← Back
CWE-79

46,280 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (46,280)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Magento
1Magento
Jun 17, 2026
Aug 2, 2019
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
A stored cross-site scripting vulnerability exists in the admin panel of Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This can be exploited by an authenticated user with access to...Show more
A stored cross-site scripting vulnerability exists in the admin panel of Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This can be exploited by an authenticated user with access to manage orders and order status.Show less
1Magento
1Magento
Jun 17, 2026
Aug 2, 2019
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
A stored cross-site scripting vulnerability exists in the admin panel of Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This can be exploited by an authenticated user with access to...Show more
A stored cross-site scripting vulnerability exists in the admin panel of Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This can be exploited by an authenticated user with access to edit Product information via the TinyMCE editor.Show less
1Magento
1Magento
Jun 17, 2026
Aug 2, 2019
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
A stored cross-site scripting vulnerability exists in the admin panel for Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This can be exploited by an authenticated user with access to...Show more
A stored cross-site scripting vulnerability exists in the admin panel for Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This can be exploited by an authenticated user with access to products and categories.Show less
1Magento
1Magento
Jun 17, 2026
Aug 2, 2019
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
A reflected cross-site scripting vulnerability exists in the Product widget chooser functionality in the admin panel for Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2.
1Magento
1Magento
Jun 17, 2026
Aug 2, 2019
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
A stored cross-site scripting vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This could be exploited by an authenticated user with privileges to the tax notif...Show more
A stored cross-site scripting vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This could be exploited by an authenticated user with privileges to the tax notifications configuration in the Magento admin panel.Show less
1Dlink
1Dva 5592 Firmware
Jun 17, 2026
Aug 2, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The web interface of the D-Link DVA-5592 20180823 is vulnerable to an authentication bypass that allows an unauthenticated user to have access to sensitive information such as the Wi-Fi password and the phone number (if...Show more
The web interface of the D-Link DVA-5592 20180823 is vulnerable to an authentication bypass that allows an unauthenticated user to have access to sensitive information such as the Wi-Fi password and the phone number (if VoIP is in use).Show less
1Dlink
1Dva 5592 Firmware
Jun 17, 2026
Aug 2, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The web interface of the D-Link DVA-5592 20180823 is vulnerable to XSS because HTML form parameters are directly reflected.
1Cpanel
1Cpanel
Nov 21, 2024
Aug 2, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
cPanel before 62.0.17 allows self XSS in the WHM cPAddons showsecurity interface (SEC-217).
1Cpanel
1Cpanel
Nov 21, 2024
Aug 2, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
cPanel before 62.0.24 allows stored XSS in the WHM cPAddons install interface (SEC-262).
1Cpanel
1Cpanel
Nov 21, 2024
Aug 2, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
cPanel before 66.0.2 allows stored XSS during WHM cPAddons processing (SEC-269).
1Cpanel
1Cpanel
Nov 21, 2024
Aug 2, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
cPanel before 66.0.2 allows stored XSS during WHM cPAddons uninstallation (SEC-266).
1Cpanel
1Cpanel
Nov 21, 2024
Aug 2, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
cPanel before 66.0.2 allows stored XSS during WHM cPAddons file operations (SEC-265).
1Cpanel
1Cpanel
Nov 21, 2024
Aug 2, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
cPanel before 66.0.2 allows stored XSS during WHM cPAddons installation (SEC-263).
1Cpanel
1Cpanel
Nov 21, 2024
Aug 2, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
cPanel before 67.9999.103 allows stored XSS in WHM MySQL Password Change interfaces (SEC-282).
1Cpanel
1Cpanel
Nov 21, 2024
Aug 2, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
cPanel before 68.0.15 allows stored XSS during a cpaddons moderated upgrade (SEC-336).
1Editor.md Project
1Editor.md
Jun 17, 2026
Aug 1, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
pandao Editor.md 1.5.0 allows XSS via the Javascript: string.
1Hp
1Hp2910al 48g Firmware
Jun 17, 2026
Aug 1, 2019
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
A potential security vulnerability has been identified in HP2910al-48G version W.15.14.0016. The attack exploits an xss injection by setting the attack vector in one of the switch persistent configuration fields (managem...Show more
A potential security vulnerability has been identified in HP2910al-48G version W.15.14.0016. The attack exploits an xss injection by setting the attack vector in one of the switch persistent configuration fields (management URL, location, contact). But admin privileges are required to configure these fields thereby reducing the likelihood of exploit. HPE Aruba has provided firmware updates to resolve the vulnerability in HP 2910-48G al Switch. Please update to W.15.14.0017.Show less
1Cpanel
1Cpanel
Nov 21, 2024
Aug 1, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
cPanel before 57.9999.54 allows self XSS during ftp account creation under addon domains (SEC-118).
1Cpanel
1Cpanel
Nov 21, 2024
Aug 1, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
cPanel before 68.0.27 allows self XSS in the WHM listips interface (SEC-389).
1Cpanel
1Cpanel
Nov 21, 2024
Aug 1, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
cPanel before 68.0.27 allows self XSS in WHM Spamd Startup Config (SEC-387).