← Back
CWE-79

46,275 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (46,275)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Otcms
1Otcms
Jun 17, 2026
Jul 19, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
OTCMS 3.81 allows XSS via the mode parameter in an apiRun.php?mudi=autoRun request.
1Antsword Project
1Antsword
Jun 17, 2026
Jul 19, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In antSword before 2.1.0, self-XSS in the database configuration leads to code execution via modules/database/asp/index.js, modules/database/custom/index.js, modules/database/index.js, or modules/database/php/index.js.
1Adobe
1Experience Manager
Jun 17, 2026
Jul 18, 2019
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
Adobe Experience Manager version 6.4 and ealier have a Reflected Cross-site Scripting vulnerability. Successful exploitation could lead to Sensitive Information disclosure in the context of the current user.
1Adobe
1Experience Manager
Jun 17, 2026
Jul 18, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Adobe Experience Manager version 6.4 and ealier have a Stored Cross-site Scripting vulnerability. Successful exploitation could lead to Sensitive Information disclosure in the context of the current user.
1Gitea
1Gitea
Jun 17, 2026
Jul 18, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Gitea 1.7.0 and earlier is affected by: Cross Site Scripting (XSS). The impact is: Attacker is able to have victim execute arbitrary JS in browser. The component is: go-get URL generation - PR to fix: https://github.com/...Show more
Gitea 1.7.0 and earlier is affected by: Cross Site Scripting (XSS). The impact is: Attacker is able to have victim execute arbitrary JS in browser. The component is: go-get URL generation - PR to fix: https://github.com/go-gitea/gitea/pull/5905. The attack vector is: victim must open a specifically crafted URL. The fixed version is: 1.7.1 and later.Show less
1Syguestbook A5 Project
1Syguestbook A5
Jun 17, 2026
Jul 18, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
index.php?c=admin&a=index in SyGuestBook A5 Version 1.2 has stored XSS via a reply to a comment.
1Syguestbook A5 Project
1Syguestbook A5
Jun 17, 2026
Jul 18, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
SyGuestBook A5 Version 1.2 allows stored XSS because the isValidData function in include/functions.php does not properly block XSS payloads, as demonstrated by a crafted use of the onerror attribute of an IMG element.
1Audiocodes
4Mediant 500 Mbsr Firmware
Mediant 500l Msbr FirmwareMediant 800c Msbr Firmware+1 more
Jun 17, 2026
Jul 18, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered on AudioCodes Mediant 500L-MSBR, 500-MBSR, M800B-MSBR and 800C-MSBR devices with firmware versions F7.20A to F7.20A.253. A cross-site scripting (XSS) vulnerability in the search function of the ma...Show more
An issue was discovered on AudioCodes Mediant 500L-MSBR, 500-MBSR, M800B-MSBR and 800C-MSBR devices with firmware versions F7.20A to F7.20A.253. A cross-site scripting (XSS) vulnerability in the search function of the management web interface allows remote attackers to inject arbitrary web script or HTML via the keyword parameter.Show less
1Opera
1Mini
Jun 17, 2026
Jul 18, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Opera Mini application through 16.0.14 for iOS has a UXSS vulnerability that can be triggered by performing navigation to a javascript: URL.
1Automattic
1Camptix Event Ticketing
Nov 21, 2024
Jul 18, 2019
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The CampTix Event Ticketing plugin before 1.5 for WordPress allows XSS in the admin section via a ticket title or body.
