CWE-79
46,280 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (46,280)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
A stored cross-site scripting vulnerability exists in the admin panel of Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This can be exploited by an authenticated user with access to...Show more |
A stored cross-site scripting vulnerability exists in the admin panel of Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This can be exploited by an authenticated user with access to...Show more |
A stored cross-site scripting vulnerability exists in the admin panel for Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This can be exploited by an authenticated user with access to...Show more |
A reflected cross-site scripting vulnerability exists in the Product widget chooser functionality in the admin panel for Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. |
A stored cross-site scripting vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This could be exploited by an authenticated user with privileges to the tax notif...Show more |
The web interface of the D-Link DVA-5592 20180823 is vulnerable to an authentication bypass that allows an unauthenticated user to have access to sensitive information such as the Wi-Fi password and the phone number (if...Show more |
The web interface of the D-Link DVA-5592 20180823 is vulnerable to XSS because HTML form parameters are directly reflected. |
cPanel before 62.0.17 allows self XSS in the WHM cPAddons showsecurity interface (SEC-217). |
cPanel before 62.0.24 allows stored XSS in the WHM cPAddons install interface (SEC-262). |
cPanel before 66.0.2 allows stored XSS during WHM cPAddons processing (SEC-269). |
cPanel before 66.0.2 allows stored XSS during WHM cPAddons uninstallation (SEC-266). |
cPanel before 66.0.2 allows stored XSS during WHM cPAddons file operations (SEC-265). |
cPanel before 66.0.2 allows stored XSS during WHM cPAddons installation (SEC-263). |
cPanel before 67.9999.103 allows stored XSS in WHM MySQL Password Change interfaces (SEC-282). |
cPanel before 68.0.15 allows stored XSS during a cpaddons moderated upgrade (SEC-336). |
1Editor.md Project 1Editor.md Jun 17, 2026 Aug 1, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 pandao Editor.md 1.5.0 allows XSS via the Javascript: string. |
A potential security vulnerability has been identified in HP2910al-48G version W.15.14.0016. The attack exploits an xss injection by setting the attack vector in one of the switch persistent configuration fields (managem...Show more |
cPanel before 57.9999.54 allows self XSS during ftp account creation under addon domains (SEC-118). |
cPanel before 68.0.27 allows self XSS in the WHM listips interface (SEC-389). |
cPanel before 68.0.27 allows self XSS in WHM Spamd Startup Config (SEC-387). |