← Back
CWE-79

46,266 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (46,266)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ibm
1Security Access Manager
Jun 17, 2026
Jun 25, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
IBM Security Access Manager 9.0.1 through 9.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially...Show more
IBM Security Access Manager 9.0.1 through 9.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 158573.Show less
1Livezilla
1Livezilla
Jun 17, 2026
Jun 25, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
LiveZilla Server before 8.0.1.1 is vulnerable to XSS in the ticket.php Subject.
1Livezilla
1Livezilla
Jun 17, 2026
Jun 25, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
LiveZilla Server before 8.0.1.1 is vulnerable to XSS in the chat.php Create Ticket Action.
1Livezilla
1Livezilla
Jun 17, 2026
Jun 25, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
LiveZilla Server before 8.0.1.1 is vulnerable to XSS in mobile/index.php via the Accept-Language HTTP header.
1Netgate
1Pfsense
Jun 17, 2026
Jun 25, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In pfSense 2.4.4-p2 and 2.4.4-p3, if it is possible to trick an authenticated administrator into clicking on a button on a phishing page, an attacker can leverage XSS to upload arbitrary executable code, via diag_command...Show more
In pfSense 2.4.4-p2 and 2.4.4-p3, if it is possible to trick an authenticated administrator into clicking on a button on a phishing page, an attacker can leverage XSS to upload arbitrary executable code, via diag_command.php and rrd_fetch_json.php (timePeriod parameter), to a server. Then, the remote attacker can run any command with root privileges on that server.Show less
1Miniorange
1Saml Sp Single Sign On
Jun 17, 2026
Jun 24, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In the miniOrange SAML SP Single Sign On plugin before 4.8.73 for WordPress, the SAML Login Endpoint is vulnerable to XSS via a specially crafted SAMLResponse XML post.
1Quadbase
1Espressreport Es
Jun 17, 2026
Jun 24, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Stored XSS within Quadbase EspressReport ES (ERES) v7.0 update 7 allows remote attackers to execute malicious JavaScript and inject arbitrary source code into the target pages. The XSS payload is stored by creating a new...Show more
Stored XSS within Quadbase EspressReport ES (ERES) v7.0 update 7 allows remote attackers to execute malicious JavaScript and inject arbitrary source code into the target pages. The XSS payload is stored by creating a new user account, and setting the username to an XSS payload. The stored payload can then be triggered by accessing the "Set Security Levels" or "View User/Group Relationships" page. If the attacker does not currently have permission to create a new user, another vulnerability such as CSRF must be exploited first.Show less
1Microfocus
1Netiq Self Service Password Reset
Jun 17, 2026
Jun 24, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A potential XSS exists in Self Service Password Reset, in Micro Focus NetIQ Software all versions prior to version 4.4. The vulnerability could be exploited to enable an XSS attack.
1Shopware
1Shopware
Jun 17, 2026
Jun 23, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Shopware before 5.5.8 has XSS via the Query String to the backend/Login or backend/Login/load/ URI.
1Cloudera
1Cloudera Manager
Nov 21, 2024
Jun 20, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in Cloudera Manager 5.x through 5.15.0. One type of page in Cloudera Manager uses a 'returnUrl' parameter to redirect the user to another page in Cloudera Manager once a wizard is completed. The v...Show more
An issue was discovered in Cloudera Manager 5.x through 5.15.0. One type of page in Cloudera Manager uses a 'returnUrl' parameter to redirect the user to another page in Cloudera Manager once a wizard is completed. The validity of this parameter was not checked. As a result, the user could be automatically redirected to an attacker's external site or perform a malicious JavaScript function that results in cross-site scripting (XSS). This was fixed by not allowing any value in the returnUrl parameter with patterns such as http://, https://, //, or javascript. The only exceptions to this rule are the SAML Login/Logout URLs, which remain supported since they are explicitly configured and they are not passed via the returnUrl parameter.Show less
1Seeddms
1Seeddms
Jun 17, 2026
Jun 20, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
out/out.UsrMgr.php in SeedDMS before 5.1.11 allows Stored Cross-Site Scripting (XSS) via the name field.
