← Back
CWE-79

46,318 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (46,318)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Momizat
1Goodnews
Nov 21, 2024
Sep 20, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Goodnews theme through 2016-02-28 for WordPress has XSS via the s parameter.
1Ocimscripts
1Ocim Mp3
Nov 21, 2024
Sep 20, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The ocim-mp3 plugin through 2016-03-07 for WordPress has wp-content/plugins/ocim-mp3/source/pages.php?id= XSS.
1Ostenta
1Yawpp
Nov 21, 2024
Sep 20, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The yawpp plugin through 1.2.2 for WordPress has XSS via the field1 parameter.
1Mtouch Quiz Project
1Mtouch Quiz
Nov 21, 2024
Sep 20, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The mtouch-quiz plugin before 3.1.3 for WordPress has XSS via a quiz name.
1Mtouch Quiz Project
1Mtouch Quiz
Nov 21, 2024
Sep 20, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The mtouch-quiz plugin before 3.1.3 for WordPress has XSS via the quiz parameter during a Quiz Manage operation.
1Bestwebsoft
1Quotes And Tips
Nov 21, 2024
Sep 20, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The quotes-and-tips plugin before 1.20 for WordPress has XSS.
1Bestwebsoft
1Relevant
Nov 21, 2024
Sep 20, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The relevant plugin before 1.0.8 for WordPress has XSS.
1Prise
1Adas
Jun 17, 2026
Sep 20, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in PRiSE adAS 1.7.0. The newentityID parameter is not properly escaped, leading to a reflected XSS in the error message.
1Prise
1Adas
Jun 17, 2026
Sep 20, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in PRiSE adAS 1.7.0. Certificate data are not properly escaped. This leads to XSS when submitting a rogue certificate.
1Prise
1Adas
Jun 17, 2026
Sep 20, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
An issue was discovered in PRiSE adAS 1.7.0. Log data are not properly escaped, leading to persistent XSS in the administration panel.
1Prise
1Adas
Jun 17, 2026
Sep 20, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in PRiSE adAS 1.7.0. The OPENSSO module does not properly escape output on error, leading to reflected XSS.
1Checklist
1Checklist
Jun 17, 2026
Sep 19, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An XSS issue was discovered in the checklist plugin before 1.1.9 for WordPress. The fill parameter is not correctly filtered in the checklist-icon.php file, and it is possible to inject JavaScript code.
1Zulip
1Zulip Server
Jun 17, 2026
Sep 18, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Zulip server before 2.0.5 incompletely validated the MIME types of uploaded files. A user who is logged into the server could upload files of certain types to mount a stored cross-site scripting attack on other logged-in...Show more
Zulip server before 2.0.5 incompletely validated the MIME types of uploaded files. A user who is logged into the server could upload files of certain types to mount a stored cross-site scripting attack on other logged-in users. On a Zulip server using the default local uploads backend, the attack is only effective against browsers lacking support for Content-Security-Policy such as Internet Explorer 11. On a Zulip server using the S3 uploads backend, the attack is confined to the origin of the configured S3 uploads hostname and cannot reach the Zulip server itself.Show less
1Truemag Theme Project
1Truemag Theme
Nov 21, 2024
Sep 18, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Truemag theme 2016 Q2 for WordPress has XSS via the s parameter.
3Canonical
DebianSpip
3Debian Linux
SpipUbuntu Linux
Jun 17, 2026
Sep 17, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
SPIP before 3.1.11 and 3.2 before 3.2.5 allows prive/formulaires/login.php XSS via error messages.
1Schneider Electric
4Meg6260 0410 Firmware
Meg6260 0415 FirmwareMeg6501 0001 Firmware+1 more
Jun 17, 2026
Sep 17, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A Cross-Site Scripting (XSS) CWE-79 vulnerability exists in U.motion Server (MEG6501-0001 - U.motion KNX server, MEG6501-0002 - U.motion KNX Server Plus, MEG6260-0410 - U.motion KNX Server Plus, Touch 10, MEG6260-0415 -...Show more
A Cross-Site Scripting (XSS) CWE-79 vulnerability exists in U.motion Server (MEG6501-0001 - U.motion KNX server, MEG6501-0002 - U.motion KNX Server Plus, MEG6260-0410 - U.motion KNX Server Plus, Touch 10, MEG6260-0415 - U.motion KNX Server Plus, Touch 15), which could allow an attacker to inject client-side script when a user visits a web page.Show less
1Codesys
1Codesys
Jun 17, 2026
Sep 17, 2019
N/A· v4
8.6 HIGH· v3
6.8 MEDIUM· v2
3S-Smart Software Solutions GmbH CODESYS V3 Library Manager, all versions prior to 3.5.16.0, allows the system to display active library content without checking its validity, which may allow the contents of manipulated...Show more
3S-Smart Software Solutions GmbH CODESYS V3 Library Manager, all versions prior to 3.5.16.0, allows the system to display active library content without checking its validity, which may allow the contents of manipulated libraries to be displayed or executed. The issue also exists for source libraries, but 3S-Smart Software Solutions GmbH strongly recommends distributing compiled libraries only.Show less
2Ibm
Netapp
2Cognos Analytics
Oncommand Insight
Jun 17, 2026
Sep 17, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM Cognos Analytics 11.0 and 11.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to c...Show more
IBM Cognos Analytics 11.0 and 11.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 161421.Show less
1Ibm
1Websphere Application Server
Jun 17, 2026
Sep 17, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 Admin Console is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended fun...Show more
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 Admin Console is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 160203.Show less
1Hrworks
1Hrworks
Jun 17, 2026
Sep 17, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A reflected Cross-site scripting (XSS) vulnerability in HRworks V 1.16.1 allows remote attackers to inject arbitrary web script or HTML via the URL parameter to the Login component.