CWE-79
46,279 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (46,279)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Min Http Server Project 1Min Http Server Jun 17, 2026 Jul 30, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 Cross-site scripting (XSS) vulnerability in min-http-server (all versions) allows an attacker with access to the server file system to execute arbitrary JavaScript code in victim's browser. |
Improper sanitization of HTML in directory names in the Nextcloud Android app prior to version 3.7.0 allowed to style the directory name in the header bar when using basic HTML. |
edx-platform before 2018-07-18 allows XSS via a response to a Chemical Equation advanced problem. |
cPanel before 78.0.18 has stored XSS in the BoxTrapper Queue Listing (SEC-493). |
cPanel before 76.0.8 has Stored XSS in the WHM MultiPHP Manager interface (SEC-464). |
cPanel before 76.0.8 has Stored XSS in the WHM "Reset a DNS Zone" feature (SEC-461). |
cPanel before 76.0.8 has Self XSS in the WHM Additional Backup Destination field (SEC-459). |
cPanel before 82.0.2 has stored XSS in the WHM Modify Account interface (SEC-512). |
cPanel before 82.0.2 has Self XSS in the cPanel and webmail master templates (SEC-506). |
cPanel before 82.0.2 has stored XSS in the WHM Tomcat Manager interface (SEC-504). |
Planon before Live Build 41 has XSS. |
An issue was discovered in Veritas Resiliency Platform (VRP) before 3.4 HF1. A persistent cross-site scripting (XSS) vulnerability allows a malicious VRP user to inject malicious script into another user's browser, relat...Show more |
Dolibarr ERP/CRM 9.0.1 was affected by stored XSS within uploaded files. These vulnerabilities allowed the execution of a JavaScript payload each time any regular user or administrative user clicked on the malicious link...Show more |
edx-platform before 2015-09-17 allows XSS via a team name. |
edx-platform before 2015-08-17 allows XSS in the Studio listing of courses. |
1Stacktable.js Project 1Stacktable.js Jun 17, 2026 Jul 29, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 stacktable.js before 1.0.4 allows XSS. |
Dependency-Track before 3.5.1 allows XSS. |
1Inveniosoftware 1Invenio Communities Jun 17, 2026 Jul 29, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 invenio-communities before 1.0.0a20 allows XSS. |
1Inveniosoftware 1Invenio Records Jun 17, 2026 Jul 29, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 invenio-records before 1.2.2 allows XSS. |
A spoofing vulnerability exists in the way Microsoft Outlook for Android software parses specifically crafted email messages. An authenticated attacker could exploit the vulnerability by sending a specially crafted email...Show more |