2Freepbx
Sangoma
2Freepbx
Freepbx
Nov 21, 2024
Jun 20, 2019
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
An issue was discovered in FreePBX core before 3.0.122.43, 14.0.18.34, and 5.0.1beta4. By crafting a request for adding Asterisk modules, an attacker is able to store JavaScript commands in a module name.
1Afian
1Filerun
Jun 17, 2026
Jun 20, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
FileRun 2019.05.21 allows XSS via the filename to the ?module=fileman&section=do&page=up URI. This issue has been fixed in FileRun 2019.06.01.
1B3log
1Solo
Nov 21, 2024
Jun 20, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
b3log Solo 2.9.3 has XSS in the Input page under the "Publish Articles" menu with an ID of "articleTags" stored in the "tag" JSON field, which allows remote attackers to inject arbitrary Web scripts or HTML via a careful...Show more
b3log Solo 2.9.3 has XSS in the Input page under the "Publish Articles" menu with an ID of "articleTags" stored in the "tag" JSON field, which allows remote attackers to inject arbitrary Web scripts or HTML via a carefully crafted site name in an admin-authenticated HTTP request.Show less
1Yzmcms
1Yzmcms
Nov 21, 2024
Jun 20, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
YzmCMS 5.1 has XSS via the admin/system_manage/user_config_add.html title parameter.
1Mantisbt
1Mantisbt
Nov 21, 2024
Jun 20, 2019
N/A· v4
4.7 MEDIUM· v3
2.6 LOW· v2
A cross-site scripting (XSS) vulnerability in the View Filters page (view_filters_page.php) and Edit Filter page (manage_filter_edit_page.php) in MantisBT 2.1.0 through 2.17.0 allows remote attackers to inject arbitrary...Show more
A cross-site scripting (XSS) vulnerability in the View Filters page (view_filters_page.php) and Edit Filter page (manage_filter_edit_page.php) in MantisBT 2.1.0 through 2.17.0 allows remote attackers to inject arbitrary code (if CSP settings permit it) through a crafted PATH_INFO. NOTE: this vulnerability exists because of an incomplete fix for CVE-2018-13055.Show less
1Creatiwity
1Witycms
Nov 21, 2024
Jun 20, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The "utilisateur" menu in Creatiwity wityCMS 0.6.2 modifies the presence of XSS at two input points for user information, with the "first name" and "last name" parameters.
1B3log
1Symphony
Nov 21, 2024
Jun 20, 2019
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
In Symphony before 3.3.0, there is XSS in the Title under Post. The ID "articleTitle" of this is stored in the "articleTitle" JSON field, and executes a payload when accessing the /member/test/points URI, allowing remote...Show more
In Symphony before 3.3.0, there is XSS in the Title under Post. The ID "articleTitle" of this is stored in the "articleTitle" JSON field, and executes a payload when accessing the /member/test/points URI, allowing remote attacks. Any Web script or HTML can be inserted by an admin-authenticated user via a crafted web site name.Show less
1Cisco
1Prime Service Catalog
Jun 17, 2026
Jun 20, 2019
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
A vulnerability in the web-based management interface of Cisco Prime Service Catalog could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based interface....Show more
A vulnerability in the web-based management interface of Cisco Prime Service Catalog could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based interface. The vulnerability is due to insufficient validation of user-supplied input by the web-based management interface. An attacker could exploit this vulnerability by adding specific strings to multiple configuration fields. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface or allow the attacker to access sensitive browser-based information.Show less
1Forgerock
2Access Management
Openam
Nov 21, 2024
Jun 19, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Auth 2.0 Authorization Server of ForgeRock Access Management (OpenAM) 13.5.0-13.5.1 and Access Management (AM) 5.0.0-5.1.1 does not correctly validate redirect_uri for some invalid requests, which allows attackers to exe...Show more
Auth 2.0 Authorization Server of ForgeRock Access Management (OpenAM) 13.5.0-13.5.1 and Access Management (AM) 5.0.0-5.1.1 does not correctly validate redirect_uri for some invalid requests, which allows attackers to execute a script in the user's browser via reflected XSS.Show less