← Back
CWE-79

46,279 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (46,279)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Inveniosoftware
1Invenio Previewer
Jun 17, 2026
Jul 29, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
invenio-previewer before 1.0.0a12 allows XSS.
1Misskey
1Misskey
Jun 17, 2026
Jul 29, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Misskey before 10.102.4 allows hijacking a user's token.
1Icegram
1Email Subscribers & Newsletters
Jun 17, 2026
Jul 28, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An XSS vulnerability in the "Email Subscribers & Newsletters" plugin 4.1.6 for WordPress allows an attacker to inject malicious JavaScript code through a publicly available subscription form using the esfpx_name wp-admin...Show more
An XSS vulnerability in the "Email Subscribers & Newsletters" plugin 4.1.6 for WordPress allows an attacker to inject malicious JavaScript code through a publicly available subscription form using the esfpx_name wp-admin/admin-ajax.php POST parameter.Show less
1Espocrm
1Espocrm
Jun 17, 2026
Jul 28, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
EspoCRM 5.6.4 is vulnerable to stored XSS due to lack of filtration of user-supplied data in the Knowledge base. A malicious attacker can inject JavaScript code in the body parameter during api/v1/KnowledgeBaseArticle kn...Show more
EspoCRM 5.6.4 is vulnerable to stored XSS due to lack of filtration of user-supplied data in the Knowledge base. A malicious attacker can inject JavaScript code in the body parameter during api/v1/KnowledgeBaseArticle knowledge-base record creation.Show less
1Espocrm
1Espocrm
Jun 17, 2026
Jul 28, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
EspoCRM version 5.6.4 is vulnerable to stored XSS due to lack of filtration of user-supplied data in the api/v1/Document functionality for storing documents in the account tab. An attacker can upload a crafted file that...Show more
EspoCRM version 5.6.4 is vulnerable to stored XSS due to lack of filtration of user-supplied data in the api/v1/Document functionality for storing documents in the account tab. An attacker can upload a crafted file that contains JavaScript code in its name. This code will be executed when a user opens a page of any profile with this.Show less
1Espocrm
1Espocrm
Jun 17, 2026
Jul 28, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in EspoCRM before 5.6.6. Stored XSS exists due to lack of filtration of user-supplied data in Create User. A malicious attacker can modify the firstName and lastName to contain JavaScript code.
1Espocrm
1Espocrm
Jun 17, 2026
Jul 28, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in EspoCRM before 5.6.6. Stored XSS exists due to lack of filtration of user-supplied data in Create Case. A malicious attacker can modify the firstName and lastName to contain JavaScript code.
1Espocrm
1Espocrm
Jun 17, 2026
Jul 28, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in EspoCRM before 5.6.6. There is stored XSS due to lack of filtration of user-supplied data in Create Task. A malicious attacker can modify the parameter name to contain JavaScript code.
1Sunhater
1Kcfinder
Jun 17, 2026
Jul 28, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A cross-site scripting (XSS) vulnerability in upload.php in SunHater KCFinder 3.20-test1, 3.20-test2, 3.12, and earlier allows remote attackers to inject arbitrary web script or HTML via the CKEditorFuncNum parameter.
1Veeam
1One Reporter
Jun 17, 2026
Jul 27, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Veeam ONE Reporter 9.5.0.3201 allows XSS via a crafted Description(config) field to addDashboard or editDashboard in CommonDataHandlerReadOnly.ashx.
1Veeam
1One Reporter
Jun 17, 2026
Jul 27, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Veeam ONE Reporter 9.5.0.3201 allows XSS via the Add/Edit Widget with a crafted Caption field to setDashboardWidget in CommonDataHandlerReadOnly.ashx.
2Misp
Misp Project
2Misp
Misp
Jun 22, 2026
Jul 27, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In app/webroot/js/event-graph.js in MISP 2.4.111, a stored XSS vulnerability exists in the event-graph view when a user toggles the event graph view. A malicious MISP event must be crafted in order to trigger the vulnera...Show more
In app/webroot/js/event-graph.js in MISP 2.4.111, a stored XSS vulnerability exists in the event-graph view when a user toggles the event graph view. A malicious MISP event must be crafted in order to trigger the vulnerability.Show less
1Wikindx Project
1Wikindx
Jun 17, 2026
Jul 26, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A cross-site scripting (XSS) vulnerability in getPagingStart() in core/lists/PAGING.php in WIKINDX before 5.8.2 allows remote attackers to inject arbitrary web script or HTML via the PagingStart parameter.
1Ahsay
1Cloud Backup Suite
Jun 17, 2026
Jul 26, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in Ahsay Cloud Backup Suite before 8.1.1.50. When creating a trial account, it is possible to inject XSS in the Alias field, allowing the attacker to retrieve the admin's cookie and take over the...Show more
An issue was discovered in Ahsay Cloud Backup Suite before 8.1.1.50. When creating a trial account, it is possible to inject XSS in the Alias field, allowing the attacker to retrieve the admin's cookie and take over the account.Show less
1Central Dogma Project
1Central Dogma
Jun 17, 2026
Jul 26, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting vulnerability in Central Dogma 0.17.0 to 0.40.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
1Angry Frog
1Xavier
Jun 17, 2026
Jul 26, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Xavier PHP Management Panel 3.0 is vulnerable to Reflected POST-based XSS via the username parameter when registering a new user at admin/includes/adminprocess.php. If there is an error when registering the user, the uns...Show more
Xavier PHP Management Panel 3.0 is vulnerable to Reflected POST-based XSS via the username parameter when registering a new user at admin/includes/adminprocess.php. If there is an error when registering the user, the unsanitized username will reflect via the error page. Due to the lack of CSRF protection on the admin/includes/adminprocess.php endpoint, an attacker is able to chain the XSS with CSRF in order to cause remote exploitation.Show less
1Control Webpanel
1Webpanel
Jun 17, 2026
Jul 26, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.846, Reflected XSS in filemanager2.php (parameter fm_current_dir) allows attackers to steal a cookie or session, or redirect to a phishing website.
2Bmc
Yellowfinbi
2Remedy Smart Reporting
Yellowfin Bi
Jun 17, 2026
Jul 26, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Yellowfin Smart Reporting All Versions Prior to 7.3 is affected by: Incorrect Access Control - Privileges Escalation. The impact is: Victim attacked and access admin functionality through their browser and control browse...Show more
Yellowfin Smart Reporting All Versions Prior to 7.3 is affected by: Incorrect Access Control - Privileges Escalation. The impact is: Victim attacked and access admin functionality through their browser and control browser. The component is: MIAdminStyles.i4. The attack vector is: Victims are typically lured to a web site under the attacker's control; the XSS vulnerability on the target domain is silently exploited without the victim's knowledge. The fixed version is: 7.4 and later.Show less
1Hp
1Arcsight Management Center
Jun 17, 2026
Jul 25, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Mitigates a stored cross site scripting issue in ArcSight Security Management Center versions prior to 2.9.1
1Hp
1Arcsight Logger
Jun 17, 2026
Jul 24, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Mitigates a stored cross site scripting issue in ArcSight Logger versions prior to 6.7.1