerability. Worker name and task name aren’t user facing configuration options. They are internal backend config options and person having rights to change them already has full accessShow less
1Flower Project
1Flower
Jun 17, 2026
Sep 28, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Flower 0.9.3 has XSS via the name parameter in an @app.task call. NOTE: The project author stated that he doesn't think this is a valid vulnerability. Worker name and task name aren’t user facing configuration options. T...Show more
Flower 0.9.3 has XSS via the name parameter in an @app.task call. NOTE: The project author stated that he doesn't think this is a valid vulnerability. Worker name and task name aren’t user facing configuration options. They are internal backend config options and person having rights to change them already has full accessShow less
1Dell
1Emc Integrated Data Protection Appliance Firmware
Jun 17, 2026
Sep 27, 2019
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Dell EMC Integrated Data Protection Appliance versions prior to 2.3 contain a stored cross-site scripting vulnerability. A remote malicious ACM admin user may potentially exploit this vulnerability to store malicious HTM...Show more
Dell EMC Integrated Data Protection Appliance versions prior to 2.3 contain a stored cross-site scripting vulnerability. A remote malicious ACM admin user may potentially exploit this vulnerability to store malicious HTML or JavaScript code in Cloud DR add-on specific field. When victim users access the page through their browsers, the malicious code gets executed by the web browser in the context of the vulnerable web application.Show less
1Dolibarr
1Dolibarr Erp/crm
Jun 17, 2026
Sep 27, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Dolibarr 9.0.5 has stored XSS in an Email Template section to mails_templates.php. A user with no privileges can inject script to attack the admin. (This stored XSS can affect all types of user privilege from Admin to us...Show more
Dolibarr 9.0.5 has stored XSS in an Email Template section to mails_templates.php. A user with no privileges can inject script to attack the admin. (This stored XSS can affect all types of user privilege from Admin to users with no permissions.)Show less
1Dolibarr
1Dolibarr Erp/crm
Jun 17, 2026
Sep 27, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Dolibarr 9.0.5 has stored XSS in a User Profile in a Signature section to card.php. A user with the "Create/modify other users, groups and permissions" privilege can inject script and can also achieve privilege escalatio...Show more
Dolibarr 9.0.5 has stored XSS in a User Profile in a Signature section to card.php. A user with the "Create/modify other users, groups and permissions" privilege can inject script and can also achieve privilege escalation.Show less
1Dolibarr
1Dolibarr Erp/crm
Jun 17, 2026
Sep 27, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Dolibarr 9.0.5 has stored XSS in a User Note section to note.php. A user with no privileges can inject script to attack the admin.
1Dolibarr
1Dolibarr Erp/crm
Jun 17, 2026
Sep 27, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Dolibarr 9.0.5 has stored XSS vulnerability via a User Group Description section to card.php. A user with the "Create/modify other users, groups and permissions" privilege can inject script and can also achieve privilege...Show more
Dolibarr 9.0.5 has stored XSS vulnerability via a User Group Description section to card.php. A user with the "Create/modify other users, groups and permissions" privilege can inject script and can also achieve privilege escalation.Show less
1Mozilla
2Firefox
Thunderbird
Jun 17, 2026
Sep 27, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Some HTML elements, such as <title> and <textarea>, can contain literal angle brackets without treating them as markup. It is possible to pass a literal closing tag to .innerHTML on these elements, and subseq...Show more
Some HTML elements, such as &lt;title&gt; and &lt;textarea&gt;, can contain literal angle brackets without treating them as markup. It is possible to pass a literal closing tag to .innerHTML on these elements, and subsequent content after that will be parsed as if it were outside the tag. This can lead to XSS if a site does not filter user input as strictly for these elements as it does for other elements. This vulnerability affects Firefox < 69, Thunderbird < 68.1, Thunderbird < 60.9, Firefox ESR < 60.9, and Firefox ESR < 68.1.Show less
1Mozilla
1Firefox
Jun 17, 2026
Sep 27, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A compromised sandboxed content process can perform a Universal Cross-site Scripting (UXSS) attack on content from any site it can cause to be loaded in the same process. Because addons.mozilla.org and accounts.firefox.c...Show more
A compromised sandboxed content process can perform a Universal Cross-site Scripting (UXSS) attack on content from any site it can cause to be loaded in the same process. Because addons.mozilla.org and accounts.firefox.com have close ties to the Firefox product, malicious manipulation of these sites within the browser can potentially be used to modify a user's Firefox configuration. These two sites will now be isolated into their own process and not allowed to be loaded in a standard content process. This vulnerability affects Firefox < 69.Show less
1Kkcms Project
1Kkcms
Jun 17, 2026
Sep 27, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
kkcms 1.3 has jx.php?url= XSS.
