← Back
CWE-79

46,266 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (46,266)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Intelliants
1Subrion
Nov 21, 2024
Jul 3, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Subrion CMS before 4.1.4 has XSS.
1Monstra
1Monstra Cms
Nov 21, 2024
Jul 3, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Monstra CMS 3.0.4 and earlier has XSS via index.php.
1Nortekcontrol
2Linear Emerge Elite Firmware
Linear Emerge Essential Firmware
Jun 17, 2026
Jul 2, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Linear eMerge E3-Series devices allow XSS.
1Ibm
1Planning Analytics
Jun 17, 2026
Jul 2, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
IBM Planning Analytics 2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentia...Show more
IBM Planning Analytics 2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 158281.Show less
1Tenable
1Nessus
Jun 17, 2026
Jul 1, 2019
N/A· v4
3.3 LOW· v3
4.3 MEDIUM· v2
Content Injection vulnerability in Tenable Nessus prior to 8.5.0 may allow an authenticated, local attacker to exploit this vulnerability by convincing another targeted Nessus user to view a malicious URL and use Nessus...Show more
Content Injection vulnerability in Tenable Nessus prior to 8.5.0 may allow an authenticated, local attacker to exploit this vulnerability by convincing another targeted Nessus user to view a malicious URL and use Nessus to send fraudulent messages. Successful exploitation could allow the authenticated adversary to inject arbitrary text into the feed status, which will remain saved post session expiration.Show less
1Paloaltonetworks
1Minemeld
Jun 17, 2026
Jul 1, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting vulnerability in Palo Alto Networks MineMeld version 0.9.60 and earlier may allow a remote attacker able to convince an authenticated MineMeld admin to type malicious input in the MineMeld UI could e...Show more
Cross-site scripting vulnerability in Palo Alto Networks MineMeld version 0.9.60 and earlier may allow a remote attacker able to convince an authenticated MineMeld admin to type malicious input in the MineMeld UI could execute arbitrary JavaScript code in the admin’s browser.Show less
1F5
1Websafe Alert Server
Nov 21, 2024
Jul 1, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-Site-Scripting (XSS) vulnerabilities in F5 WebSafe Dashboard 3.9.5 and earlier, aka F5 WebSafe Alert Server, allow privileged authenticated users to inject arbitrary web script or HTML when creating a new user, acc...Show more
Cross-Site-Scripting (XSS) vulnerabilities in F5 WebSafe Dashboard 3.9.5 and earlier, aka F5 WebSafe Alert Server, allow privileged authenticated users to inject arbitrary web script or HTML when creating a new user, account or signature.Show less
1F5
1Websafe Alert Server
Nov 21, 2024
Jul 1, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A Cross Site Scripting (XSS) vulnerability in versions of F5 WebSafe Dashboard 3.9.x and earlier, aka F5 WebSafe Alert Server, allows an unauthenticated user to inject HTML via a crafted alert.
1Ibm
2Business Automation Workflow
Business Process Manager
Jun 17, 2026
Jul 1, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM Business Automation Workflow 18.0.0.0, 18.0.0.1, 18.0.0.2, and 19.0.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intend...Show more
IBM Business Automation Workflow 18.0.0.0, 18.0.0.1, 18.0.0.2, and 19.0.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 162657.Show less
1Ibm
3Infosphere Information Governance Catalog
Infosphere Information ServerInfosphere Information Server On Cloud
Jun 17, 2026
Jul 1, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A Cross-Frame Scripting vulnerability in IBM InfoSphere Information Server 11.3, 11.5, and 11.7 can allow an attacker to load the vulnerable application inside an HTML iframe tag on a malicious page. IBM X-Force ID: 1594...Show more
A Cross-Frame Scripting vulnerability in IBM InfoSphere Information Server 11.3, 11.5, and 11.7 can allow an attacker to load the vulnerable application inside an HTML iframe tag on a malicious page. IBM X-Force ID: 159419.Show less
2Draw
Jgraph
2Draw.io Diagrams
Mxgraph
Jun 17, 2026
Jul 1, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in mxGraph through 4.0.0, related to the "draw.io Diagrams" plugin before 8.3.14 for Confluence and other products. Improper input validation/sanitization of a color field leads to XSS. This is as...Show more
An issue was discovered in mxGraph through 4.0.0, related to the "draw.io Diagrams" plugin before 8.3.14 for Confluence and other products. Improper input validation/sanitization of a color field leads to XSS. This is associated with javascript/examples/grapheditor/www/js/Dialogs.js.Show less
1Squirrelmail
1Squirrelmail
Jun 17, 2026
Jul 1, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
XSS was discovered in SquirrelMail through 1.4.22 and 1.5.x through 1.5.2. Due to improper handling of RCDATA and RAWTEXT type elements, the built-in sanitization mechanism can be bypassed. Malicious script content from...Show more
XSS was discovered in SquirrelMail through 1.4.22 and 1.5.x through 1.5.2. Due to improper handling of RCDATA and RAWTEXT type elements, the built-in sanitization mechanism can be bypassed. Malicious script content from HTML e-mail can be executed within the application context via crafted use of (for example) a NOEMBED, NOFRAMES, NOSCRIPT, or TEXTAREA element.Show less
1Arastta
1Ecommerce
Nov 21, 2024
Jun 30, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Arastta eCommerce 1.6.2 is vulnerable to XSS via the PATH_INFO to the login/ URI.
1Peel
1Peel Shopping
Nov 21, 2024
Jun 30, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Advisto PEEL SHOPPING 9.0.0 has CSRF via en/achat/caddie_ajout.php and en/achat/caddie_affichage.php, as demonstrated by an XSS payload in the couleurId[0] parameter to the latter.
1Synology
1Office
Jun 17, 2026
Jun 30, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-site scripting (XSS) vulnerability in Chart in Synology Office before 3.1.4-2771 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
1Synology
1Note Station
Jun 17, 2026
Jun 30, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-site scripting (XSS) vulnerability in SYNO.NoteStation.Shard in Synology Note Station before 2.5.3-0863 allows remote attackers to inject arbitrary web script or HTML via the object_id parameter.
1Synology
1Calendar
Jun 17, 2026
Jun 30, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-site scripting (XSS) vulnerability in Event Editor in Synology Calendar before 2.3.0-0615 allows remote attackers to inject arbitrary web script or HTML via the title parameter.
1Zoneminder
1Zoneminder
Jun 17, 2026
Jun 30, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Stored XSS in the Filters page (Name field) in ZoneMinder 1.32.3 allows a malicious user to embed and execute JavaScript code in the browser of any user who navigates to this page.
1Grafana
1Grafana
Jun 17, 2026
Jun 30, 2019
N/A· v4
5.4 MEDIUM· v3
4.3 MEDIUM· v2
public/app/features/panel/panel_ctrl.ts in Grafana before 6.2.5 allows HTML Injection in panel drilldown links (via the Title or url field).
1Seeddms
1Seeddms
Jun 17, 2026
Jun 28, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A stored XSS vulnerability was found in SeedDMS 5.1.11 due to poorly escaping the search result in the autocomplete search form placed in the header of out/out.Viewfolder.php.