CWE-79
46,267 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (46,267)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Cisco 1Secure Firewall Management Center Jun 17, 2026 Jul 6, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Multiple vulnerabilities in the RSS dashboard in the web-based management interface of Cisco Firepower Management Center (FMC) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attac...Show more |
2Debian Squid Cache2Debian Linux SquidJun 17, 2026 Jul 5, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The cachemgr.cgi web module of Squid through 4.7 has XSS via the user_name or auth parameter. |
1Digisol 1Dg Hr 3300 Firmware Nov 21, 2024 Jul 5, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Digisol Wireless Wifi Home Router HR-3300 allows XSS via the userid or password parameter to the admin login page. |
In MiniCMS V1.10, stored XSS was found in mc-admin/conf.php (comment box), which can be used to get a user's cookie. |
In MiniCMS V1.10, stored XSS was found in mc-admin/post-edit.php via the content box. An attacker can use it to get a user's cookie. This is different from CVE-2018-10296, CVE-2018-16233, CVE-2018-20520, and CVE-2019-131...Show more |
In MiniCMS V1.10, stored XSS was found in mc-admin/page-edit.php (content box), which can be used to get a user's cookie. |
1Sukimalab 1Online Lesson Booking Jun 17, 2026 Jul 5, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Cross-site scripting vulnerability in Online Lesson Booking 0.8.6 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. |
1Sukimalab 1Attendance Manager Jun 17, 2026 Jul 5, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Cross-site scripting vulnerability in Attendance Manager 0.5.6 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. |
Cross-site scripting vulnerability in Joruri CMS 2017 Release2 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. |
Cross-site scripting vulnerability in Zoho SalesIQ 1.0.8 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. |
inc/user.class.php in GLPI before 9.4.3 allows XSS via a user picture. |
1Stormshield 1Stormshield Network Security Nov 21, 2024 Jul 4, 2019 N/A· v4 8.2 HIGH· v3 7.2 HIGH· v2 Stormshield Network Security 2.0.0 through 2.13.0 and 3.0.0 through 3.7.1 has self-XSS in the command line interface of the SNS web server. |
A reflected XSS on a user page was detected on one of the JetBrains TeamCity pages. The issue was fixed in TeamCity 2018.2.2. |
1F5 2Big Ip Advanced Firewall Manager Big Ip Policy Enforcement ManagerJun 17, 2026 Jul 3, 2019 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 On BIG-IP (AFM, PEM) 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, 13.0.0-13.1.1.4, 12.1.0-12.1.4, 11.6.1-11.6.3.4, and 11.5.1-11.5.8, an undisclosed TMUI pages for AFM and PEM Subscriber management are vulnerable to a stored cross-...Show more |
1F5 2Big Ip Advanced Firewall Manager Big Ip Application Security ManagerJun 17, 2026 Jul 3, 2019 N/A· v4 8.4 HIGH· v3 8.5 HIGH· v2 On BIG-IP (AFM, ASM) 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, 13.0.0-13.1.1.4, 12.1.0-12.1.4, and 11.5.1-11.6.4, a stored cross-site scripting vulnerability in AFM feed list. In the worst case, an attacker can store a CSRF whic...Show more |
1F5 3Big Ip Advanced Firewall Manager Big Ip AnalyticsBig Ip Application Security ManagerJun 17, 2026 Jul 3, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 On BIG-IP (AFM, Analytics, ASM) 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, 13.0.0-13.1.1.4, 12.1.0-12.1.4, and 11.5.1-11.6.3.4, A reflected cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Traf...Show more |
1F5 13Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Analytics+10 moreJun 17, 2026 Jul 3, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 On BIG-IP 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, 13.0.0-13.1.1.4, 12.1.0-12.1.4, and 11.5.1-11.6.4, a reflected cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Traffic Management User Inte...Show more |
DIGISOL DG-HR3400 devices have XSS via a modified SSID when the apssid value is unchanged. |
In MiniCMS V1.10, stored XSS was found in mc-admin/post-edit.php via the tags box. An attacker can use it to get a user's cookie. This is different from CVE-2018-10296, CVE-2018-16233, and CVE-2018-20520. |
1Novaksolutions 1Infusionsoft Php Sdk Nov 21, 2024 Jul 3, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 novaksolutions/infusionsoft-php-sdk v2016-10-31 is vulnerable to a reflected XSS in the leadscoring.php resulting code execution |