← Back
CWE-79

46,279 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (46,279)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Mcafee
1Data Loss Prevention Endpoint
Jun 17, 2026
Jul 24, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in ePO extension in McAfee Data Loss Prevention (DLPe) for Windows 11.x prior to 11.3.0 allows unauthenticated remote user to trigger s...Show more
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in ePO extension in McAfee Data Loss Prevention (DLPe) for Windows 11.x prior to 11.3.0 allows unauthenticated remote user to trigger specially crafted JavaScript to render in the ePO UI via a carefully crafted upload to a remote website which is correctly blocked by DLPe Web Protection. This would then render as an XSS when the DLP Admin viewed the event in the ePO UI.Show less
1Hisiphp
1Hisiphp
Jun 17, 2026
Jul 24, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
hisiphp 1.0.8 is affected by: Cross Site Scripting (XSS).
1Servicestack
1Servicestack
Jun 17, 2026
Jul 23, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
ServiceStack ServiceStack Framework 4.5.14 is affected by: Cross Site Scripting (XSS). The impact is: JavaScrpit is reflected in the server response, hence executed by the browser. The component is: the query used in the...Show more
ServiceStack ServiceStack Framework 4.5.14 is affected by: Cross Site Scripting (XSS). The impact is: JavaScrpit is reflected in the server response, hence executed by the browser. The component is: the query used in the GET request is prone. The attack vector is: Since there is no server-side validation and If Browser encoding is bypassed, the victim is affected when opening a crafted URL. The fixed version is: 5.2.0.Show less
1Sir
1Gnuboard
Nov 21, 2024
Jul 23, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
GNUBOARD5 5.3.1.9 has XSS that allows remote attackers to inject arbitrary web script or HTML via the "mobile board tail contents" parameter, aka the adm/board_form_update.php bo_mobile_content_tail parameter.
1Sir
1Gnuboard
Nov 21, 2024
Jul 23, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
GNUBOARD5 5.3.1.9 has XSS that allows remote attackers to inject arbitrary web script or HTML via the "mobile board title contents" parameter, aka the adm/board_form_update.php bo_mobile_subject parameter.
1Sir
1Gnuboard
Nov 21, 2024
Jul 23, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
GNUBOARD5 5.3.1.9 has XSS that allows remote attackers to inject arbitrary web script or HTML via the "board head contents" parameter, aka the adm/board_form_update.php bo_content_head parameter.
1Sir
1Gnuboard
Nov 21, 2024
Jul 23, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
GNUBOARD5 5.3.1.9 has XSS that allows remote attackers to inject arbitrary web script or HTML via the "Extra Contents" parameter, aka the adm/config_form_update.php cf_1~10 parameter.
1Sir
1Gnuboard
Nov 21, 2024
Jul 23, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
GNUBOARD5 5.3.1.9 has XSS that allows remote attackers to inject arbitrary web script or HTML via the "Menu Link" parameter, aka the adm/menu_list_update.php me_link parameter.
1Sir
1Gnuboard
Nov 21, 2024
Jul 23, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
GNUBOARD5 5.3.1.9 has XSS that allows remote attackers to inject arbitrary web script or HTML via the "mobile board head contents" parameter, aka the adm/board_form_update.php bo_mobile_content_head parameter.
1Sir
1Gnuboard
Nov 21, 2024
Jul 23, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
GNUBOARD5 5.3.1.9 has XSS that allows remote attackers to inject arbitrary web script or HTML via the "board title contents" parameter, aka the adm/board_form_update.php bo_subject parameter.
