CWE-79
46,299 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (46,299)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
In system/workplace/ in Alkacon OpenCms 10.5.4 and 10.5.5, there are multiple Reflected and Stored XSS issues in the management interface. |
1Alkacon 1Opencms Apollo Template Jun 17, 2026 Aug 27, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 In the Alkacon OpenCms Apollo Template 10.5.4 and 10.5.5, there is XSS in the Login form. |
1Alkacon 1Opencms Apollo Template Jun 17, 2026 Aug 27, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 In the Alkacon OpenCms Apollo Template 10.5.4 and 10.5.5, there is XSS in the search engine. |
The anycomment plugin before 0.0.33 for WordPress has XSS. |
The timesheet plugin before 0.1.5 for WordPress has multiple XSS issues. |
1Check Email Project 1Check Email Nov 21, 2024 Aug 27, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The check-email plugin before 0.5.2 for WordPress has XSS. |
The ckeditor-for-wordpress plugin before 4.5.3.1 for WordPress has reflected XSS in the "built-in (old)" file browser. |
The wp-plotly plugin before 1.0.3 for WordPress has XSS by authors. |
The cp-polls plugin before 1.0.5 for WordPress has XSS. |
The wp-rollback plugin before 1.2.3 for WordPress has XSS. |
The cp-polls plugin before 1.0.1 for WordPress has XSS in the votes list. |
GNUBOARD5 before 5.3.2.0 has XSS that allows remote attackers to inject arbitrary web script or HTML via the "homepage title" parameter, aka the adm/config_form_update.php cf_title parameter. |
Reflected cross site scripting (XSS) in L-Soft LISTSERV before 16.5-2018a exists via the /scripts/wa.exe OK parameter. |
1Status Board Project 1Status Board Jun 17, 2026 Aug 26, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Status Board 1.1.81 has reflected XSS via dashboard.ts. |
CyberChef before 8.31.2 allows XSS in core/operations/TextEncodingBruteForce.mjs. |
laracom (aka Laravel FREE E-Commerce Software) 1.4.11 has search?q= XSS. |
1Status Board Project 1Status Board Jun 17, 2026 Aug 26, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Status Board 1.1.81 has reflected XSS via logic.ts. |
The authentication applet in Watchguard Fireware 11.11 Operating System has reflected XSS (this can also cause an open redirect). |
An Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") in Fortinet FortiNAC 8.3.0 to 8.3.6 and 8.5.0 admin webUI may allow an unauthenticated attacker to perform a reflected XSS attack vi...Show more |
Escalation of privilege vulnerability in the Palo Alto Networks Twistlock console 19.07.358 and earlier allows a Twistlock user with Operator capabilities to escalate privileges to that of another user. Active interactio...Show more |