← Back
CWE-79

46,289 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (46,289)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Getawesomesupport
1Awesome Support
Nov 21, 2024
Aug 20, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The awesome-support plugin before 3.1.7 for WordPress has XSS via custom information messages.
1Oldstreetsolutions
1Live Input Macros
Jun 17, 2026
Aug 20, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Live:Text Box macro in the Old Street Live Input Macros app before 2.11 for Confluence has XSS, leading to theft of the Administrator Session Cookie.
1Yofla
1360 Product Rotation
Jun 17, 2026
Aug 20, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The 360-product-rotation plugin before 1.4.8 for WordPress has reflected XSS.
1Open Xchange
1Open Xchange Appsuite
Jun 17, 2026
Aug 20, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
OX App Suite 7.10.0 to 7.10.2 allows XSS.
1Fatfreecrm
1Fat Free Crm
Nov 21, 2024
Aug 20, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Fat Free CRM before 0.18.1 has XSS in the tags_helper in app/helpers/tags_helper.rb.
1Getflightpath
1Flightpath
Jun 17, 2026
Aug 20, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
FlightPath 4.8.3 has XSS in the Content, Edit urgent message, and Users sections of the Admin Console. This could lead to cookie stealing and other malicious actions.
1Thedaylightstudio
1Fuel Cms
Jun 17, 2026
Aug 20, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
FUEL CMS 1.4.4 has XSS in the Create Blocks section of the Admin console. This could lead to cookie stealing and other malicious actions. This vulnerability can be exploited with an authenticated account but can also imp...Show more
FUEL CMS 1.4.4 has XSS in the Create Blocks section of the Admin console. This could lead to cookie stealing and other malicious actions. This vulnerability can be exploited with an authenticated account but can also impact unauthenticated visitors.Show less
1Lenovo
15Bladecenter Hs22 Firmware
Bladecenter Hs22v FirmwareBladecenter Hx5 Firmware+12 more
Jun 17, 2026
Aug 19, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A stored cross-site scripting (XSS) vulnerability exists in various firmware versions of the legacy IBM System x IMM (IMM v1) embedded Baseboard Management Controller (BMC). This vulnerability could allow an unauthentica...Show more
A stored cross-site scripting (XSS) vulnerability exists in various firmware versions of the legacy IBM System x IMM (IMM v1) embedded Baseboard Management Controller (BMC). This vulnerability could allow an unauthenticated user to cause JavaScript code to be stored in the IMM log which may then be executed in the user's web browser when IMM log records containing the JavaScript code are viewed. The JavaScript code is not executed on IMM itself. The later IMM2 (IMM v2) is not affected.Show less
1Awesomemotive
1Easy Digital Downloads
Jun 17, 2026
Aug 16, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The easy-digital-downloads plugin before 2.9.16 for WordPress has XSS related to IP address logging.
1Bestwebsoft
1Zendesk Help Center
Nov 21, 2024
Aug 16, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The zendesk-help-center plugin before 1.0.5 for WordPress has multiple XSS issues.
1Xakuro
1Xo Security
Nov 21, 2024
Aug 16, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The xo-security plugin before 1.5.3 for WordPress has XSS.
1Kunena
1Kunena
Jun 17, 2026
Aug 16, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The Kunena extension before 5.1.14 for Joomla! allows XSS via BBCode.
1Wso2
1Api Manager
Jun 17, 2026
Aug 16, 2019
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
An issue was discovered in WSO2 API Manager 2.6.0 before WSO2-CARBON-PATCH-4.4.0-4457. There is XSS via a crafted filename to the file-upload feature of the event simulator component.
1Diaowen
1Dwsurvey
Jun 17, 2026
Aug 16, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
DWSurvey through 2019-07-22 has reflected XSS via the design/qu-multi-fillblank!answers.action surveyId parameter.
1Prospecta
1Master Data Online
Nov 21, 2024
Aug 15, 2019
N/A· v4
5.4 MEDIUM· v3
4.3 MEDIUM· v2
Prospecta Master Data Online (MDO) 2.0 has Stored XSS.
1Clippercms
1Clippercms
Nov 21, 2024
Aug 15, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
CMS Clipper 1.3.3 has XSS in the Security tab search, User Groups, Resource Groups, and User/Resource Group Links fields.
1Kunalnagar
1Custom 404 Pro
Jun 17, 2026
Aug 15, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Custom 404 Pro plugin 3.2.8 for WordPress has XSS via the wp-admin/admin.php?page=c4p-main page parameter.
1Codepeople
1Cp Contact Form With Paypal
Jun 17, 2026
Aug 15, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The "CP Contact Form with PayPal" plugin before 1.2.98 for WordPress has XSS in CSS edition.
1Modx
1Evolution Cms
Jun 17, 2026
Aug 15, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Evolution CMS 2.0.x allows XSS via a description and new category location in a template. NOTE: the vendor states that the behavior is consistent with the "access policy in the administration panel.
1Zte
1Zxhn F670 Firmware
Jun 17, 2026
Aug 15, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
All versions up to V1.1.10P3T18 of ZTE ZXHN F670 product are impacted by cross-site scripting vulnerability (XSS). Due to incomplete input validation, an authorized user can exploit this vulnerability to execute maliciou...Show more
All versions up to V1.1.10P3T18 of ZTE ZXHN F670 product are impacted by cross-site scripting vulnerability (XSS). Due to incomplete input validation, an authorized user can exploit this vulnerability to execute malicious scripts.Show less