CWE-79
46,279 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (46,279)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
cPanel before 71.9980.37 allows Remote-Stored XSS in WHM Save Theme Interface (SEC-400). |
cPanel before 11.54.0.4 allows self XSS in the X3 Entropy Banner interface (SEC-87). |
cPanel before 11.54.0.4 allows stored XSS in the WHM Feature Manager interface (SEC-86). |
cPanel before 11.54.0.4 allows self XSS in the WHM PHP Configuration editor interface (SEC-84). |
Windu CMS 2.2 allows XSS via the name parameter to admin/content/edit or admin/content/add, or the username parameter to admin/users. |
cPanel before 71.9980.37 allows stored XSS in the YUM autorepair functionality (SEC-399). |
cPanel before 71.9980.37 allows stored XSS in the WHM cPAddons installation interface (SEC-398). |
1Dlink 26600 Ap Firmware Dwl 3600ap FirmwareJun 17, 2026 Aug 1, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered on D-Link 6600-AP and DWL-3600AP Ax 4.2.0.14 21/03/2019 devices. There is a post-authentication admin.cgi?action= XSS vulnerability on the management interface. |
cPanel before 74.0.0 allows stored XSS in the WHM File Restoration interface (SEC-367). |
cPanel before 74.0.8 allows self stored XSS on the Security Questions login page (SEC-446). |
cPanel before 74.0.8 allows stored XSS in WHM "File and Directory Restoration" interface (SEC-441). |
cPanel before 74.0.8 allows self XSS in WHM Style Upload interface (SEC-437). |
cPanel before 74.0.8 allows self XSS in the Site Software Moderation interface (SEC-434). |
cPanel before 74.0.8 allows self XSS in the WHM Security Questions interface (SEC-433). |
cPanel before 74.0.8 allows self XSS in the WHM "Create a New Account" interface (SEC-428). |
A Cross-Site Scripting (XSS) vulnerability in the Web UI of Avaya Aura Conferencing may allow code execution and potentially disclose sensitive information. Affected versions of Avaya Aura Conferencing include all 8.x ve...Show more |
Opengear console server firmware releases prior to 4.5.0 have a stored XSS vulnerability related to serial port logging. If a malicious user of an external system (connected to a serial port on an Opengear console server...Show more |
Insufficient output sanitization in WallacePOS 1.4.3 allows a remote, authenticated attacker to conduct persistent cross-site scripting (XSS) attacks via a crafted sales transaction. |
A stored cross site scripting vulnerability in Jenkins Maven Release Plugin 0.14.0 and earlier allowed attackers to inject arbitrary HTML and JavaScript in the plugin-provided web pages in Jenkins. |
1Http File Server Project 1Http File Server Jun 17, 2026 Jul 30, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 Cross-site scripting (XSS) vulnerability in http-file-server (all versions) allows an attacker with access to the server file system to execute arbitrary JavaScript code in victim's browser. |