1Firefly Iii
1Firefly Iii
Jun 17, 2026
Jul 18, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Firefly III before 4.7.17.3 is vulnerable to stored XSS due to lack of filtration of user-supplied data in image file content. The JavaScript code is executed during attachments/view/$file_id$ attachment viewing. NOTE: I...Show more
Firefly III before 4.7.17.3 is vulnerable to stored XSS due to lack of filtration of user-supplied data in image file content. The JavaScript code is executed during attachments/view/$file_id$ attachment viewing. NOTE: It is asserted that an attacker must have the same access rights as the user in order to be able to execute the vulnerabilityShow less
1Firefly Iii
1Firefly Iii
Jun 17, 2026
Jul 18, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Firefly III before 4.7.17.3 is vulnerable to reflected XSS due to lack of filtration of user-supplied data in a search query. NOTE: It is asserted that an attacker must have the same access rights as the user in order to...Show more
Firefly III before 4.7.17.3 is vulnerable to reflected XSS due to lack of filtration of user-supplied data in a search query. NOTE: It is asserted that an attacker must have the same access rights as the user in order to be able to execute the vulnerabilityShow less
1Firefly Iii
1Firefly Iii
Jun 17, 2026
Jul 18, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Firefly III before 4.7.17.3 is vulnerable to stored XSS due to lack of filtration of user-supplied data in image file names. The JavaScript code is executed during attachments/edit/$file_id$ attachment editing. NOTE: It...Show more
Firefly III before 4.7.17.3 is vulnerable to stored XSS due to lack of filtration of user-supplied data in image file names. The JavaScript code is executed during attachments/edit/$file_id$ attachment editing. NOTE: It is asserted that an attacker must have the same access rights as the user in order to be able to execute the vulnerabilityShow less
1Firefly Iii
1Firefly Iii
Jun 17, 2026
Jul 18, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Firefly III before 4.7.17.1 is vulnerable to stored XSS due to lack of filtration of user-supplied data in a budget name. The JavaScript code is contained in a transaction, and is executed on the tags/show/$tag_number$ t...Show more
Firefly III before 4.7.17.1 is vulnerable to stored XSS due to lack of filtration of user-supplied data in a budget name. The JavaScript code is contained in a transaction, and is executed on the tags/show/$tag_number$ tag summary page. NOTE: It is asserted that an attacker must have the same access rights as the user in order to be able to execute the vulnerabilityShow less
1Espocrm
1Espocrm
Jun 17, 2026
Jul 18, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Stored XSS in EspoCRM before 5.6.4 allows remote attackers to execute malicious JavaScript and inject arbitrary source code into the target pages. The attack begins by storing a new stream message containing an XSS paylo...Show more
Stored XSS in EspoCRM before 5.6.4 allows remote attackers to execute malicious JavaScript and inject arbitrary source code into the target pages. The attack begins by storing a new stream message containing an XSS payload. The stored payload can then be triggered by clicking a malicious link on the Notifications page.Show less
1Cisco
1Identity Services Engine
Jun 17, 2026
Jul 17, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based...Show more
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. The vulnerability exists because the web-based management interface does not properly validate user-supplied input. An attacker could exploit this vulnerability by persuading a user to click a malicious link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information. At the time of publication, this vulnerability affected Cisco ISE running software releases prior to 2.4.0 Patch 9 and 2.6.0.Show less
1Timesheet Next Gen Project
1Timesheet Next Gen
Jun 17, 2026
Jul 17, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Timesheet Next Gen 1.5.3 and earlier is affected by: Cross Site Scripting (XSS). The impact is: Allows an attacker to execute arbitrary HTML and JavaScript code via a "redirect" parameter. The component is: Web login for...Show more
Timesheet Next Gen 1.5.3 and earlier is affected by: Cross Site Scripting (XSS). The impact is: Allows an attacker to execute arbitrary HTML and JavaScript code via a "redirect" parameter. The component is: Web login form: login.php, lines 40 and 54. The attack vector is: reflected XSS, victim may click the malicious url.Show less
1Sitecore
1Experience Platform
Jun 17, 2026
Jul 17, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
In Sitecore 9.0 rev 171002, Persistent XSS exists in the Media Library and File Manager. An authenticated unprivileged user can modify the uploaded file extension parameter to inject arbitrary JavaScript.
1Sertek
1Xpare
Jun 17, 2026
Jul 17, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in Sertek Xpare 3.67. The login form does not sanitize input data. Because of this, a malicious agent could exploit the vulnerable function in order to prepare an XSS payload to send to the produc...Show more
An issue was discovered in Sertek Xpare 3.67. The login form does not sanitize input data. Because of this, a malicious agent could exploit the vulnerable function in order to prepare an XSS payload to send to the product's clients.Show less
1Myt Project
1Myt
Jun 17, 2026
Jul 17, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In MyT 1.5.1, the User[username] parameter has XSS.