← Back
CWE-79

46,299 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (46,299)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Alkacon
1Opencms
Jun 17, 2026
Aug 27, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In system/workplace/ in Alkacon OpenCms 10.5.4 and 10.5.5, there are multiple Reflected and Stored XSS issues in the management interface.
1Alkacon
1Opencms Apollo Template
Jun 17, 2026
Aug 27, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In the Alkacon OpenCms Apollo Template 10.5.4 and 10.5.5, there is XSS in the Login form.
1Alkacon
1Opencms Apollo Template
Jun 17, 2026
Aug 27, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In the Alkacon OpenCms Apollo Template 10.5.4 and 10.5.5, there is XSS in the search engine.
1Bologer
1Anycomment
Nov 21, 2024
Aug 27, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The anycomment plugin before 0.0.33 for WordPress has XSS.
1Bestwebsoft
1Timesheet
Nov 21, 2024
Aug 27, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The timesheet plugin before 0.1.5 for WordPress has multiple XSS issues.
1Check Email Project
1Check Email
Nov 21, 2024
Aug 27, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The check-email plugin before 0.5.2 for WordPress has XSS.
1Cksource
1Ckeditor
Nov 21, 2024
Aug 27, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The ckeditor-for-wordpress plugin before 4.5.3.1 for WordPress has reflected XSS in the "built-in (old)" file browser.
1Plot
1Plotly
Nov 21, 2024
Aug 27, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The wp-plotly plugin before 1.0.3 for WordPress has XSS by authors.
1Codepeople
1Polls Cp
Nov 21, 2024
Aug 27, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The cp-polls plugin before 1.0.5 for WordPress has XSS.
1Impress
1Wp Rollback
Nov 21, 2024
Aug 27, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The wp-rollback plugin before 1.2.3 for WordPress has XSS.
1Codepeople
1Polls Cp
Nov 21, 2024
Aug 27, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The cp-polls plugin before 1.0.1 for WordPress has XSS in the votes list.
1Sir
1Gnuboard
Nov 21, 2024
Aug 26, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
GNUBOARD5 before 5.3.2.0 has XSS that allows remote attackers to inject arbitrary web script or HTML via the "homepage title" parameter, aka the adm/config_form_update.php cf_title parameter.
1Lsoft
1Listserv
Jun 17, 2026
Aug 26, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Reflected cross site scripting (XSS) in L-Soft LISTSERV before 16.5-2018a exists via the /scripts/wa.exe OK parameter.
1Status Board Project
1Status Board
Jun 17, 2026
Aug 26, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Status Board 1.1.81 has reflected XSS via dashboard.ts.
1Gchq
1Cyberchef
Jun 17, 2026
Aug 26, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
CyberChef before 8.31.2 allows XSS in core/operations/TextEncodingBruteForce.mjs.
1Laracom
1Laracom
Jun 17, 2026
Aug 26, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
laracom (aka Laravel FREE E-Commerce Software) 1.4.11 has search?q= XSS.
1Status Board Project
1Status Board
Jun 17, 2026
Aug 26, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Status Board 1.1.81 has reflected XSS via logic.ts.
1Watchguard
1Fireware
Nov 21, 2024
Aug 23, 2019
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
The authentication applet in Watchguard Fireware 11.11 Operating System has reflected XSS (this can also cause an open redirect).
1Fortinet
1Fortinac
Jun 17, 2026
Aug 23, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") in Fortinet FortiNAC 8.3.0 to 8.3.6 and 8.5.0 admin webUI may allow an unauthenticated attacker to perform a reflected XSS attack vi...Show more
An Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") in Fortinet FortiNAC 8.3.0 to 8.3.6 and 8.5.0 admin webUI may allow an unauthenticated attacker to perform a reflected XSS attack via the search field in the webUI.Show less
1Paloaltonetworks
1Twistlock
Jun 17, 2026
Aug 23, 2019
N/A· v4
8.0 HIGH· v3
6.0 MEDIUM· v2
Escalation of privilege vulnerability in the Palo Alto Networks Twistlock console 19.07.358 and earlier allows a Twistlock user with Operator capabilities to escalate privileges to that of another user. Active interactio...Show more
Escalation of privilege vulnerability in the Palo Alto Networks Twistlock console 19.07.358 and earlier allows a Twistlock user with Operator capabilities to escalate privileges to that of another user. Active interaction with an affected component is required for the payload to execute on the victim.Show less