← Back
CWE-79

46,279 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (46,279)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Min Http Server Project
1Min Http Server
Jun 17, 2026
Jul 30, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-site scripting (XSS) vulnerability in min-http-server (all versions) allows an attacker with access to the server file system to execute arbitrary JavaScript code in victim's browser.
1Nextcloud
1Nextcloud
Jun 17, 2026
Jul 30, 2019
N/A· v4
6.8 MEDIUM· v3
4.6 MEDIUM· v2
Improper sanitization of HTML in directory names in the Nextcloud Android app prior to version 3.7.0 allowed to style the directory name in the header bar when using basic HTML.
1Edx
1Edx Platform
Nov 21, 2024
Jul 30, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
edx-platform before 2018-07-18 allows XSS via a response to a Chemical Equation advanced problem.
1Cpanel
1Cpanel
Jun 17, 2026
Jul 30, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
cPanel before 78.0.18 has stored XSS in the BoxTrapper Queue Listing (SEC-493).
1Cpanel
1Cpanel
Nov 21, 2024
Jul 30, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
cPanel before 76.0.8 has Stored XSS in the WHM MultiPHP Manager interface (SEC-464).
1Cpanel
1Cpanel
Nov 21, 2024
Jul 30, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
cPanel before 76.0.8 has Stored XSS in the WHM "Reset a DNS Zone" feature (SEC-461).
1Cpanel
1Cpanel
Nov 21, 2024
Jul 30, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
cPanel before 76.0.8 has Self XSS in the WHM Additional Backup Destination field (SEC-459).
1Cpanel
1Cpanel
Jun 17, 2026
Jul 30, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
cPanel before 82.0.2 has stored XSS in the WHM Modify Account interface (SEC-512).
1Cpanel
1Cpanel
Jun 17, 2026
Jul 30, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
cPanel before 82.0.2 has Self XSS in the cPanel and webmail master templates (SEC-506).
1Cpanel
1Cpanel
Jun 17, 2026
Jul 30, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
cPanel before 82.0.2 has stored XSS in the WHM Tomcat Manager interface (SEC-504).
1Planonsoftware
1Planon
Nov 21, 2024
Jul 29, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Planon before Live Build 41 has XSS.
1Veritas
1Resiliency Platform
Jun 17, 2026
Jul 29, 2019
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
An issue was discovered in Veritas Resiliency Platform (VRP) before 3.4 HF1. A persistent cross-site scripting (XSS) vulnerability allows a malicious VRP user to inject malicious script into another user's browser, relat...Show more
An issue was discovered in Veritas Resiliency Platform (VRP) before 3.4 HF1. A persistent cross-site scripting (XSS) vulnerability allows a malicious VRP user to inject malicious script into another user's browser, related to resiliency plans functionality. A victim must open a resiliency plan that an attacker has access to.Show less
1Dolibarr
1Dolibarr Erp/crm
Jun 17, 2026
Jul 29, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Dolibarr ERP/CRM 9.0.1 was affected by stored XSS within uploaded files. These vulnerabilities allowed the execution of a JavaScript payload each time any regular user or administrative user clicked on the malicious link...Show more
Dolibarr ERP/CRM 9.0.1 was affected by stored XSS within uploaded files. These vulnerabilities allowed the execution of a JavaScript payload each time any regular user or administrative user clicked on the malicious link hosted on the same domain. The vulnerabilities could be exploited by low privileged users to target administrators. The viewimage.php page did not perform any contextual output encoding and would display the content within the uploaded file with a user-requested MIME type.Show less
1Edx
1Edx Platform
Nov 21, 2024
Jul 29, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
edx-platform before 2015-09-17 allows XSS via a team name.
1Edx
1Edx Platform
Nov 21, 2024
Jul 29, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
edx-platform before 2015-08-17 allows XSS in the Studio listing of courses.
1Stacktable.js Project
1Stacktable.js
Jun 17, 2026
Jul 29, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
stacktable.js before 1.0.4 allows XSS.
1Owasp
1Dependency Track
Jun 17, 2026
Jul 29, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Dependency-Track before 3.5.1 allows XSS.
1Inveniosoftware
1Invenio Communities
Jun 17, 2026
Jul 29, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
invenio-communities before 1.0.0a20 allows XSS.
1Inveniosoftware
1Invenio Records
Jun 17, 2026
Jul 29, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
invenio-records before 1.2.2 allows XSS.
1Microsoft
1Outlook
Jun 17, 2026
Jul 29, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A spoofing vulnerability exists in the way Microsoft Outlook for Android software parses specifically crafted email messages. An authenticated attacker could exploit the vulnerability by sending a specially crafted email...Show more
A spoofing vulnerability exists in the way Microsoft Outlook for Android software parses specifically crafted email messages. An authenticated attacker could exploit the vulnerability by sending a specially crafted email message to a victim. The attacker who successfully exploited this vulnerability could then perform cross-site scripting attacks on the affected systems and run scripts in the security context of the current user. The security update addresses the vulnerability by correcting how Outlook for Android parses specially crafted email messages.Show less