← Back
CWE-79

46,265 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (46,265)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Nagios
1Nagios Xi
Nov 21, 2024
Jun 19, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A cross-site scripting vulnerability exists in Nagios XI before 5.5.4 via the 'name' parameter within the Account Information page. Exploitation of this vulnerability allows an attacker to execute arbitrary JavaScript co...Show more
A cross-site scripting vulnerability exists in Nagios XI before 5.5.4 via the 'name' parameter within the Account Information page. Exploitation of this vulnerability allows an attacker to execute arbitrary JavaScript code within the auto login admin management page.Show less
1Zrlog
1Zrlog
Nov 21, 2024
Jun 19, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in ZRLOG 2.0.1. There is a Stored XSS vulnerability in the nickname field of the comment area.
1Microfocus
1Fortify Software Security Center
Jun 17, 2026
Jun 19, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-Site Scripting vulnerability in Micro Focus Fortify Software Security Center Server, versions 17.2, 18.1, 18.2, has been identified in Micro Focus Software Security Center. The vulnerability could be exploited to e...Show more
Cross-Site Scripting vulnerability in Micro Focus Fortify Software Security Center Server, versions 17.2, 18.1, 18.2, has been identified in Micro Focus Software Security Center. The vulnerability could be exploited to execute JavaScript code in user’s browser. The vulnerability could be exploited to execute JavaScript code in user’s browser.Show less
1E107
1E107
Nov 21, 2024
Jun 19, 2019
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
An issue was discovered in e107 v2.1.9. There is a XSS attack on e107_admin/comment.php.
1Symantec
1Data Loss Prevention
Jun 17, 2026
Jun 19, 2019
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
DLP 15.5 MP1 and all prior versions may be susceptible to a cross-site scripting (XSS) vulnerability, a type of issue that can enable attackers to inject client-side scripts into web pages viewed by other users. A cross-...Show more
DLP 15.5 MP1 and all prior versions may be susceptible to a cross-site scripting (XSS) vulnerability, a type of issue that can enable attackers to inject client-side scripts into web pages viewed by other users. A cross-site scripting vulnerability may be used by attackers to bypass access controls such as the same-origin policy.Show less
1Ibm
10Control Desk
Maximo Asset ManagementMaximo For Aviation+7 more
Jun 17, 2026
Jun 19, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM Maximo Asset Management 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to cred...Show more
IBM Maximo Asset Management 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 160949.Show less
1Apache
1Allura
Jun 17, 2026
Jun 19, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In Apache Allura prior to 1.11.0, a vulnerability exists for stored XSS on the user dropdown selector when creating or editing tickets. The XSS executes when a user engages with that dropdown on that page.
1Evernote
1Web Clipper
Jun 17, 2026
Jun 18, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A universal Cross-site scripting (UXSS) vulnerability in the Evernote Web Clipper extension before 7.11.1 for Chrome allows remote attackers to run arbitrary web script or HTML in the context of any loaded 3rd-party IFra...Show more
A universal Cross-site scripting (UXSS) vulnerability in the Evernote Web Clipper extension before 7.11.1 for Chrome allows remote attackers to run arbitrary web script or HTML in the context of any loaded 3rd-party IFrame.Show less
1Securifi
3Almond+firmware
Almond 2015 FirmwareAlmond Firmware
Nov 21, 2024
Jun 18, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
An issue was discovered on Securifi Almond, Almond+, and Almond 2015 devices with firmware AL-R096. The device provides a user with the capability of blocking key words passing in the web traffic to prevent kids from wat...Show more
An issue was discovered on Securifi Almond, Almond+, and Almond 2015 devices with firmware AL-R096. The device provides a user with the capability of blocking key words passing in the web traffic to prevent kids from watching content that might be deemed unsafe using the web management interface. It seems that the device does not implement any cross-site scripting protection mechanism which allows an attacker to trick a user who is logged in to the web management interface into executing a stored cross-site scripting payload on the user's browser and execute any action on the device provided by the web management interface.Show less
1Columbiaweather
1Weather Microserver Firmware
Nov 21, 2024
Jun 18, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
In firmware version MS_2.6.9900 of Columbia Weather MicroServer, a stored Cross-site scripting (XSS) vulnerability allows remote authenticated users to inject arbitrary web script via changestationname.php.
