← Back
CWE-79

46,267 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (46,267)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Cisco
1Secure Firewall Management Center
Jun 17, 2026
Jul 6, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Multiple vulnerabilities in the RSS dashboard in the web-based management interface of Cisco Firepower Management Center (FMC) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attac...Show more
Multiple vulnerabilities in the RSS dashboard in the web-based management interface of Cisco Firepower Management Center (FMC) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. The vulnerabilities are due to insufficient validation of user-supplied input by the web-based management interface of the affected device. An attacker could exploit these vulnerabilities by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.Show less
2Debian
Squid Cache
2Debian Linux
Squid
Jun 17, 2026
Jul 5, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The cachemgr.cgi web module of Squid through 4.7 has XSS via the user_name or auth parameter.
1Digisol
1Dg Hr 3300 Firmware
Nov 21, 2024
Jul 5, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Digisol Wireless Wifi Home Router HR-3300 allows XSS via the userid or password parameter to the admin login page.
11234n
1Minicms
Jun 17, 2026
Jul 5, 2019
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
In MiniCMS V1.10, stored XSS was found in mc-admin/conf.php (comment box), which can be used to get a user's cookie.
11234n
1Minicms
Jun 17, 2026
Jul 5, 2019
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
In MiniCMS V1.10, stored XSS was found in mc-admin/post-edit.php via the content box. An attacker can use it to get a user's cookie. This is different from CVE-2018-10296, CVE-2018-16233, CVE-2018-20520, and CVE-2019-131...Show more
In MiniCMS V1.10, stored XSS was found in mc-admin/post-edit.php via the content box. An attacker can use it to get a user's cookie. This is different from CVE-2018-10296, CVE-2018-16233, CVE-2018-20520, and CVE-2019-13186.Show less
11234n
1Minicms
Jun 17, 2026
Jul 5, 2019
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
In MiniCMS V1.10, stored XSS was found in mc-admin/page-edit.php (content box), which can be used to get a user's cookie.
1Sukimalab
1Online Lesson Booking
Jun 17, 2026
Jul 5, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting vulnerability in Online Lesson Booking 0.8.6 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
1Sukimalab
1Attendance Manager
Jun 17, 2026
Jul 5, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting vulnerability in Attendance Manager 0.5.6 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
1Joruri
1Joruri Cms 2017
Jun 17, 2026
Jul 5, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting vulnerability in Joruri CMS 2017 Release2 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
1Zoho
1Salesiq
Jun 17, 2026
Jul 5, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting vulnerability in Zoho SalesIQ 1.0.8 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
1Glpi Project
1Glpi
Jun 17, 2026
Jul 4, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
inc/user.class.php in GLPI before 9.4.3 allows XSS via a user picture.
1Stormshield
1Stormshield Network Security
Nov 21, 2024
Jul 4, 2019
N/A· v4
8.2 HIGH· v3
7.2 HIGH· v2
Stormshield Network Security 2.0.0 through 2.13.0 and 3.0.0 through 3.7.1 has self-XSS in the command line interface of the SNS web server.
1Jetbrains
1Teamcity
Jun 17, 2026
Jul 3, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A reflected XSS on a user page was detected on one of the JetBrains TeamCity pages. The issue was fixed in TeamCity 2018.2.2.
1F5
2Big Ip Advanced Firewall Manager
Big Ip Policy Enforcement Manager
Jun 17, 2026
Jul 3, 2019
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
On BIG-IP (AFM, PEM) 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, 13.0.0-13.1.1.4, 12.1.0-12.1.4, 11.6.1-11.6.3.4, and 11.5.1-11.5.8, an undisclosed TMUI pages for AFM and PEM Subscriber management are vulnerable to a stored cross-...Show more
On BIG-IP (AFM, PEM) 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, 13.0.0-13.1.1.4, 12.1.0-12.1.4, 11.6.1-11.6.3.4, and 11.5.1-11.5.8, an undisclosed TMUI pages for AFM and PEM Subscriber management are vulnerable to a stored cross-site scripting (XSS) issue. This is a control plane issue only and is not accessible from the data plane. The attack requires a malicious resource administrator to store the XSS.Show less
1F5
2Big Ip Advanced Firewall Manager
Big Ip Application Security Manager
Jun 17, 2026
Jul 3, 2019
N/A· v4
8.4 HIGH· v3
8.5 HIGH· v2
On BIG-IP (AFM, ASM) 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, 13.0.0-13.1.1.4, 12.1.0-12.1.4, and 11.5.1-11.6.4, a stored cross-site scripting vulnerability in AFM feed list. In the worst case, an attacker can store a CSRF whic...Show more
On BIG-IP (AFM, ASM) 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, 13.0.0-13.1.1.4, 12.1.0-12.1.4, and 11.5.1-11.6.4, a stored cross-site scripting vulnerability in AFM feed list. In the worst case, an attacker can store a CSRF which results in code execution as the admin user. The level of user role which can perform this attack are resource administrator and administrator.Show less
1F5
3Big Ip Advanced Firewall Manager
Big Ip AnalyticsBig Ip Application Security Manager
Jun 17, 2026
Jul 3, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
On BIG-IP (AFM, Analytics, ASM) 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, 13.0.0-13.1.1.4, 12.1.0-12.1.4, and 11.5.1-11.6.3.4, A reflected cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Traf...Show more
On BIG-IP (AFM, Analytics, ASM) 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, 13.0.0-13.1.1.4, 12.1.0-12.1.4, and 11.5.1-11.6.3.4, A reflected cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Traffic Management User Interface (TMUI), also known as the Configuration utility.Show less
1F5
13Big Ip Access Policy Manager
Big Ip Advanced Firewall ManagerBig Ip Analytics+10 more
Jun 17, 2026
Jul 3, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
On BIG-IP 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, 13.0.0-13.1.1.4, 12.1.0-12.1.4, and 11.5.1-11.6.4, a reflected cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Traffic Management User Inte...Show more
On BIG-IP 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, 13.0.0-13.1.1.4, 12.1.0-12.1.4, and 11.5.1-11.6.4, a reflected cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Traffic Management User Interface (TMUI) also known as the BIG-IP Configuration utility.Show less
1Digisol
1Dg Hr3400 Firmware
Nov 21, 2024
Jul 3, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
DIGISOL DG-HR3400 devices have XSS via a modified SSID when the apssid value is unchanged.
11234n
1Minicms
Jun 17, 2026
Jul 3, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In MiniCMS V1.10, stored XSS was found in mc-admin/post-edit.php via the tags box. An attacker can use it to get a user's cookie. This is different from CVE-2018-10296, CVE-2018-16233, and CVE-2018-20520.
1Novaksolutions
1Infusionsoft Php Sdk
Nov 21, 2024
Jul 3, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
novaksolutions/infusionsoft-php-sdk v2016-10-31 is vulnerable to a reflected XSS in the leadscoring.php resulting code execution