← Back
CWE-79

46,289 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (46,289)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Opencart
1Opencart
Jun 17, 2026
Aug 15, 2019
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
OpenCart 3.x, when the attacker has login access to the admin panel, allows stored XSS within the Source/HTML editing feature of the Categories, Product, and Information pages.
1Toggle The Title Project
1Toggle The Title
Jun 17, 2026
Aug 15, 2019
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The toggle-the-title (aka Toggle The Title) plugin 1.4 for WordPress has XSS via the wp-admin/admin-ajax.php?action=update_title_options isAutoSaveValveChecked or isDisableAllPagesValveChecked parameter.
1Limbcode
1Limb Gallery
Jun 17, 2026
Aug 15, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The limb-gallery (aka Limb Gallery) plugin 1.4.0 for WordPress has XSS via the wp-admin/admin-ajax.php?action=grsGalleryAjax&grsAction=shortcode task parameter,
1Webstudio
1Ultimate Loan Manager
Jun 17, 2026
Aug 14, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
XSS exists in WEB STUDIO Ultimate Loan Manager 2.0 by adding a branch under the Branches button that sets the notes parameter with crafted JavaScript code.
1Microsoft
1Outlook
Jun 17, 2026
Aug 14, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A spoofing vulnerability exists in the way Microsoft Outlook iOS software parses specifically crafted email messages. An authenticated attacker could exploit the vulnerability by sending a specially crafted email message...Show more
A spoofing vulnerability exists in the way Microsoft Outlook iOS software parses specifically crafted email messages. An authenticated attacker could exploit the vulnerability by sending a specially crafted email message to a victim. The attacker who successfully exploited this vulnerability could then perform cross-site scripting attacks on the affected systems and run scripts in the security context of the current user. The security update addresses the vulnerability by correcting how Outlook iOS parses specially crafted email messages.Show less
1Microsoft
2Sharepoint Enterprise Server
Sharepoint Server
Jun 17, 2026
Aug 14, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server. An authenticated attacker could exploit the...Show more
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server. An authenticated attacker could exploit the vulnerability by sending a specially crafted request to an affected SharePoint server. The attacker who successfully exploited the vulnerability could then perform cross-site scripting attacks on affected systems and run script in the security context of the current user. The attacks could allow the attacker to read content that the attacker is not authorized to read, use the victim's identity to take actions on the SharePoint site on behalf of the user, such as change permissions and delete content, and inject malicious content in the browser of the user. The security update addresses the vulnerability by helping to ensure that SharePoint Server properly sanitizes web requests.Show less
1Solarwinds
1Database Performance Analyzer
Nov 21, 2024
Aug 14, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
SolarWinds Database Performance Analyzer 11.1.457 contains an instance of Reflected XSS in its idcStateError component, where the page parameter is reflected into the HREF of the 'Try Again' Button on the page, aka a /iw...Show more
SolarWinds Database Performance Analyzer 11.1.457 contains an instance of Reflected XSS in its idcStateError component, where the page parameter is reflected into the HREF of the 'Try Again' Button on the page, aka a /iwc/idcStateError.iwc?page= URI.Show less
1Atlassian
1Html Include And Replace Macro
Jun 17, 2026
Aug 14, 2019
N/A· v4
6.8 MEDIUM· v3
6.0 MEDIUM· v2
The "HTML Include and replace macro" plugin before 1.5.0 for Confluence Server allows a bypass of the includeScripts=false XSS protection mechanism via vectors involving an IFRAME element.
1Sugarcrm
1Sugarcrm
Jun 17, 2026
Aug 14, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
SugarCRM Enterprise 9.0.0 allows mobile/error-not-supported-platform.html?desktop_url= XSS.
1Google Doc Embedder Project
1Google Doc Embedder
Nov 21, 2024
Aug 14, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The google-document-embedder plugin before 2.6.2 for WordPress has XSS.
1Google Doc Embedder Project
1Google Doc Embedder
Nov 21, 2024
Aug 14, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The google-document-embedder plugin before 2.6.1 for WordPress has XSS.
1Newstatpress Project
1Newstatpress
Nov 21, 2024
Aug 14, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The newstatpress plugin before 1.0.4 for WordPress has XSS related to the Referer header.
1Newstatpress Project
1Newstatpress
Nov 21, 2024
Aug 14, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The newstatpress plugin before 1.0.5 for WordPress has XSS related to an IMG element.
1Newstatpress Project
1Newstatpress
Nov 21, 2024
Aug 14, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The newstatpress plugin before 1.0.6 for WordPress has reflected XSS.
