CWE-79
46,267 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (46,267)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Paypal 1Adaptive Payments Sdk Nov 21, 2024 Jul 10, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 paypal/adaptivepayments-sdk-php v3.9.2 is vulnerable to a reflected XSS in the SetPaymentOptions.php resulting code execution |
An issue was discovered in the Teclib News plugin through 1.5.2 for GLPI. It allows a stored XSS attack via the $_POST['name'] parameter. |
Nagios XI before 5.5.4 has XSS in the auto login admin management page. |
An issue was discovered in Eventum 3.5.0. /htdocs/list.php has XSS via the show_notification_list_issues or show_authorized_issues parameter. |
An issue was discovered in Eventum 3.5.0. /htdocs/popup.php has XSS via the cat parameter. |
An issue was discovered in Eventum 3.5.0. /htdocs/validate.php has XSS via the values parameter. |
An issue was discovered in Eventum 3.5.0. htdocs/switch.php has XSS via the current_page parameter. |
An issue was discovered in Eventum 3.5.0. htdocs/ajax/update.php has XSS via the field_name parameter. |
The Yoast SEO plugin before 11.6-RC5 for WordPress does not properly restrict unfiltered HTML in term descriptions. |
PHPWind 9.1.0 has XSS vulnerabilities in the c and m parameters of the index.php file. |
1Keynto 1Team Password Manager Jun 17, 2026 Jul 9, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 KEYNTO Team Password Manager 1.5.0 allows XSS because data saved from websites is mishandled in the online vault. |
A stored XSS vulnerability in the Agent/Center component of CyberPower PowerPanel Business Edition 3.4.0 allows a privileged attacker to embed malicious JavaScript in the SNMP trap receivers form. Upon visiting the /agen...Show more |
iart.php in XAMPP 1.7.0 has XSS, a related issue to CVE-2008-3569. |
Unauthenticated Stored XSS in osTicket 1.10.1 allows a remote attacker to gain admin privileges by injecting arbitrary web script or HTML via arbitrary file extension while creating a support ticket. |
TYPO3 8.3.0 through 8.7.26 and 9.0.0 through 9.5.7 allows XSS. |
MailEnable Enterprise Premium 10.23 was vulnerable to stored and reflected cross-site scripting (XSS) attacks. Because the session cookie did not use the HttpOnly flag, it was possible to hijack the session cookie by exp...Show more |
A cross-site scripting (XSS) vulnerability in noMenu() and noSubMenu() in core/navigation/MENU.php in WIKINDX prior to version 5.8.1 allows remote attackers to inject arbitrary web script or HTML via the method parameter...Show more |
The Rencontre plugin before 3.1.3 for WordPress allows XSS via inc/rencontre_widget.php. |
A cross-site scripting (XSS) vulnerability in resource view in PayAction.class.php in D-Link Central WiFi Manager CWM(100) before v1.03R0100_BETA6 allows remote attackers to inject arbitrary web script or HTML via the in...Show more |
1Cisco 1Secure Firewall Management Center Jun 17, 2026 Jul 6, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Multiple vulnerabilities in the RSS dashboard in the web-based management interface of Cisco Firepower Management Center (FMC) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attac...Show more |