← Back
CWE-79

46,267 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (46,267)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Paypal
1Adaptive Payments Sdk
Nov 21, 2024
Jul 10, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
paypal/adaptivepayments-sdk-php v3.9.2 is vulnerable to a reflected XSS in the SetPaymentOptions.php resulting code execution
1Teclib Edition
1News
Jun 17, 2026
Jul 10, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in the Teclib News plugin through 1.5.2 for GLPI. It allows a stored XSS attack via the $_POST['name'] parameter.
1Nagios
1Nagios Xi
Nov 21, 2024
Jul 10, 2019
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Nagios XI before 5.5.4 has XSS in the auto login admin management page.
1Eventum Project
1Eventum
Nov 21, 2024
Jul 10, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in Eventum 3.5.0. /htdocs/list.php has XSS via the show_notification_list_issues or show_authorized_issues parameter.
1Eventum Project
1Eventum
Nov 21, 2024
Jul 10, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in Eventum 3.5.0. /htdocs/popup.php has XSS via the cat parameter.
1Eventum Project
1Eventum
Nov 21, 2024
Jul 10, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in Eventum 3.5.0. /htdocs/validate.php has XSS via the values parameter.
1Eventum Project
1Eventum
Nov 21, 2024
Jul 10, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in Eventum 3.5.0. htdocs/switch.php has XSS via the current_page parameter.
1Eventum Project
1Eventum
Nov 21, 2024
Jul 10, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in Eventum 3.5.0. htdocs/ajax/update.php has XSS via the field_name parameter.
1Yoast
1Yoast Seo
Jun 17, 2026
Jul 9, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The Yoast SEO plugin before 11.6-RC5 for WordPress does not properly restrict unfiltered HTML in term descriptions.
1Phpwind
1Phpwind
Jun 17, 2026
Jul 9, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
PHPWind 9.1.0 has XSS vulnerabilities in the c and m parameters of the index.php file.
1Keynto
1Team Password Manager
Jun 17, 2026
Jul 9, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
KEYNTO Team Password Manager 1.5.0 allows XSS because data saved from websites is mishandled in the online vault.
1Cyberpowersystems
1Powerpanel
Jun 17, 2026
Jul 9, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A stored XSS vulnerability in the Agent/Center component of CyberPower PowerPanel Business Edition 3.4.0 allows a privileged attacker to embed malicious JavaScript in the SNMP trap receivers form. Upon visiting the /agen...Show more
A stored XSS vulnerability in the Agent/Center component of CyberPower PowerPanel Business Edition 3.4.0 allows a privileged attacker to embed malicious JavaScript in the SNMP trap receivers form. Upon visiting the /agent/action_recipient Event Action/Recipient page, the embedded code will be executed in the browser of the victim.Show less
1Apachefriends
1Xampp
Jun 17, 2026
Jul 9, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
iart.php in XAMPP 1.7.0 has XSS, a related issue to CVE-2008-3569.
1Enhancesoft
1Osticket
Jun 17, 2026
Jul 9, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Unauthenticated Stored XSS in osTicket 1.10.1 allows a remote attacker to gain admin privileges by injecting arbitrary web script or HTML via arbitrary file extension while creating a support ticket.
1Typo3
1Typo3
Jun 17, 2026
Jul 9, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
TYPO3 8.3.0 through 8.7.26 and 9.0.0 through 9.5.7 allows XSS.
1Mailenable
1Mailenable
Jun 17, 2026
Jul 8, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
MailEnable Enterprise Premium 10.23 was vulnerable to stored and reflected cross-site scripting (XSS) attacks. Because the session cookie did not use the HttpOnly flag, it was possible to hijack the session cookie by exp...Show more
MailEnable Enterprise Premium 10.23 was vulnerable to stored and reflected cross-site scripting (XSS) attacks. Because the session cookie did not use the HttpOnly flag, it was possible to hijack the session cookie by exploiting this vulnerability.Show less
1Wikindx Project
1Wikindx
Jun 17, 2026
Jul 8, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A cross-site scripting (XSS) vulnerability in noMenu() and noSubMenu() in core/navigation/MENU.php in WIKINDX prior to version 5.8.1 allows remote attackers to inject arbitrary web script or HTML via the method parameter...Show more
A cross-site scripting (XSS) vulnerability in noMenu() and noSubMenu() in core/navigation/MENU.php in WIKINDX prior to version 5.8.1 allows remote attackers to inject arbitrary web script or HTML via the method parameter.Show less
1Boiteasite
1Rencontre
Jun 17, 2026
Jul 8, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Rencontre plugin before 3.1.3 for WordPress allows XSS via inc/rencontre_widget.php.
1Dlink
1Central Wifimanager
Jun 17, 2026
Jul 6, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A cross-site scripting (XSS) vulnerability in resource view in PayAction.class.php in D-Link Central WiFi Manager CWM(100) before v1.03R0100_BETA6 allows remote attackers to inject arbitrary web script or HTML via the in...Show more
A cross-site scripting (XSS) vulnerability in resource view in PayAction.class.php in D-Link Central WiFi Manager CWM(100) before v1.03R0100_BETA6 allows remote attackers to inject arbitrary web script or HTML via the index.php/Pay/passcodeAuth passcode parameter.Show less
1Cisco
1Secure Firewall Management Center
Jun 17, 2026
Jul 6, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Multiple vulnerabilities in the RSS dashboard in the web-based management interface of Cisco Firepower Management Center (FMC) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attac...Show more
Multiple vulnerabilities in the RSS dashboard in the web-based management interface of Cisco Firepower Management Center (FMC) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. The vulnerabilities are due to insufficient validation of user-supplied input by the web-based management interface of the affected device. An attacker could exploit these vulnerabilities by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.Show less