← Back
CWE-79

46,275 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (46,275)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Microstrategy
1Microstrategy Web
Jun 17, 2026
Jul 17, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In MicroStrategy Web before 10.4.6, there is stored XSS in metric due to insufficient input validation.
1Tiny
1Tinymce
Jun 17, 2026
Jul 17, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
tinymce 4.7.11, 4.7.12 is affected by: CWE-79: Improper Neutralization of Input During Web Page Generation. The impact is: JavaScript code execution. The component is: Media element. The attack vector is: The victim must...Show more
tinymce 4.7.11, 4.7.12 is affected by: CWE-79: Improper Neutralization of Input During Web Page Generation. The impact is: JavaScript code execution. The component is: Media element. The attack vector is: The victim must paste malicious content to media element's embed tab.Show less
1Ibm
1Qradar Security Information And Event Manager
Jun 17, 2026
Jul 17, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM QRadar SIEM 7.2 and 7.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credenti...Show more
IBM QRadar SIEM 7.2 and 7.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 159131.Show less
1Ibm
1Qradar Security Information And Event Manager
Nov 21, 2024
Jul 17, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
IBM QRadar SIEM 7.2 and 7.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credenti...Show more
IBM QRadar SIEM 7.2 and 7.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 155345.Show less
1Ibm
1Campaign
Nov 21, 2024
Jul 17, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM Campaign 9.1.0, 9.1.2, 10.1, and 11.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leadi...Show more
IBM Campaign 9.1.0, 9.1.2, 10.1, and 11.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 152857.Show less
1Ht2labs
1Learning Locker
Jun 17, 2026
Jul 16, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In HT2 Labs Learning Locker 3.15.1, it's possible to inject malicious HTML and JavaScript code into the DOM of the website via the PATH_INFO to the dashboards/ URI.
1Zammad
1Zammad
Jun 17, 2026
Jul 16, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Zammad GmbH Zammad 2.3.0 and earlier is affected by: Cross Site Scripting (XSS) - CWE-80. The impact is: Execute java script code on users browser. The component is: web app. The attack vector is: the victim must open a...Show more
Zammad GmbH Zammad 2.3.0 and earlier is affected by: Cross Site Scripting (XSS) - CWE-80. The impact is: Execute java script code on users browser. The component is: web app. The attack vector is: the victim must open a ticket. The fixed version is: 2.3.1, 2.2.2 and 2.1.3.Show less
1Apache
1Roller
Jun 17, 2026
Jul 15, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A Reflected Cross-site Scripting (XSS) vulnerability exists in Apache Roller. Roller's Math Comment Authenticator did not property sanitize user input and could be exploited to perform Reflected Cross Site Scripting (XSS...Show more
A Reflected Cross-site Scripting (XSS) vulnerability exists in Apache Roller. Roller's Math Comment Authenticator did not property sanitize user input and could be exploited to perform Reflected Cross Site Scripting (XSS). The mitigation for this vulnerability is to upgrade to the latest version of Roller, which is now Roller 5.2.3.Show less
1Microsoft
1Exchange Server
Jun 17, 2026
Jul 15, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A cross-site-scripting (XSS) vulnerability exists when Microsoft Exchange Server does not properly sanitize a specially crafted web request to an affected Exchange server, aka 'Microsoft Exchange Server Spoofing Vulnerab...Show more
A cross-site-scripting (XSS) vulnerability exists when Microsoft Exchange Server does not properly sanitize a specially crafted web request to an affected Exchange server, aka 'Microsoft Exchange Server Spoofing Vulnerability'.Show less
1Microsoft
2Sharepoint Enterprise Server
Sharepoint Server
Jun 17, 2026
Jul 15, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office SharePoint XSS Vulnera...Show more
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office SharePoint XSS Vulnerability'.Show less
1Microsoft
2Azure Devops Server
Team Foundation Server
Jun 17, 2026
Jul 15, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A Cross-site Scripting (XSS) vulnerability exists when Team Foundation Server does not properly sanitize user provided input, aka 'Team Foundation Server Cross-site Scripting Vulnerability'.
