← Back
CWE-79

46,312 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (46,312)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Cybozu
1Garoon
Jun 17, 2026
Sep 12, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
DOM-based cross-site scripting vulnerability in Cybozu Garoon 4.6.0 to 4.10.2 allows remote authenticated attackers to inject arbitrary web script or HTML via unspecified vectors.
1Mcafee
1Web Gateway
Jun 17, 2026
Sep 12, 2019
N/A· v4
9.6 CRITICAL· v3
4.3 MEDIUM· v2
Reflected Cross Site Scripting vulnerability in Administrators web console in McAfee Web Gateway (MWG) 7.8.x prior to 7.8.2.13 allows remote attackers to collect sensitive information or execute commands with the MWG adm...Show more
Reflected Cross Site Scripting vulnerability in Administrators web console in McAfee Web Gateway (MWG) 7.8.x prior to 7.8.2.13 allows remote attackers to collect sensitive information or execute commands with the MWG administrator's credentials via tricking the administrator to click on a carefully constructed malicious link.Show less
1Afterlogic
1Aurora
Jun 17, 2026
Sep 12, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Afterlogic Aurora through 8.3.9-build-a3 has XSS that can be leveraged for session hijacking by retrieving the session cookie from the administrator login.
1Jenkins
1Dashboard View
Jun 17, 2026
Sep 12, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Jenkins Dashboard View Plugin 2.11 and earlier did not escape build descriptions, resulting in a cross-site scripting vulnerability exploitable by users able to change build descriptions.
1Jenkins
1Build Environment
Jun 17, 2026
Sep 12, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Jenkins Build Environment Plugin 1.6 and earlier did not escape variables shown on its views, resulting in a cross-site scripting vulnerability in Jenkins 2.145, 2.138.1, or older, exploitable by users able to change var...Show more
Jenkins Build Environment Plugin 1.6 and earlier did not escape variables shown on its views, resulting in a cross-site scripting vulnerability in Jenkins 2.145, 2.138.1, or older, exploitable by users able to change various job/build properties.Show less
1Microsoft
2Azure Devops Server
Team Foundation Server
Jun 17, 2026
Sep 11, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A Cross-site Scripting (XSS) vulnerability exists when Team Foundation Server does not properly sanitize user provided input, aka 'Team Foundation Server Cross-site Scripting Vulnerability'.
1Microsoft
3Windows 10
Windows Server 2016Windows Server 2019
Jun 17, 2026
Sep 11, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A cross-site-scripting (XSS) vulnerability exists when Active Directory Federation Services (ADFS) does not properly sanitize certain error messages, aka 'Active Directory Federation Services XSS Vulnerability'.
1Microsoft
1Exchange Server
Jun 17, 2026
Sep 11, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A spoofing vulnerability exists in Microsoft Exchange Server when Outlook Web App (OWA) fails to properly handle web requests, aka 'Microsoft Exchange Spoofing Vulnerability'.
1Microsoft
1Sharepoint Foundation
Jun 17, 2026
Sep 11, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office SharePoint XSS Vulnera...Show more
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office SharePoint XSS Vulnerability'.Show less
1Apache
1Ofbiz
Jun 17, 2026
Sep 11, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The "Blog", "Forum", "Contact Us" screens of the template "ecommerce" application bundled in Apache OFBiz are weak to Stored XSS attacks. Mitigation: Upgrade to 16.11.06 or manually apply the following commits on branch...Show more
The "Blog", "Forum", "Contact Us" screens of the template "ecommerce" application bundled in Apache OFBiz are weak to Stored XSS attacks. Mitigation: Upgrade to 16.11.06 or manually apply the following commits on branch 16.11: 1858438, 1858543, 1860595 and 1860616Show less
1Dell
2Rsa Identity Governance And Lifecycle
Rsa Via Lifecycle And Governance
Jun 17, 2026
Sep 11, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The RSA Identity Governance and Lifecycle software and RSA Via Lifecycle and Governance products prior to 7.1.0 P08 contain a stored cross-site scripting vulnerability in the Access Request module. A remote authenticated...Show more
The RSA Identity Governance and Lifecycle software and RSA Via Lifecycle and Governance products prior to 7.1.0 P08 contain a stored cross-site scripting vulnerability in the Access Request module. A remote authenticated malicious user could potentially exploit this vulnerability to store malicious HTML or JavaScript code in a trusted application data store. When victim users access the data store through their browsers, the stored malicious code would gets executed by the web browser in the context of the vulnerable web application.Show less
1Atlassian
1Jira Server
Jun 17, 2026
Sep 11, 2019
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Various templates of the Optimization plugin in Jira before version 7.13.6, and from version 8.0.0 before version 8.4.0 allow remote attackers who have permission to manage custom fields to inject arbitrary HTML or JavaS...Show more
Various templates of the Optimization plugin in Jira before version 7.13.6, and from version 8.0.0 before version 8.4.0 allow remote attackers who have permission to manage custom fields to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the name of a custom field.Show less
2Debian
Wordpress
2Debian Linux
Wordpress
Jun 17, 2026
Sep 11, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
WordPress before 5.2.3 allows XSS in post previews by authenticated users.
2Debian
Wordpress
2Debian Linux
Wordpress
Jun 17, 2026
Sep 11, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
WordPress before 5.2.3 has an issue with URL sanitization in wp_kses_bad_protocol_once in wp-includes/kses.php that can lead to cross-site scripting (XSS) attacks.
2Debian
Wordpress
2Debian Linux
Wordpress
Jun 17, 2026
Sep 11, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
WordPress before 5.2.3 allows reflected XSS in the dashboard.
2Debian
Wordpress
2Debian Linux
Wordpress
Jun 17, 2026
Sep 11, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
WordPress before 5.2.3 allows XSS in shortcode previews.
2Debian
Wordpress
2Debian Linux
Wordpress
Jun 17, 2026
Sep 11, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
WordPress before 5.2.3 allows XSS in stored comments.
2Debian
Wordpress
2Debian Linux
Wordpress
Jun 17, 2026
Sep 11, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
WordPress before 5.2.3 allows XSS in media uploads because wp_ajax_upload_attachment is mishandled.
1Atlassian
1Jira Server
Jun 17, 2026
Sep 11, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The FilterPickerPopup.jspa resource in Jira before version 7.13.7, and from version 8.0.0 before version 8.3.3 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability...Show more
The FilterPickerPopup.jspa resource in Jira before version 7.13.7, and from version 8.0.0 before version 8.3.3 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the searchOwnerUserName parameter.Show less
1Esri
1Arcgis Enterprise
Jun 17, 2026
Sep 11, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
In ArcGIS Enterprise 10.6.1, a crafted IFRAME element can be used to trigger a Cross Frame Scripting (XFS) attack through the EDIT MY PROFILE feature.