CWE-79
46,275 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (46,275)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Microstrategy 1Microstrategy Web Jun 17, 2026 Jul 17, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 In MicroStrategy Web before 10.4.6, there is stored XSS in metric due to insufficient input validation. |
tinymce 4.7.11, 4.7.12 is affected by: CWE-79: Improper Neutralization of Input During Web Page Generation. The impact is: JavaScript code execution. The component is: Media element. The attack vector is: The victim must...Show more |
1Ibm 1Qradar Security Information And Event Manager Jun 17, 2026 Jul 17, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 IBM QRadar SIEM 7.2 and 7.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credenti...Show more |
1Ibm 1Qradar Security Information And Event Manager Nov 21, 2024 Jul 17, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 IBM QRadar SIEM 7.2 and 7.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credenti...Show more |
IBM Campaign 9.1.0, 9.1.2, 10.1, and 11.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leadi...Show more |
In HT2 Labs Learning Locker 3.15.1, it's possible to inject malicious HTML and JavaScript code into the DOM of the website via the PATH_INFO to the dashboards/ URI. |
Zammad GmbH Zammad 2.3.0 and earlier is affected by: Cross Site Scripting (XSS) - CWE-80. The impact is: Execute java script code on users browser. The component is: web app. The attack vector is: the victim must open a...Show more |
A Reflected Cross-site Scripting (XSS) vulnerability exists in Apache Roller. Roller's Math Comment Authenticator did not property sanitize user input and could be exploited to perform Reflected Cross Site Scripting (XSS...Show more |
A cross-site-scripting (XSS) vulnerability exists when Microsoft Exchange Server does not properly sanitize a specially crafted web request to an affected Exchange server, aka 'Microsoft Exchange Server Spoofing Vulnerab...Show more |
1Microsoft 2Sharepoint Enterprise Server Sharepoint ServerJun 17, 2026 Jul 15, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office SharePoint XSS Vulnera...Show more |
1Microsoft 2Azure Devops Server Team Foundation ServerJun 17, 2026 Jul 15, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 A Cross-site Scripting (XSS) vulnerability exists when Team Foundation Server does not properly sanitize user provided input, aka 'Team Foundation Server Cross-site Scripting Vulnerability'. |
GLPI GLPI Product 9.3.1 is affected by: Cross Site Scripting (XSS). The impact is: All dropdown values are vulnerable to XSS leading to privilege escalation and executing js on admin. The component is: /glpi/ajax/getDrop...Show more |
1School College Portal With Erp Script Project 1School College Portal With Erp Script Jun 17, 2026 Jul 15, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 phpscriptsmall.com School College Portal with ERP Script 2.6.1 and earlier is affected by: Cross Site Scripting (XSS). The impact is: Attack administrators and teachers, students and more. The component is: /pro-school/i...Show more |
1Dolibarr 1Dolibarr Erp/crm Jun 17, 2026 Jul 15, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Dolibarr 6.0.4 is affected by: Cross Site Scripting (XSS). The impact is: Cookie stealing. The component is: htdocs/product/stats/card.php. The attack vector is: Victim must click a specially crafted link sent by the att...Show more |
OpenEnergyMonitor Project Emoncms 9.8.8 is affected by: Cross Site Scripting (XSS). The impact is: Theoretically low, but might potentially enable persistent XSS (user could embed mal. code). The component is: Javascript...Show more |
1Hexoeditor Project 1Hexoeditor Jun 17, 2026 Jul 15, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 HexoEditor v1.1.8-beta is affected by: XSS to code execution. |
1Siemens 4Spectrum Power 3 Spectrum Power 4Spectrum Power 5+1 moreJun 17, 2026 Jul 11, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 A vulnerability has been identified in Spectrum Power 3 (Corporate User Interface) (All versions <= v3.11), Spectrum Power 4 (Corporate User Interface) (Version v4.75), Spectrum Power 5 (Corporate User Interface) (All ve...Show more |
Gitea 1.7.2, 1.7.3 is affected by: Cross Site Scripting (XSS). The impact is: execute JavaScript in victim's browser, when the vulnerable repo page is loaded. The component is: repository's description. The attack vector...Show more |
1Redhat 1Openshift Container Platform Jun 17, 2026 Jul 11, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 A reflected XSS vulnerability exists in authorization flow of OpenShift Container Platform versions: openshift-online-3, openshift-enterprise-3.4 through 3.7 and openshift-enterprise-3.9 through 3.11. An attacker could u...Show more |
Multiple stored Cross-site scripting (XSS) issues in the admin panel and survey system in REDCap 8 before 8.10.20 and 9 before 9.1.2 allow an attacker to inject arbitrary malicious HTML or JavaScript code into a user's w...Show more |