CWE-79
46,289 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (46,289)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
OpenCart 3.x, when the attacker has login access to the admin panel, allows stored XSS within the Source/HTML editing feature of the Categories, Product, and Information pages. |
1Toggle The Title Project 1Toggle The Title Jun 17, 2026 Aug 15, 2019 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 The toggle-the-title (aka Toggle The Title) plugin 1.4 for WordPress has XSS via the wp-admin/admin-ajax.php?action=update_title_options isAutoSaveValveChecked or isDisableAllPagesValveChecked parameter. |
The limb-gallery (aka Limb Gallery) plugin 1.4.0 for WordPress has XSS via the wp-admin/admin-ajax.php?action=grsGalleryAjax&grsAction=shortcode task parameter, |
1Webstudio 1Ultimate Loan Manager Jun 17, 2026 Aug 14, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 XSS exists in WEB STUDIO Ultimate Loan Manager 2.0 by adding a branch under the Branches button that sets the notes parameter with crafted JavaScript code. |
A spoofing vulnerability exists in the way Microsoft Outlook iOS software parses specifically crafted email messages. An authenticated attacker could exploit the vulnerability by sending a specially crafted email message...Show more |
1Microsoft 2Sharepoint Enterprise Server Sharepoint ServerJun 17, 2026 Aug 14, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server. An authenticated attacker could exploit the...Show more |
1Solarwinds 1Database Performance Analyzer Nov 21, 2024 Aug 14, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 SolarWinds Database Performance Analyzer 11.1.457 contains an instance of Reflected XSS in its idcStateError component, where the page parameter is reflected into the HREF of the 'Try Again' Button on the page, aka a /iw...Show more |
1Atlassian 1Html Include And Replace Macro Jun 17, 2026 Aug 14, 2019 N/A· v4 6.8 MEDIUM· v3 6.0 MEDIUM· v2 The "HTML Include and replace macro" plugin before 1.5.0 for Confluence Server allows a bypass of the includeScripts=false XSS protection mechanism via vectors involving an IFRAME element. |
SugarCRM Enterprise 9.0.0 allows mobile/error-not-supported-platform.html?desktop_url= XSS. |
1Google Doc Embedder Project 1Google Doc Embedder Nov 21, 2024 Aug 14, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The google-document-embedder plugin before 2.6.2 for WordPress has XSS. |
1Google Doc Embedder Project 1Google Doc Embedder Nov 21, 2024 Aug 14, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The google-document-embedder plugin before 2.6.1 for WordPress has XSS. |
1Newstatpress Project 1Newstatpress Nov 21, 2024 Aug 14, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The newstatpress plugin before 1.0.4 for WordPress has XSS related to the Referer header. |
1Newstatpress Project 1Newstatpress Nov 21, 2024 Aug 14, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The newstatpress plugin before 1.0.5 for WordPress has XSS related to an IMG element. |
1Newstatpress Project 1Newstatpress Nov 21, 2024 Aug 14, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The newstatpress plugin before 1.0.6 for WordPress has reflected XSS. |
1Sap 1Netweaver Process Integration Jun 17, 2026 Aug 14, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Java Proxy Runtime of SAP NetWeaver Process Integration, versions 7.10, 7.11, 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user-controlled inputs and allows an attacker to execute malicious scripts in the url the...Show more |
1Sap 1Businessobjects Business Intelligence Jun 17, 2026 Aug 14, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Under certain conditions SAP BusinessObjects Business Intelligence Platform (Central Management Console), versions 4.1, 4.2, 4.3, allows an attacker to store a malicious payload within the description field of a user acc...Show more |
1Sap 1Businessobjects Business Intelligence Jun 17, 2026 Aug 14, 2019 N/A· v4 5.4 MEDIUM· v3 4.9 MEDIUM· v2 When creating a module in SAP BusinessObjects Business Intelligence Platform (BI Workspace), versions 4.1, 4.2, 4.3, it is possible to store a malicious script which when executed later could potentially allow a user to...Show more |
1Sap 1Businessobjects Business Intelligence Jun 17, 2026 Aug 14, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 SAP BusinessObjects Business Intelligence Platform (Info View), versions 4.1, 4.2, 4.3, allows an attacker to give some payload for keyword in the search and it will be executed while search performs its action, resultin...Show more |
1Tibco 22Loglogic Enterprise Virtual Appliance Loglogic Log Management IntelligenceLoglogic Lx1025 Firmware+19 moreJun 17, 2026 Aug 13, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 The web server component of TIBCO Software Inc.'s TIBCO LogLogic Enterprise Virtual Appliance, and TIBCO LogLogic Log Management Intelligence contains multiple vulnerabilities that theoretically allow persistent and refl...Show more |
The Backup Guard plugin before 1.1.47 for WordPress has multiple XSS issues. |