← Back
CWE-79

46,311 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (46,311)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Gitlab
1Gitlab
Jun 17, 2026
Sep 9, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
An input validation and output encoding issue was discovered in the GitLab email notification feature which could result in a persistent XSS. This was addressed in GitLab 12.1.2, 12.0.4, and 11.11.6.
1Gitlab
1Gitlab
Jun 17, 2026
Sep 9, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
An input validation and output encoding issue was discovered in the GitLab CE/EE wiki pages feature which could result in a persistent XSS. This vulnerability was addressed in 12.1.2, 12.0.4, and 11.11.6.
1Librenms
1Librenms
Jun 17, 2026
Sep 9, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in LibreNMS through 1.47. Many of the scripts rely on the function mysqli_escape_real_string for filtering data. However, this is particularly ineffective when returning user supplied input in an...Show more
An issue was discovered in LibreNMS through 1.47. Many of the scripts rely on the function mysqli_escape_real_string for filtering data. However, this is particularly ineffective when returning user supplied input in an HTML or a JavaScript context, resulting in unsafe data being injected into these contexts, leading to attacker controlled JavaScript executing in the browser. One example of this is the string parameter in html/pages/inventory.inc.php.Show less
1Sakailms
1Sakai
Jun 17, 2026
Sep 9, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Sakai through 12.6 allows XSS via a chat user name.
1Getgophish
1Gophish
Jun 17, 2026
Sep 9, 2019
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Gophish through 0.8.0 allows XSS via a username.
1Buddyboss
1Buddymoss Media
Nov 21, 2024
Sep 9, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The buddyboss-media plugin through 3.2.3 for WordPress has stored XSS.
1Vsourz
1Cf7 Invisible Recaptcha
Nov 21, 2024
Sep 9, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The cf7-invisible-recaptcha plugin before 1.3.2 for WordPress has XSS.
1Hgw168cc
1Yii Cms
Jun 17, 2026
Sep 9, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
YII2-CMS v1.0 has XSS in protected\core\modules\home\models\Contact.php via a name field to /contact.html.
1Getgrav
1Grav Cms
Jun 17, 2026
Sep 9, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Grav through 1.6.15 allows (Stored) Cross-Site Scripting due to JavaScript execution in SVG images.
110web
1Photo Gallery
Jun 17, 2026
Sep 8, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross site scripting (XSS) in the photo-gallery (10Web Photo Gallery) plugin before 1.5.35 for WordPress exists via admin/controllers/Options.php.
110web
1Photo Gallery
Jun 17, 2026
Sep 8, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross site scripting (XSS) in the photo-gallery (10Web Photo Gallery) plugin before 1.5.35 for WordPress exists via admin/models/Galleries.php.
1Silver Peak
1Unity Edgeconnect Sd Wan Firmware
Jun 17, 2026
Sep 8, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Silver Peak EdgeConnect SD-WAN before 8.1.7.x has reflected XSS via the rest/json/configdb/download/ PATH_INFO.
1Acquia
1Mautic
Nov 21, 2024
Sep 6, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in Mautic 2.13.1. There is Stored XSS via the authorUrl field in config.json.
1Jetbrains
1Teamcity
Jun 17, 2026
Sep 5, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
JetBrains TeamCity 2019.1 and 2019.1.1 allows cross-site scripting (XSS), potentially making it possible to send an arbitrary HTTP request to a TeamCity server under the name of the currently logged-in user.
1Ibm
1Jazz For Service Management
Jun 17, 2026
Sep 5, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
IBM Jazz for Service Management 1.1.3 is vulnerable to HTTP header injection, caused by incorrect trust in the HTTP Host header during caching. By sending a specially crafted HTTP GET request, a remote attacker could exp...Show more
IBM Jazz for Service Management 1.1.3 is vulnerable to HTTP header injection, caused by incorrect trust in the HTTP Host header during caching. By sending a specially crafted HTTP GET request, a remote attacker could exploit this vulnerability to inject arbitrary HTTP headers, which will allow the attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking. IBM X-force ID: 158976.Show less
1Ibm
2Business Automation Workflow
Business Process Manager
Jun 17, 2026
Sep 5, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM Business Automation Workflow V18.0.0.0 through V18.0.0.2 and IBM Business Process Manager V8.6.0.0 through V8.6.0.0 Cumulative Fix 2018.03, V8.5.7.0 through V8.5.7.0 Cumulative Fix 2017.06, and V8.5.6.0 through V8.5....Show more
IBM Business Automation Workflow V18.0.0.0 through V18.0.0.2 and IBM Business Process Manager V8.6.0.0 through V8.6.0.0 Cumulative Fix 2018.03, V8.5.7.0 through V8.5.7.0 Cumulative Fix 2017.06, and V8.5.6.0 through V8.5.6.0 CF2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 158415.Show less
1Dasanzhone
1Znid Gpon 2426a Eu Firmware
Jun 17, 2026
Sep 5, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Multiple Cross-Site Scripting (XSS) issues in the web interface on DASAN Zhone ZNID GPON 2426A EU version S3.1.285 devices allow a remote attacker to execute arbitrary JavaScript via manipulation of an unsanitized GET pa...Show more
Multiple Cross-Site Scripting (XSS) issues in the web interface on DASAN Zhone ZNID GPON 2426A EU version S3.1.285 devices allow a remote attacker to execute arbitrary JavaScript via manipulation of an unsanitized GET parameter: /zhndnsdisplay.cmd (name), /wlsecrefresh.wl (wlWscCfgMethod, wl_wsc_reg).Show less
1Cisco
1Identity Services Engine
Jun 17, 2026
Sep 5, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the...Show more
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. The vulnerability exists because the web-based management interface of the affected device does not properly validate user-supplied input. An attacker could exploit this vulnerability by persuading a user to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.Show less
2Instagram Php Api Project
Userproplugin
2Instagram Php Api
User Pro
Jun 17, 2026
Sep 4, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
cosenary Instagram-PHP-API (aka Instagram PHP API V2), as used in the UserPro plugin through 4.9.32 for WordPress, has XSS via the example/success.php error_description parameter.
1Egain
1Chat
Jun 17, 2026
Sep 4, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
eGain Chat 15.0.3 allows HTML Injection.