CWE-79
46,265 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (46,265)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
A cross-site scripting vulnerability exists in Nagios XI before 5.5.4 via the 'name' parameter within the Account Information page. Exploitation of this vulnerability allows an attacker to execute arbitrary JavaScript co...Show more |
An issue was discovered in ZRLOG 2.0.1. There is a Stored XSS vulnerability in the nickname field of the comment area. |
1Microfocus 1Fortify Software Security Center Jun 17, 2026 Jun 19, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 Cross-Site Scripting vulnerability in Micro Focus Fortify Software Security Center Server, versions 17.2, 18.1, 18.2, has been identified in Micro Focus Software Security Center. The vulnerability could be exploited to e...Show more |
An issue was discovered in e107 v2.1.9. There is a XSS attack on e107_admin/comment.php. |
DLP 15.5 MP1 and all prior versions may be susceptible to a cross-site scripting (XSS) vulnerability, a type of issue that can enable attackers to inject client-side scripts into web pages viewed by other users. A cross-...Show more |
1Ibm 10Control Desk Maximo Asset ManagementMaximo For Aviation+7 moreJun 17, 2026 Jun 19, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 IBM Maximo Asset Management 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to cred...Show more |
In Apache Allura prior to 1.11.0, a vulnerability exists for stored XSS on the user dropdown selector when creating or editing tickets. The XSS executes when a user engages with that dropdown on that page. |
A universal Cross-site scripting (UXSS) vulnerability in the Evernote Web Clipper extension before 7.11.1 for Chrome allows remote attackers to run arbitrary web script or HTML in the context of any loaded 3rd-party IFra...Show more |
1Securifi 3Almond+firmware Almond 2015 FirmwareAlmond FirmwareNov 21, 2024 Jun 18, 2019 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 An issue was discovered on Securifi Almond, Almond+, and Almond 2015 devices with firmware AL-R096. The device provides a user with the capability of blocking key words passing in the web traffic to prevent kids from wat...Show more |
1Columbiaweather 1Weather Microserver Firmware Nov 21, 2024 Jun 18, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 In firmware version MS_2.6.9900 of Columbia Weather MicroServer, a stored Cross-site scripting (XSS) vulnerability allows remote authenticated users to inject arbitrary web script via changestationname.php. |
Helpy v2.1.0 has Stored XSS via the Ticket title. |
1Columbiaweather 1Weather Microserver Firmware Nov 21, 2024 Jun 18, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 In firmware version MS_2.6.9900 of Columbia Weather MicroServer, a networkdiags.php reflected Cross-site scripting (XSS) vulnerability allows remote authenticated users to inject arbitrary web script. |
An XSS issue was discovered in i-doit Open 1.12 via the src/tools/php/qr/qr.php url parameter. |
Craft CMS before 3.1.31 does not properly filter XML feeds and thus allowing XSS. |
Concrete5 8.4.3 has XSS because config/concrete.php allows uploads (by administrators) of SVG files that may contain HTML data with a SCRIPT element. |
1Getvera 2Veraedge Firmware Veralite FirmwareNov 21, 2024 Jun 17, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered on Vera VeraEdge 1.7.19 and Veralite 1.7.481 devices. The device provides a shell script called connect.sh which is supposed to return a specific cookie for the user when the user is authenticated...Show more |
1Getvera 2Veraedge Firmware Veralite FirmwareNov 21, 2024 Jun 17, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 An issue was discovered on Vera VeraEdge 1.7.19 and Veralite 1.7.481 devices. The device provides a shell script called relay.sh which is used for creating new SSH relays for the device so that the device connects to Ver...Show more |
out/out.GroupMgr.php in SeedDMS 5.1.11 has Stored XSS by making a new group with a JavaScript payload as the "GROUP" Name. |
XSS in app/operator_panel/index_inc.php in the Operator Panel module in FusionPBX 4.4.3 allows remote unauthenticated attackers to inject arbitrary JavaScript characters by placing a phone call using a specially crafted...Show more |
1Hp 10T6b80a Firmware T6b81a FirmwareT6b82a Firmware+7 moreJun 17, 2026 Jun 17, 2019 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 HP Color LaserJet Pro M280-M281 Multifunction Printer series (before v. 20190419), HP LaserJet Pro MFP M28-M31 Printer series (before v. 20190426) may have an embedded web server potentially vulnerable to stored XSS in w...Show more |