← Back
CWE-79

46,282 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (46,282)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Enhancesoft
Osticket
2Osticket
Osticket
Jul 10, 2026
Aug 7, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in osTicket before 1.10.7 and 1.12.x before 1.12.1. Stored XSS exists in setup/install.php. It was observed that no input sanitization was provided in the firstname and lastname fields of the appl...Show more
An issue was discovered in osTicket before 1.10.7 and 1.12.x before 1.12.1. Stored XSS exists in setup/install.php. It was observed that no input sanitization was provided in the firstname and lastname fields of the application. The insertion of malicious queries in those fields leads to the execution of those queries. This can further lead to cookie stealing or other malicious actions.Show less
2Enhancesoft
Osticket
2Osticket
Osticket
Jul 10, 2026
Aug 7, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
An issue was discovered in osTicket before 1.10.7 and 1.12.x before 1.12.1. The Ticket creation form allows users to upload files along with queries. It was found that the file-upload functionality has fewer (or no) miti...Show more
An issue was discovered in osTicket before 1.10.7 and 1.12.x before 1.12.1. The Ticket creation form allows users to upload files along with queries. It was found that the file-upload functionality has fewer (or no) mitigations implemented for file content checks; also, the output is not handled properly, causing persistent XSS that leads to cookie stealing or malicious actions. For example, a non-agent user can upload a .html file, and Content-Disposition will be set to inline instead of attachment.Show less
1Diaowen
1Dwsurvey
Jun 17, 2026
Aug 7, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
DWSurvey through 2019-07-22 has stored XSS via the design/my-survey-design!copySurvey.action surveyName parameter.
1Jenkins
1Wall Display
Jun 17, 2026
Aug 7, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A reflected cross-site scripting vulnerability in Jenkins Wall Display Plugin 0.6.34 and earlier allows attackers to inject arbitrary HTML and JavaScript into web pages provided by this plugin.
1Jenkins
1Pegdown Formatter
Jun 17, 2026
Aug 7, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A stored cross-site scripting vulnerability in Jenkins PegDown Formatter Plugin 1.3 and earlier allows attackers able to edit descriptions and other fields rendered using the configured markup formatter to insert links w...Show more
A stored cross-site scripting vulnerability in Jenkins PegDown Formatter Plugin 1.3 and earlier allows attackers able to edit descriptions and other fields rendered using the configured markup formatter to insert links with the javascript scheme into the Jenkins UI.Show less
1Jenkins
1Build Pipeline
Jun 17, 2026
Aug 7, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A stored cross-site scripting vulnerability in Jenkins Build Pipeline Plugin 1.5.8 and earlier allows attackers able to edit the build pipeline description to inject arbitrary HTML and JavaScript in the plugin-provided w...Show more
A stored cross-site scripting vulnerability in Jenkins Build Pipeline Plugin 1.5.8 and earlier allows attackers able to edit the build pipeline description to inject arbitrary HTML and JavaScript in the plugin-provided web pages in Jenkins.Show less
1Annke
1Sp1 Firmware
Nov 21, 2024
Aug 7, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
ANNKE SP1 HD wireless camera 3.4.1.1604071109 devices allow XSS via a crafted SSID.
1Cpanel
1Cpanel
Nov 21, 2024
Aug 7, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
cPanel before 57.9999.54 allows self XSS on the Paper Lantern Landing Page (SEC-110).
1Cnezsoft
1Zentao
Jun 17, 2026
Aug 7, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
An issue was discovered in ZenTao 11.5.1. There is an XSS (stored) vulnerability that leads to the capture of other people's cookies via the Rich Text Box.
1Teampass
1Teampass
Jun 17, 2026
Aug 6, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
An issue was discovered in TeamPass 2.1.27.35. From the sources/items.queries.php "Import items" feature, it is possible to load a crafted CSV file with an XSS payload.
1Open School
1Open School
Jun 17, 2026
Aug 6, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Open-School 3.0, and Community Edition 2.3, allows XSS via the osv/index.php?r=students/guardians/create id parameter.
1Cpanel
1Cpanel
Nov 21, 2024
Aug 6, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
cPanel before 59.9999.145 allows stored XSS in the WHM tail_upcp2.cgi interface (SEC-156).
1Cpanel
1Cpanel
Nov 21, 2024
Aug 6, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
cPanel before 60.0.25 allows self XSS in the alias upload interface (SEC-184).
1Cpanel
1Cpanel
Nov 21, 2024
Aug 6, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
cPanel before 60.0.25 allows self stored XSS in SSL_listkeys (SEC-182).
1Cpanel
1Cpanel
Nov 21, 2024
Aug 6, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
cPanel before 60.0.25 allows self stored XSS in postgres API1 listdbs (SEC-181).
1Cpanel
1Cpanel
Nov 21, 2024
Aug 6, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
cPanel before 60.0.25 allows self XSS in the UI_confirm API (SEC-180).
1Cpanel
1Cpanel
Nov 21, 2024
Aug 6, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
cPanel before 60.0.25 allows stored XSS in the ftp_sessions API (SEC-180).
1Cpanel
1Cpanel
Nov 21, 2024
Aug 6, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
cPanel before 60.0.25 allows stored XSS in api1_listautoresponders (SEC-179).
1Cpanel
1Cpanel
Nov 21, 2024
Aug 6, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
cPanel before 60.0.25 allows self stored XSS in the listftpstable API (SEC-178).
1Cpanel
1Cpanel
Nov 21, 2024
Aug 6, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
cPanel before 60.0.25 allows self XSS in WHM Tweak Settings for autodiscover_host (SEC-177).