1Sap
1Netweaver Process Integration
Jun 17, 2026
Aug 14, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Java Proxy Runtime of SAP NetWeaver Process Integration, versions 7.10, 7.11, 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user-controlled inputs and allows an attacker to execute malicious scripts in the url the...Show more
Java Proxy Runtime of SAP NetWeaver Process Integration, versions 7.10, 7.11, 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user-controlled inputs and allows an attacker to execute malicious scripts in the url thereby resulting in Reflected Cross-Site Scripting (XSS) vulnerabilityShow less
1Sap
1Businessobjects Business Intelligence
Jun 17, 2026
Aug 14, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Under certain conditions SAP BusinessObjects Business Intelligence Platform (Central Management Console), versions 4.1, 4.2, 4.3, allows an attacker to store a malicious payload within the description field of a user acc...Show more
Under certain conditions SAP BusinessObjects Business Intelligence Platform (Central Management Console), versions 4.1, 4.2, 4.3, allows an attacker to store a malicious payload within the description field of a user account. The payload is triggered when the mouse cursor is moved over the description field in the list, when generating the little yellow informational pop up box, resulting in Stored Cross Site Scripting Attack.Show less
1Sap
1Businessobjects Business Intelligence
Jun 17, 2026
Aug 14, 2019
N/A· v4
5.4 MEDIUM· v3
4.9 MEDIUM· v2
When creating a module in SAP BusinessObjects Business Intelligence Platform (BI Workspace), versions 4.1, 4.2, 4.3, it is possible to store a malicious script which when executed later could potentially allow a user to...Show more
When creating a module in SAP BusinessObjects Business Intelligence Platform (BI Workspace), versions 4.1, 4.2, 4.3, it is possible to store a malicious script which when executed later could potentially allow a user to escalate privileges via session hijacking. The attacker could also access other sensitive information, leading to Stored Cross Site Scripting.Show less
1Sap
1Businessobjects Business Intelligence
Jun 17, 2026
Aug 14, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
SAP BusinessObjects Business Intelligence Platform (Info View), versions 4.1, 4.2, 4.3, allows an attacker to give some payload for keyword in the search and it will be executed while search performs its action, resultin...Show more
SAP BusinessObjects Business Intelligence Platform (Info View), versions 4.1, 4.2, 4.3, allows an attacker to give some payload for keyword in the search and it will be executed while search performs its action, resulting in Cross-Site Scripting (XSS) vulnerability.Show less
1Tibco
22Loglogic Enterprise Virtual Appliance
Loglogic Log Management IntelligenceLoglogic Lx1025 Firmware+19 more
Jun 17, 2026
Aug 13, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
The web server component of TIBCO Software Inc.'s TIBCO LogLogic Enterprise Virtual Appliance, and TIBCO LogLogic Log Management Intelligence contains multiple vulnerabilities that theoretically allow persistent and refl...Show more
The web server component of TIBCO Software Inc.'s TIBCO LogLogic Enterprise Virtual Appliance, and TIBCO LogLogic Log Management Intelligence contains multiple vulnerabilities that theoretically allow persistent and reflected cross-site scripting (XSS) attacks, as well as cross-site request forgery (CSRF) attacks. This issue affects: TIBCO Software Inc. TIBCO LogLogic Enterprise Virtual Appliance version 6.2.1 and prior versions. TIBCO Software Inc. TIBCO LogLogic Log Management Intelligence 6.2.1. TIBCO LogLogic LX825 Appliance 0.0.004, TIBCO LogLogic LX1025 Appliance 0.0.004, TIBCO LogLogic LX4025 Appliance 0.0.004, TIBCO LogLogic MX3025 Appliance 0.0.004, TIBCO LogLogic MX4025 Appliance 0.0.004, TIBCO LogLogic ST1025 Appliance 0.0.004, TIBCO LogLogic ST2025-SAN Appliance 0.0.004, and TIBCO LogLogic ST4025 Appliance 0.0.004 using TIBCO LogLogic Log Management Intelligence versions 6.2.1 and below. TIBCO LogLogic LX1035 Appliance 0.0.005, TIBCO LogLogic LX1025R1 Appliance 0.0.004, TIBCO LogLogic LX1025R2 Appliance 0.0.004, TIBCO LogLogic LX4025R1 Appliance 0.0.004, TIBCO LogLogic LX4025R2 Appliance 0.0.004, TIBCO LogLogic LX4035 Appliance 0.0.005, TIBCO LogLogic ST2025-SANR1 Appliance 0.0.004, TIBCO LogLogic ST2025-SANR2 Appliance 0.0.004, TIBCO LogLogic ST2035-SAN Appliance 0.0.005, TIBCO LogLogic ST4025R1 Appliance 0.0.004, TIBCO LogLogic ST4025R2 Appliance 0.0.004, and TIBCO LogLogic ST4035 Appliance 0.0.005 using TIBCO LogLogic Log Management Intelligence versions 6.2.1 and below.Show less
1Backup Guard
1Backup Guard
Nov 21, 2024
Aug 13, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Backup Guard plugin before 1.1.47 for WordPress has multiple XSS issues.