CWE-79
46,311 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (46,311)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Sap 1Supplier Relationship Management Jun 17, 2026 Sep 10, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 SAP Supplier Relationship Management (Master Data Management Catalog - SRM_MDM_CAT, before versions 3.73, 7.31, 7.32) does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerabi...Show more |
The magic-fields plugin before 1.7.2 for WordPress has XSS via the RCCWP_CreateCustomFieldPage.php custom-field-css parameter. |
The magic-fields plugin before 1.7.2 for WordPress has XSS via the RCCWP_CreateCustomFieldPage.php custom-group-id parameter. |
The magic-fields plugin before 1.7.2 for WordPress has XSS via the custom-write-panel-id parameter. |
The spotim-comments plugin before 4.0.4 for WordPress has multiple XSS issues. |
The avada theme before 5.1.5 for WordPress has stored XSS. |
1Postman Smtp Project 1Postman Smtp Nov 21, 2024 Sep 10, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The postman-smtp plugin through 2017-10-04 for WordPress has XSS via the wp-admin/tools.php?page=postman_email_log page parameter. |
1Ibps Online Exam Project 1Ibps Online Exam Nov 21, 2024 Sep 10, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 The examapp plugin 1.0 for WordPress has XSS via exam input text fields. |
The formcraft3 plugin before 3.4 for WordPress has stored XSS via the "New Form > Heading > Heading Text" field. |
1Pinfinity Project 1Pinfinity Nov 21, 2024 Sep 10, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The Pinfinity theme before 2.0 for WordPress has XSS via the s parameter. |
The Qards plugin through 2017-10-11 for WordPress has XSS via a remote document specified in the url parameter to html2canvasproxy.php. |
A reflected cross-site scripting (XSS) vulnerability was found in Limesurvey before 3.17.14 that allows remote attackers to inject arbitrary web script or HTML via extensions of uploaded files. |
A stored cross-site scripting (XSS) vulnerability was found in Limesurvey before 3.17.14 that allows authenticated users with correct permissions to inject arbitrary web script or HTML via titles of admin box buttons on...Show more |
Liferay Portal through 7.2.0 GA1 allows XSS via a journal article title to journal_article/page.jsp in journal/journal-taglib. |
The breadcrumbs contributed module through 0.2.0 for Padrino Framework allows XSS via a caption. |
An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It allows XSS (issue 1 of 2). Markdown fields contain a lack of input validation and outpu...Show more |
LimeSurvey before v3.17.14 allows reflected XSS for escalating privileges from a low-privileged account to, for example, SuperAdmin. This occurs in application/core/Survey_Common_Action.php, |
LimeSurvey before v3.17.14 allows stored XSS for escalating privileges from a low-privileged account to, for example, SuperAdmin. The attack uses a survey group in which the title contains JavaScript that is mishandled u...Show more |
An issue was discovered in GitLab Community and Enterprise Edition before 11.8.9. It has Incorrect Access Control. Unprivileged members of a project are able to post comments on confidential issues through an authorizati...Show more |
An issue was discovered in GitLab Community and Enterprise Edition before 11.8.9, 11.9.x before 11.9.10, and 11.10.x before 11.10.2. It has Improper Encoding or Escaping of Output. The branch name on new merge request no...Show more |