1Glpi Project
1Glpi
Jun 17, 2026
Jul 15, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
GLPI GLPI Product 9.3.1 is affected by: Cross Site Scripting (XSS). The impact is: All dropdown values are vulnerable to XSS leading to privilege escalation and executing js on admin. The component is: /glpi/ajax/getDrop...Show more
GLPI GLPI Product 9.3.1 is affected by: Cross Site Scripting (XSS). The impact is: All dropdown values are vulnerable to XSS leading to privilege escalation and executing js on admin. The component is: /glpi/ajax/getDropDownValue.php. The attack vector is: 1- User Create a ticket , 2- Admin opens another ticket and click on the "Link Tickets" feature, 3- a request to the endpoint fetches js and executes it.Show less
1School College Portal With Erp Script Project
1School College Portal With Erp Script
Jun 17, 2026
Jul 15, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
phpscriptsmall.com School College Portal with ERP Script 2.6.1 and earlier is affected by: Cross Site Scripting (XSS). The impact is: Attack administrators and teachers, students and more. The component is: /pro-school/i...Show more
phpscriptsmall.com School College Portal with ERP Script 2.6.1 and earlier is affected by: Cross Site Scripting (XSS). The impact is: Attack administrators and teachers, students and more. The component is: /pro-school/index.php?student/message/send_reply/. The attack vector is: <img src=x onerror=alert(document.domain) />.Show less
1Dolibarr
1Dolibarr Erp/crm
Jun 17, 2026
Jul 15, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Dolibarr 6.0.4 is affected by: Cross Site Scripting (XSS). The impact is: Cookie stealing. The component is: htdocs/product/stats/card.php. The attack vector is: Victim must click a specially crafted link sent by the att...Show more
Dolibarr 6.0.4 is affected by: Cross Site Scripting (XSS). The impact is: Cookie stealing. The component is: htdocs/product/stats/card.php. The attack vector is: Victim must click a specially crafted link sent by the attacker.Show less
1Openenergymonitor
1Emoncms
Jun 17, 2026
Jul 15, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
OpenEnergyMonitor Project Emoncms 9.8.8 is affected by: Cross Site Scripting (XSS). The impact is: Theoretically low, but might potentially enable persistent XSS (user could embed mal. code). The component is: Javascript...Show more
OpenEnergyMonitor Project Emoncms 9.8.8 is affected by: Cross Site Scripting (XSS). The impact is: Theoretically low, but might potentially enable persistent XSS (user could embed mal. code). The component is: Javascript code execution in "Name", "Location", "Bio" and "Starting Page" fields in the "My Account" page. File: Lib/listjs/list.js, line 67. The attack vector is: unknown, victim must open profile page if persistent was possible.Show less
1Hexoeditor Project
1Hexoeditor
Jun 17, 2026
Jul 15, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
HexoEditor v1.1.8-beta is affected by: XSS to code execution.
1Siemens
4Spectrum Power 3
Spectrum Power 4Spectrum Power 5+1 more
Jun 17, 2026
Jul 11, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A vulnerability has been identified in Spectrum Power 3 (Corporate User Interface) (All versions <= v3.11), Spectrum Power 4 (Corporate User Interface) (Version v4.75), Spectrum Power 5 (Corporate User Interface) (All ve...Show more
A vulnerability has been identified in Spectrum Power 3 (Corporate User Interface) (All versions <= v3.11), Spectrum Power 4 (Corporate User Interface) (Version v4.75), Spectrum Power 5 (Corporate User Interface) (All versions < v5.50), Spectrum Power 7 (Corporate User Interface) (All versions <= v2.20). The web server could allow Cross-Site Scripting (XSS) attacks if unsuspecting users are tricked into accessing a malicious link. User interaction is required for a successful exploitation. The user does not need to be logged into the web interface in order for the exploitation to succeed.At the stage of publishing this security advisory no public exploitation is known.Show less
1Gitea
1Gitea
Jun 17, 2026
Jul 11, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Gitea 1.7.2, 1.7.3 is affected by: Cross Site Scripting (XSS). The impact is: execute JavaScript in victim's browser, when the vulnerable repo page is loaded. The component is: repository's description. The attack vector...Show more
Gitea 1.7.2, 1.7.3 is affected by: Cross Site Scripting (XSS). The impact is: execute JavaScript in victim's browser, when the vulnerable repo page is loaded. The component is: repository's description. The attack vector is: victim must navigate to public and affected repo page.Show less
1Redhat
1Openshift Container Platform
Jun 17, 2026
Jul 11, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A reflected XSS vulnerability exists in authorization flow of OpenShift Container Platform versions: openshift-online-3, openshift-enterprise-3.4 through 3.7 and openshift-enterprise-3.9 through 3.11. An attacker could u...Show more
A reflected XSS vulnerability exists in authorization flow of OpenShift Container Platform versions: openshift-online-3, openshift-enterprise-3.4 through 3.7 and openshift-enterprise-3.9 through 3.11. An attacker could use this flaw to steal authorization data by getting them to click on a malicious link.Show less
1Vanderbilt
1Redcap
Jun 17, 2026
Jul 11, 2019
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Multiple stored Cross-site scripting (XSS) issues in the admin panel and survey system in REDCap 8 before 8.10.20 and 9 before 9.1.2 allow an attacker to inject arbitrary malicious HTML or JavaScript code into a user's w...Show more
Multiple stored Cross-site scripting (XSS) issues in the admin panel and survey system in REDCap 8 before 8.10.20 and 9 before 9.1.2 allow an attacker to inject arbitrary malicious HTML or JavaScript code into a user's web browser.Show less