1Phpbb
1Phpbb
Jun 17, 2026
Sep 27, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
phpBB version 3.2.7 allows the stealing of an Administration Control Panel session id by leveraging CSRF in the Remote Avatar feature. The CSRF Token Hijacking leads to stored XSS
1Dnnsoftware
1Dotnetnuke
Jun 17, 2026
Sep 26, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Stored Cross-Site Scripting in DotNetNuke (DNN) Version before 9.4.0 allows remote attackers to store and embed the malicious script into the admin notification page. The exploit could be used to perfom any action with a...Show more
Stored Cross-Site Scripting in DotNetNuke (DNN) Version before 9.4.0 allows remote attackers to store and embed the malicious script into the admin notification page. The exploit could be used to perfom any action with admin privileges such as managing content, adding users, uploading backdoors to the server, etc. Successful exploitation occurs when an admin user visits a notification page with stored cross-site scripting.Show less
1Netgate
1Pfsense
Jun 17, 2026
Sep 26, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An XSS issue was discovered in pfSense through 2.4.4-p3. In services_captiveportal_mac.php, the username and delmac parameters are displayed without sanitization.
1Status301
1Easy Fancybox
Jun 17, 2026
Sep 26, 2019
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The easy-fancybox plugin before 1.8.18 for WordPress (aka Easy FancyBox) is susceptible to Stored XSS in the Settings Menu inc/class-easyfancybox.php due to improper encoding of arbitrarily submitted settings parameters....Show more
The easy-fancybox plugin before 1.8.18 for WordPress (aka Easy FancyBox) is susceptible to Stored XSS in the Settings Menu inc/class-easyfancybox.php due to improper encoding of arbitrarily submitted settings parameters. This occurs because there is no inline styles output filter.Show less
8Apache
CanonicalDebian+5 more
10Clustered Data Ontap
Communications Element ManagerDebian Linux+7 more
Jun 17, 2026
Sep 26, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In Apache HTTP Server 2.4.0-2.4.39, a limited cross-site scripting issue was reported affecting the mod_proxy error page. An attacker could cause the link on the error page to be malformed and instead point to a page of...Show more
In Apache HTTP Server 2.4.0-2.4.39, a limited cross-site scripting issue was reported affecting the mod_proxy error page. An attacker could cause the link on the error page to be malformed and instead point to a page of their choice. This would only be exploitable where a server was set up with proxying enabled but was misconfigured in such a way that the Proxy Error page was displayed.Show less
1Teampass
1Teampass
Jun 17, 2026
Sep 26, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
TeamPass 2.1.27.36 allows Stored XSS by setting a crafted password for an item in a common available folder or sharing the item with an admin. (The crafted password is exploitable when viewing the change history of the i...Show more
TeamPass 2.1.27.36 allows Stored XSS by setting a crafted password for an item in a common available folder or sharing the item with an admin. (The crafted password is exploitable when viewing the change history of the item or tapping on the item.)Show less
1Silverstripe
1Silverstripe
Jun 17, 2026
Sep 26, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
In SilverStripe asset-admin 4.0, there is XSS in file titles managed through the CMS.
1Altosresearch
1Altos Connect
Nov 21, 2024
Sep 26, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The altos-connect plugin 1.3.0 for WordPress has XSS via the wp-content/plugins/altos-connect/jquery-validate/demo/demo/captcha/index.php/ PATH_SELF.
1Addthis
1Addthis
Nov 21, 2024
Sep 26, 2019
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The addthis plugin before 5.0.13 for WordPress has CSRF with resultant XSS via the wp-admin/options-general.php?page=addthis_social_widget pubid parameter.