CWE-79
46,299 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (46,299)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The wikirenderer component in Jira before version 7.13.6, and from version 8.0.0 before version 8.3.2 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in image...Show more |
Search Guard Kibana Plugin versions before 5.6.8-7 and before 6.x.y-12 had an issue that an attacker can redirect the user to a potentially malicious site upon Kibana login. |
The MigratePriorityScheme resource in Jira before version 8.3.2 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the priority icon url of an issue priority. |
openITCOCKPIT before 3.7.1 has reflected XSS, aka RVID 3-445b21. |
Ignite Realtime Openfire before 4.4.1 has reflected XSS via an LDAP setup test. |
1Schoolexperience 1Department For Education School Experience Jun 17, 2026 Aug 23, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 DfE School Experience before v16333-GA has XSS via a teacher training URL. |
1Django Js Reverse Project 1Django Js Reserve Jun 17, 2026 Aug 23, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 django-js-reverse (aka Django JS Reverse) before 0.9.1 has XSS via js_reverse_inline. |
Bolt before 3.6.10 has XSS via createFolder or createFile in Controller/Async/FilesystemManager.php. |
Bolt before 3.6.10 has XSS via an image's alt or title field. |
Bolt before 3.6.10 has XSS via a title that is mishandled in the system log. |
1Selectize Plugin A11y Project 1Selectize Plugin A11y Jun 17, 2026 Aug 23, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 selectize-plugin-a11y before 1.1.0 has XSS via the msg field. |
Kimai v2 before 1.1 has XSS via a timesheet description. |
Domoticz 4.10717 has XSS via item.Name. |
Jooby before 1.6.4 has XSS via the default error handler. |
Former before 4.2.1 has XSS via a checkbox value. |
CodiMD 1.3.1, when Safari is used, allows XSS via an IFRAME element with allow-top-navigation in the sandbox attribute, in conjunction with a data: URL. |
1Codection 1Import Users From Csv With Meta Jun 17, 2026 Aug 22, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The import-users-from-csv-with-meta plugin before 1.14.0.3 for WordPress has XSS. |
1Codection 1Import Users From Csv With Meta Jun 17, 2026 Aug 22, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The import-users-from-csv-with-meta plugin before 1.14.1.3 for WordPress has XSS via imported data. |
1Advancedcustomfields 1Advanced Custom Fields Nov 21, 2024 Aug 22, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 The advanced-custom-fields (aka Elliot Condon Advanced Custom Fields) plugin before 5.7.8 for WordPress has XSS by authors. |
The corner-ad plugin before 1.0.8 for WordPress has XSS. |