2Mozilla
Opensuse
2Firefox
Leap
Jun 17, 2026
Jul 23, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Some unicode characters are incorrectly treated as whitespace during the parsing of web content instead of triggering parsing errors. This allows malicious code to then be processed, evading cross-site scripting (XSS) fi...Show more
Some unicode characters are incorrectly treated as whitespace during the parsing of web content instead of triggering parsing errors. This allows malicious code to then be processed, evading cross-site scripting (XSS) filtering. This vulnerability affects Firefox < 68.Show less
1Mozilla
2Firefox
Thunderbird
Jun 17, 2026
Jul 23, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Due to an error while parsing page content, it is possible for properly sanitized user input to be misinterpreted and lead to XSS hazards on web sites in certain circumstances. This vulnerability affects Firefox ESR < 60...Show more
Due to an error while parsing page content, it is possible for properly sanitized user input to be misinterpreted and lead to XSS hazards on web sites in certain circumstances. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.Show less
1Mozilla
1Firefox
Jun 17, 2026
Jul 23, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The default webcal: protocol handler will load a web site vulnerable to cross-site scripting (XSS) attacks. This default was left in place as a legacy feature and has now been removed. *Note: this issue only affects user...Show more
The default webcal: protocol handler will load a web site vulnerable to cross-site scripting (XSS) attacks. This default was left in place as a legacy feature and has now been removed. *Note: this issue only affects users with an account on the vulnerable service. Other users are unaffected.*. This vulnerability affects Firefox < 67.Show less
1Genetechsolutions
1Pie Register
Jun 17, 2026
Jul 23, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Genetechsolutions Pie Register 3.0.15 is affected by: Cross Site Scripting (XSS). The impact is: Stealing of session cookies. The component is: File: Login. Parameters: interim-login, wp-lang, and supplied URL. The attac...Show more
Genetechsolutions Pie Register 3.0.15 is affected by: Cross Site Scripting (XSS). The impact is: Stealing of session cookies. The component is: File: Login. Parameters: interim-login, wp-lang, and supplied URL. The attack vector is: If a victim clicks a malicious link, the attacker can steal his/her account. The fixed version is: 3.0.16.Show less
1Webappick
1Woocommerce Product Feed
Jun 17, 2026
Jul 23, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
WebAppick WooCommerce Product Feed 2.2.18 and earlier is affected by: Cross Site Scripting (XSS). The impact is: XSS to RCE via editing theme files in WordPress. The component is: admin/partials/woo-feed-manage-list.php:...Show more
WebAppick WooCommerce Product Feed 2.2.18 and earlier is affected by: Cross Site Scripting (XSS). The impact is: XSS to RCE via editing theme files in WordPress. The component is: admin/partials/woo-feed-manage-list.php:63. The attack vector is: Administrator must be logged in.Show less
1Zte
1Otcp Firmware
Jun 17, 2026
Jul 22, 2019
N/A· v4
4.8 MEDIUM· v3
2.3 LOW· v2
All versions up to V1.19.20.02 of ZTE OTCP product are impacted by XSS vulnerability. Due to XSS, when an attacker invokes the security management to obtain the resources of the specified operation code owned by a user,...Show more
All versions up to V1.19.20.02 of ZTE OTCP product are impacted by XSS vulnerability. Due to XSS, when an attacker invokes the security management to obtain the resources of the specified operation code owned by a user, the malicious script code could be transmitted in the parameter. If the front end does not process the returned result from the interface properly, the malicious script may be executed and the user cookie or other important information may be stolen.Show less
1Ilias
1Ilias
Jun 17, 2026
Jul 22, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Ilias 5.3 before 5.3.12; 5.2 before 5.2.21 is affected by: Cross Site Scripting (XSS) - CWE-79 Type 2: Stored XSS (or Persistent). The impact is: Execute code in the victim's browser. The component is: Assessment / TestQ...Show more
Ilias 5.3 before 5.3.12; 5.2 before 5.2.21 is affected by: Cross Site Scripting (XSS) - CWE-79 Type 2: Stored XSS (or Persistent). The impact is: Execute code in the victim's browser. The component is: Assessment / TestQuestionPool. The attack vector is: Cloze Test Text gap (attacker) / Corrections view (victim). The fixed version is: 5.3.12.Show less
1Frog Cms Project
1Frog Cms
Jun 17, 2026
Jul 22, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Frog CMS 1.1 is affected by: Cross Site Scripting (XSS). The impact is: Cookie stealing, Alert pop-up on page, Redirecting to another phishing site, Executing browser exploits. The component is: Snippets.
1Wp Code Highlightjs Project
1Wp Code Highlightjs
Jun 17, 2026
Jul 20, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
An issue was discovered in the wp-code-highlightjs plugin through 0.6.2 for WordPress. wp-admin/options-general.php?page=wp-code-highlight-js allows CSRF, as demonstrated by an XSS payload in the hljs_additional_css para...Show more
An issue was discovered in the wp-code-highlightjs plugin through 0.6.2 for WordPress. wp-admin/options-general.php?page=wp-code-highlight-js allows CSRF, as demonstrated by an XSS payload in the hljs_additional_css parameter.Show less
1Microstrategy
1Microstrategy Web
Jun 17, 2026
Jul 19, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In MicroStrategy Web before 10.1 patch 10, stored XSS is possible in the FLTB parameter due to missing input validation.