← Back
CWE-79

46,311 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (46,311)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Sentrifugo
1Sentrifugo
Jun 17, 2026
Sep 4, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Multiple stored XSS vulnerabilities in Sentrifugo 3.2 could allow authenticated users to inject arbitrary web script or HTML.
1Suse
1Rancher
Jun 17, 2026
Sep 4, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Rancher 2 through 2.2.4 is vulnerable to a Cross-Site Websocket Hijacking attack that allows an exploiter to gain access to clusters managed by Rancher. The attack requires a victim to be logged into a Rancher server, an...Show more
Rancher 2 through 2.2.4 is vulnerable to a Cross-Site Websocket Hijacking attack that allows an exploiter to gain access to clusters managed by Rancher. The attack requires a victim to be logged into a Rancher server, and then to access a third-party site hosted by the exploiter. Once that is accomplished, the exploiter is able to execute commands against the cluster's Kubernetes API with the permissions and identity of the victim.Show less
1Nagios
1Log Server
Jun 17, 2026
Sep 3, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Nagios Log Server before 2.0.8 allows Reflected XSS via the username on the Login page.
1Lenovo
1Xclarity Administrator
Jun 17, 2026
Sep 3, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A reflected cross-site scripting (XSS) vulnerability was reported in Lenovo XClarity Administrator (LXCA) versions prior to 2.5.0 that could allow a crafted URL, if visited, to cause JavaScript code to be executed in the...Show more
A reflected cross-site scripting (XSS) vulnerability was reported in Lenovo XClarity Administrator (LXCA) versions prior to 2.5.0 that could allow a crafted URL, if visited, to cause JavaScript code to be executed in the user's web browser. The JavaScript code is not executed on LXCA itself.Show less
1Lenovo
1Xclarity Administrator
Jun 17, 2026
Sep 3, 2019
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
A stored cross-site scripting (XSS) vulnerability was reported in Lenovo XClarity Administrator (LXCA) versions prior to 2.5.0 that could allow an administrative user to cause JavaScript code to be stored in LXCA which m...Show more
A stored cross-site scripting (XSS) vulnerability was reported in Lenovo XClarity Administrator (LXCA) versions prior to 2.5.0 that could allow an administrative user to cause JavaScript code to be stored in LXCA which may then be executed in the user's web browser. The JavaScript code is not executed on LXCA itself.Show less
1W3eden
1Download Manager
Jun 17, 2026
Sep 3, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The download-manager plugin before 2.9.94 for WordPress has XSS via the category shortcode feature, as demonstrated by the orderby or search[publish_date] parameter.
1Dell
3Emc Unity Operating Environment
Emc Unityvsa Operating EnvironmentEmc Vnxe3200 Firmware
Jun 17, 2026
Sep 3, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Dell EMC Unity Operating Environment versions prior to 5.0.0.0.5.116, Dell EMC UnityVSA versions prior to 5.0.0.0.5.116 and Dell EMC VNXe3200 versions prior to 3.1.10.9946299 contain a reflected cross-site scripting vuln...Show more
Dell EMC Unity Operating Environment versions prior to 5.0.0.0.5.116, Dell EMC UnityVSA versions prior to 5.0.0.0.5.116 and Dell EMC VNXe3200 versions prior to 3.1.10.9946299 contain a reflected cross-site scripting vulnerability on the cas/logout page. A remote unauthenticated attacker could potentially exploit this vulnerability by tricking a victim application user to supply malicious HTML or Java Script code to Unisphere, which is then reflected back to the victim and executed by the web browser.Show less
1Scriptsbundle
1Carspot
Jun 17, 2026
Sep 3, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The CarSpot theme before 2.1.7 for WordPress has stored XSS via the Phone Number field.
1Jobcareer Project
1Jobcareer
Jun 17, 2026
Sep 3, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The JobCareer theme before 2.5.1 for WordPress has stored XSS.
1Holest
1Breadcrumbs By Menu
Jun 17, 2026
Sep 3, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The breadcrumbs-by-menu plugin before 1.0.3 for WordPress has XSS.
1Easy Pdf Restaurant Menu Upload Project
1Easy Pdf Restaurant Menu Upload
Jun 17, 2026
Aug 30, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The easy-pdf-restaurant-menu-upload plugin before 1.1.2 for WordPress has XSS.
1Kunalnagar
1Custom 404 Pro
Jun 17, 2026
Aug 30, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The custom-404-pro plugin before 3.2.8 for WordPress has reflected XSS, a different vulnerability than CVE-2019-14789.
1Bitwise It
1Webp Express
Jun 17, 2026
Aug 30, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The webp-express plugin before 0.14.8 for WordPress has stored XSS.
1Bootstrapped
1Wp Ultimate Recipe
Jun 17, 2026
Aug 30, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The wp-ultimate-recipe plugin before 3.12.7 for WordPress has stored XSS.
1Simple Mail Address Encoder Project
1Simple Mail Address Encoder
Jun 17, 2026
Aug 30, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The simple-mail-address-encoder plugin before 1.7 for WordPress has reflected XSS.
1Icegram
1Icegram Engage
Jun 17, 2026
Aug 30, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The icegram plugin before 1.10.29 for WordPress has ig_cat_list XSS.
1Greentreelabs
1Gallery Photoblocks
Jun 17, 2026
Aug 30, 2019
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The photoblocks-grid-gallery plugin before 1.1.33 for WordPress has wp-admin/admin.php?page=photoblocks-edit&id= XSS.
1Onesignal
1Onesignal Free Web Push Notifications
Jun 17, 2026
Aug 30, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The onesignal-free-web-push-notifications plugin before 1.17.8 for WordPress has XSS via the subdomain parameter.
1Realestateconnected
1Easy Property Listings
Jun 17, 2026
Aug 30, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The easy-property-listings plugin before 3.4 for WordPress has XSS.
1Wpexpertdeveloper
1Wp Private Content Plus
Jun 17, 2026
Aug 30, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The wp-private-content-plus plugin before 2.0 for WordPress has no protection against option changes via save_settings_page and other save_ functions.