← Back
CWE-79

46,282 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (46,282)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Cpanel
1Cpanel
Nov 21, 2024
Aug 6, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
cPanel before 60.0.25 allows stored XSS during the homedir removal phase of WHM Account termination (SEC-174).
1Firefly Iii
1Firefly Iii
Jun 17, 2026
Aug 5, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Firefly III 4.7.17.5 is vulnerable to stored XSS due to the lack of filtration of user-supplied data in the liability name field. The JavaScript code is executed upon an error condition during a visit to the account show...Show more
Firefly III 4.7.17.5 is vulnerable to stored XSS due to the lack of filtration of user-supplied data in the liability name field. The JavaScript code is executed upon an error condition during a visit to the account show page.Show less
1Firefly Iii
1Firefly Iii
Jun 17, 2026
Aug 5, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Firefly III 4.7.17.3 is vulnerable to stored XSS due to the lack of filtration of user-supplied data in the bill name field. The JavaScript code is executed during rule-from-bill creation.
1Firefly Iii
1Firefly Iii
Jun 17, 2026
Aug 5, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Firefly III 4.7.17.3 is vulnerable to stored XSS due to the lack of filtration of user-supplied data in the asset account name. The JavaScript code is executed during a visit to the audit account statistics page.
1Firefly Iii
1Firefly Iii
Jun 17, 2026
Aug 5, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Firefly III 4.7.17.3 is vulnerable to stored XSS due to the lack of filtration of user-supplied data in the transaction description field. The JavaScript code is executed during deletion of a transaction link.
1Firefly Iii
1Firefly Iii
Jun 17, 2026
Aug 5, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Firefly III 4.7.17.4 is vulnerable to multiple stored XSS issues due to the lack of filtration of user-supplied data in the transaction description field and the asset account name. The JavaScript code is executed during...Show more
Firefly III 4.7.17.4 is vulnerable to multiple stored XSS issues due to the lack of filtration of user-supplied data in the transaction description field and the asset account name. The JavaScript code is executed during a convert transaction action.Show less
1Espocrm
1Espocrm
Jun 17, 2026
Aug 5, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
An issue was discovered in EspoCRM before 5.6.9. Stored XSS was executed when a victim clicks on the Edit Dashboard feature present on the Homepage. An attacker can load malicious JavaScript inside the add tab list featu...Show more
An issue was discovered in EspoCRM before 5.6.9. Stored XSS was executed when a victim clicks on the Edit Dashboard feature present on the Homepage. An attacker can load malicious JavaScript inside the add tab list feature, which would fire when a user clicks on the Edit Dashboard button, thus helping him steal victims' cookies (hence compromising their accounts).Show less
1Espocrm
1Espocrm
Jun 17, 2026
Aug 5, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
An issue was discovered in EspoCRM before 5.6.9. Stored XSS was executed inside the title and breadcrumb of a newly formed entity available to all the users. A malicious user can inject JavaScript in these values of an e...Show more
An issue was discovered in EspoCRM before 5.6.9. Stored XSS was executed inside the title and breadcrumb of a newly formed entity available to all the users. A malicious user can inject JavaScript in these values of an entity, thus stealing user cookies when someone visits the publicly accessible link.Show less
1Espocrm
1Espocrm
Jun 17, 2026
Aug 5, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
An issue was discovered in EspoCRM before 5.6.9. Stored XSS in the body of an Article was executed when a victim opens articles received through mail. This Article can be formed by an attacker using the Knowledge Base fe...Show more
An issue was discovered in EspoCRM before 5.6.9. Stored XSS in the body of an Article was executed when a victim opens articles received through mail. This Article can be formed by an attacker using the Knowledge Base feature in the tab list. The attacker could inject malicious JavaScript inside the body of the article, thus helping him steal victims' cookies (hence compromising their accounts).Show less
1Espocrm
1Espocrm
Jun 17, 2026
Aug 5, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
An issue was discovered in EspoCRM before 5.6.9. Stored XSS was executed when a attacker sends an attachment to admin with malicious JavaScript in the filename. This JavaScript executed when an admin selects the particul...Show more
An issue was discovered in EspoCRM before 5.6.9. Stored XSS was executed when a attacker sends an attachment to admin with malicious JavaScript in the filename. This JavaScript executed when an admin selects the particular file from the list of all attachments. The attacker could inject the JavaScript inside the filename and send it to users, thus helping him steal victims' cookies (hence compromising their accounts).Show less
1Espocrm
1Espocrm
Jun 17, 2026
Aug 5, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
An issue was discovered in EspoCRM before 5.6.9. Stored XSS was executed on the Preference page as well as while sending an email when a malicious payload was inserted inside the Email Signature in the Preference page. T...Show more
An issue was discovered in EspoCRM before 5.6.9. Stored XSS was executed on the Preference page as well as while sending an email when a malicious payload was inserted inside the Email Signature in the Preference page. The attacker could insert malicious JavaScript inside his email signature, which fires when the victim replies or forwards the mail, thus helping him steal victims' cookies (hence compromising their accounts).Show less
1Sitecore
1Cms
Jun 17, 2026
Aug 5, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Multiple cross-site scripting (XSS) vulnerabilities in Sitecore CMS 9.0.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) #300583 - List Manager Dashboard module, (2) #307638 - Campa...Show more
Multiple cross-site scripting (XSS) vulnerabilities in Sitecore CMS 9.0.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) #300583 - List Manager Dashboard module, (2) #307638 - Campaign Creator module, (3) #316994 - Attributes field, (4) I#316995 - Icon Selection module, (5) #317000 - Latitude field, (6) #317000 - Longitude field, (7) #317017 - UploadPackage2.aspx module, (8) #317072 - Context menu, or (9) I#317073 - Insert from Template dialog.Show less
1Cpanel
1Cpanel
Nov 21, 2024
Aug 5, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
cPanel before 62.0.4 allows stored XSS in the WHM Account Suspension List interface (SEC-211).
1Cpanel
1Cpanel
Nov 21, 2024
Aug 5, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
cPanel before 62.0.4 allows self XSS on the webmail Password and Security page (SEC-199).
1Cpanel
1Cpanel
Nov 21, 2024
Aug 5, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
cPanel before 62.0.4 allows reflected XSS in reset-password interfaces (SEC-198).
1Cpanel
1Cpanel
Nov 21, 2024
Aug 5, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
cPanel before 62.0.4 allows self XSS on the paper_lantern password-change screen (SEC-197).
1Cpanel
1Cpanel
Nov 21, 2024
Aug 5, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
cPanel before 60.0.25 allows self XSS in the tail_ea4_migration.cgi interface (SEC-172).
1Cpanel
1Cpanel
Nov 21, 2024
Aug 5, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
cPanel before 60.0.25 allows stored XSS in the WHM Repair Mailbox Permissions interface (SEC-159).
1Ipandao
1Editor.md
Jun 17, 2026
Aug 3, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
pandao Editor.md 1.5.0 allows XSS via an attribute of an ABBR or SUP element.
1Magento
1Magento
Jun 17, 2026
Aug 2, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A stored cross-cite scripting vulnerability exists in Magento Open Source prior to 1.9.4.2, and Magento Commerce prior to 1.14.4.2, Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. An...Show more
A stored cross-cite scripting vulnerability exists in Magento Open Source prior to 1.9.4.2, and Magento Commerce prior to 1.14.4.2, Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. An authenticated user with privileges to modify currency symbols can inject malicious javascript.Show less