CWE-79
46,280 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (46,280)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
cPanel before 68.0.27 allows self stored XSS in WHM Account Transfer (SEC-386). |
cPanel before 68.0.27 allows self XSS in WHM Apache Configuration Include Editor (SEC-385). |
cPanel before 68.0.27 allows self XSS in cPanel Backup Restoration (SEC-383). |
cPanel before 55.9999.141 allows self stored XSS in WHM Edit System Mail Preferences (SEC-96). |
cPanel before 55.9999.141 allows self XSS in X3 Reseller Branding Images (SEC-88). |
cPanel before 70.0.23 allows stored XSS in via a WHM "Reset a DNS Zone" action (SEC-412). |
cPanel before 70.0.23 has Stored XSS via an WHM Edit DNS Zone action (SEC-410). |
cPanel before 70.0.23 allows stored XSS via the cpaddons vendor interface (SEC-391). |
Zurmo 3.2.7-2 has XSS via the app/index.php/zurmo/default PATH_INFO. |
TestLink 1.9.19 has XSS via the error.php message parameter. |
cPanel before 70.0.23 allows stored XSS via a WHM Synchronize DNS Records action (SEC-377). |
cPanel before 70.0.23 allows stored XSS via a WHM DNS Cleanup action (SEC-376). |
cPanel before 70.0.23 allows stored XSS via a WHM "Delete a DNS Zone" action (SEC-375). |
cPanel before 70.0.23 allows stored XSS via a WHM Edit DNS Zone action (SEC-374). |
cPanel before 70.0.23 allows stored XSS via a WHM Create Account action (SEC-373). |
cPanel before 70.0.23 allows stored XSS in WHM DNS Cluster (SEC-372). |
cPanel before 70.0.23 allows Stored XSS via a WHM Edit MX Entry (SEC-370). |
cPanel before 70.0.23 allows stored XSS via a WHM Edit DNS Zone action (SEC-369). |
cPanel before 70.0.23 allows code execution because "." is in @INC during a Perl syntax check of cpaddonsup (SEC-359). |
cPanel before 70.0.23 allows self XSS in the WHM cPAddons showsecurity Interface (SEC-357). |