← Back
CWE-79

46,311 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (46,311)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Sap
1Supplier Relationship Management
Jun 17, 2026
Sep 10, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
SAP Supplier Relationship Management (Master Data Management Catalog - SRM_MDM_CAT, before versions 3.73, 7.31, 7.32) does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerabi...Show more
SAP Supplier Relationship Management (Master Data Management Catalog - SRM_MDM_CAT, before versions 3.73, 7.31, 7.32) does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.Show less
1Magicfields
1Magic Fields
Nov 21, 2024
Sep 10, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The magic-fields plugin before 1.7.2 for WordPress has XSS via the RCCWP_CreateCustomFieldPage.php custom-field-css parameter.
1Magicfields
1Magic Fields
Nov 21, 2024
Sep 10, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The magic-fields plugin before 1.7.2 for WordPress has XSS via the RCCWP_CreateCustomFieldPage.php custom-group-id parameter.
1Magicfields
1Magic Fields
Nov 21, 2024
Sep 10, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The magic-fields plugin before 1.7.2 for WordPress has XSS via the custom-write-panel-id parameter.
1Spot
1Spot.im Comments
Nov 21, 2024
Sep 10, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The spotim-comments plugin before 4.0.4 for WordPress has multiple XSS issues.
1Theme Fusion
1Avada
Nov 21, 2024
Sep 10, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The avada theme before 5.1.5 for WordPress has stored XSS.
1Postman Smtp Project
1Postman Smtp
Nov 21, 2024
Sep 10, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The postman-smtp plugin through 2017-10-04 for WordPress has XSS via the wp-admin/tools.php?page=postman_email_log page parameter.
1Ibps Online Exam Project
1Ibps Online Exam
Nov 21, 2024
Sep 10, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The examapp plugin 1.0 for WordPress has XSS via exam input text fields.
1Ncrafts
1Formcraft
Nov 21, 2024
Sep 10, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The formcraft3 plugin before 3.4 for WordPress has stored XSS via the "New Form > Heading > Heading Text" field.
1Pinfinity Project
1Pinfinity
Nov 21, 2024
Sep 10, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Pinfinity theme before 2.0 for WordPress has XSS via the s parameter.
1Designmodo
1Qards
Nov 21, 2024
Sep 10, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Qards plugin through 2017-10-11 for WordPress has XSS via a remote document specified in the url parameter to html2canvasproxy.php.
1Limesurvey
1Limesurvey
Jun 17, 2026
Sep 9, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A reflected cross-site scripting (XSS) vulnerability was found in Limesurvey before 3.17.14 that allows remote attackers to inject arbitrary web script or HTML via extensions of uploaded files.
1Limesurvey
1Limesurvey
Jun 17, 2026
Sep 9, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A stored cross-site scripting (XSS) vulnerability was found in Limesurvey before 3.17.14 that allows authenticated users with correct permissions to inject arbitrary web script or HTML via titles of admin box buttons on...Show more
A stored cross-site scripting (XSS) vulnerability was found in Limesurvey before 3.17.14 that allows authenticated users with correct permissions to inject arbitrary web script or HTML via titles of admin box buttons on the home page.Show less
1Liferay
1Liferay Portal
Jun 17, 2026
Sep 9, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Liferay Portal through 7.2.0 GA1 allows XSS via a journal article title to journal_article/page.jsp in journal/journal-taglib.
1Padrinorb
1Padrino Contrib
Jun 17, 2026
Sep 9, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The breadcrumbs contributed module through 0.2.0 for Padrino Framework allows XSS via a caption.
1Gitlab
1Gitlab
Jun 17, 2026
Sep 9, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It allows XSS (issue 1 of 2). Markdown fields contain a lack of input validation and outpu...Show more
An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It allows XSS (issue 1 of 2). Markdown fields contain a lack of input validation and output encoding when processing KaTeX that results in a persistent XSS.Show less
1Limesurvey
1Limesurvey
Jun 17, 2026
Sep 9, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
LimeSurvey before v3.17.14 allows reflected XSS for escalating privileges from a low-privileged account to, for example, SuperAdmin. This occurs in application/core/Survey_Common_Action.php,
1Limesurvey
1Limesurvey
Jun 17, 2026
Sep 9, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
LimeSurvey before v3.17.14 allows stored XSS for escalating privileges from a low-privileged account to, for example, SuperAdmin. The attack uses a survey group in which the title contains JavaScript that is mishandled u...Show more
LimeSurvey before v3.17.14 allows stored XSS for escalating privileges from a low-privileged account to, for example, SuperAdmin. The attack uses a survey group in which the title contains JavaScript that is mishandled upon group deletion.Show less
1Gitlab
1Gitlab
Jun 17, 2026
Sep 9, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
An issue was discovered in GitLab Community and Enterprise Edition before 11.8.9. It has Incorrect Access Control. Unprivileged members of a project are able to post comments on confidential issues through an authorizati...Show more
An issue was discovered in GitLab Community and Enterprise Edition before 11.8.9. It has Incorrect Access Control. Unprivileged members of a project are able to post comments on confidential issues through an authorization issue in the note endpoint.Show less
1Gitlab
1Gitlab
Jun 17, 2026
Sep 9, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in GitLab Community and Enterprise Edition before 11.8.9, 11.9.x before 11.9.10, and 11.10.x before 11.10.2. It has Improper Encoding or Escaping of Output. The branch name on new merge request no...Show more
An issue was discovered in GitLab Community and Enterprise Edition before 11.8.9, 11.9.x before 11.9.10, and 11.10.x before 11.10.2. It has Improper Encoding or Escaping of Output. The branch name on new merge request notification emails isn't escaped, which could potentially lead to XSS issues.Show less