1Helpy.io
1Helpy
Nov 21, 2024
Jun 18, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Helpy v2.1.0 has Stored XSS via the Ticket title.
1Columbiaweather
1Weather Microserver Firmware
Nov 21, 2024
Jun 18, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
In firmware version MS_2.6.9900 of Columbia Weather MicroServer, a networkdiags.php reflected Cross-site scripting (XSS) vulnerability allows remote authenticated users to inject arbitrary web script.
1I Doit
1I Doit
Jun 17, 2026
Jun 18, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An XSS issue was discovered in i-doit Open 1.12 via the src/tools/php/qr/qr.php url parameter.
1Craftcms
1Craft Cms
Jun 17, 2026
Jun 18, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Craft CMS before 3.1.31 does not properly filter XML feeds and thus allowing XSS.
1Concretecms
1Concrete Cms
Nov 21, 2024
Jun 17, 2019
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Concrete5 8.4.3 has XSS because config/concrete.php allows uploads (by administrators) of SVG files that may contain HTML data with a SCRIPT element.
1Getvera
2Veraedge Firmware
Veralite Firmware
Nov 21, 2024
Jun 17, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered on Vera VeraEdge 1.7.19 and Veralite 1.7.481 devices. The device provides a shell script called connect.sh which is supposed to return a specific cookie for the user when the user is authenticated...Show more
An issue was discovered on Vera VeraEdge 1.7.19 and Veralite 1.7.481 devices. The device provides a shell script called connect.sh which is supposed to return a specific cookie for the user when the user is authenticated to https://home.getvera.com. One of the parameters retrieved by this script is "RedirectURL". However, the application lacks strict input validation of this parameter and this allows an attacker to execute the client-side code on this application.Show less
1Getvera
2Veraedge Firmware
Veralite Firmware
Nov 21, 2024
Jun 17, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
An issue was discovered on Vera VeraEdge 1.7.19 and Veralite 1.7.481 devices. The device provides a shell script called relay.sh which is used for creating new SSH relays for the device so that the device connects to Ver...Show more
An issue was discovered on Vera VeraEdge 1.7.19 and Veralite 1.7.481 devices. The device provides a shell script called relay.sh which is used for creating new SSH relays for the device so that the device connects to Vera servers. All the parameters passed in this specific script are logged to a log file called log.relay in the /tmp folder. The user can also read all the log files from the device using a script called log.sh. However, when the script loads the log files it displays them with content-type text/html and passes all the logs through the ansi2html binary which converts all the character text including HTML meta-characters correctly to be displayed in the browser. This allows an attacker to use the log files as a storing mechanism for the XSS payload and thus whenever a user navigates to that log.sh script, it enables the XSS payload and allows an attacker to execute his malicious payload on the user's browser.Show less
1Seeddms
1Seeddms
Jun 17, 2026
Jun 17, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
out/out.GroupMgr.php in SeedDMS 5.1.11 has Stored XSS by making a new group with a JavaScript payload as the "GROUP" Name.
1Fusionpbx
1Fusionpbx
Jun 17, 2026
Jun 17, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
XSS in app/operator_panel/index_inc.php in the Operator Panel module in FusionPBX 4.4.3 allows remote unauthenticated attackers to inject arbitrary JavaScript characters by placing a phone call using a specially crafted...Show more
XSS in app/operator_panel/index_inc.php in the Operator Panel module in FusionPBX 4.4.3 allows remote unauthenticated attackers to inject arbitrary JavaScript characters by placing a phone call using a specially crafted caller ID number. This can further lead to remote code execution by chaining this vulnerability with a command injection vulnerability also present in FusionPBX.Show less
1Hp
10T6b80a Firmware
T6b81a FirmwareT6b82a Firmware+7 more
Jun 17, 2026
Jun 17, 2019
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
HP Color LaserJet Pro M280-M281 Multifunction Printer series (before v. 20190419), HP LaserJet Pro MFP M28-M31 Printer series (before v. 20190426) may have an embedded web server potentially vulnerable to stored XSS in w...Show more
HP Color LaserJet Pro M280-M281 Multifunction Printer series (before v. 20190419), HP LaserJet Pro MFP M28-M31 Printer series (before v. 20190426) may have an embedded web server potentially vulnerable to stored XSS in wireless configuration pageShow less