CWE-79
46,265 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (46,265)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Hp 10T6b80a Firmware T6b81a FirmwareT6b82a Firmware+7 moreJun 17, 2026 Jun 17, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 HP Color LaserJet Pro M280-M281 Multifunction Printer series (before v. 20190419), HP LaserJet Pro MFP M28-M31 Printer series (before v. 20190426) may have an embedded web server potentially vulnerable to reflected XSS i...Show more |
IBM Cognos Controller 10.2.0, 10.2.1, 10.3.0, 10.3.1, and 10.4.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended function...Show more |
An issue was discovered in Tyto Sahi Pro through 7.x.x and 8.0.0. The logs web interface is vulnerable to stored XSS. |
1Count Per Day Project 1Count Per Day Nov 21, 2024 Jun 15, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The "Count per Day" plugin before 3.2.6 for WordPress allows XSS via the wp-admin/?page=cpd_metaboxes daytoshow parameter. |
In MyBB before 1.8.21, an attacker can exploit a parsing flaw in the Private Message / Post renderer that leads to [video] BBCode persistent XSS to take over any forum account, aka a nested video MyCode issue. |
1Sap 1Netweaver Process Integration Jun 17, 2026 Jun 14, 2019 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 SAP NetWeaver Process Integration, versions: SAP_XIESR: 7.20, SAP_XITOOL: 7.10 to 7.11, 7.30, 7.31, 7.40, 7.50, does not sufficiently validate user-controlled inputs, which allows an attacker possessing admin privileges...Show more |
SAP BusinessObjects Business Intelligence Platform (Administration Console), versions 4.2, 4.3, module BILogon/appService.jsp is reflecting requested parameter errMsg into response content without sanitation. This could...Show more |
IBM Connections 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disc...Show more |
There is a reflection XSS vulnerability in the HedEx products. Remote attackers send malicious links to users and trick users to click. Successfully exploit cloud allow the attacker to initiate XSS attacks. Affects HedEx...Show more |
2Intel Lenovo5Rapid Storage Technology Enterprise Thinkstation P520 FirmwareThinkstation P520c Firmware+2 moreJun 17, 2026 Jun 13, 2019 N/A· v4 7.4 HIGH· v3 4.3 MEDIUM· v2 Reflected XSS in web interface for Intel(R) Accelerated Storage Manager in Intel(R) RSTe before version 5.5.0.2015 may allow an unauthenticated user to potentially enable denial of service via network access. |
Automotive Dealer Portal in SAP R/3 Enterprise Application (versions: 600, 602, 603, 604, 605, 606, 616, 617) does not sufficiently encode user-controlled inputs, this makes it possible for an attacker to send unwanted s...Show more |
An authenticated attacker in SAP E-Commerce (Business-to-Consumer application), versions 7.3, 7.31, 7.32, 7.33, 7.54, can change the price of the product to zero and also checkout, by injecting an HTML code in the applic...Show more |
1Redhat 2Jboss Enterprise Application Platform Single Sign OnJun 17, 2026 Jun 12, 2019 N/A· v4 9.0 CRITICAL· v3 6.0 MEDIUM· v2 It was found that Picketlink as shipped with Jboss Enterprise Application Platform 7.2 would accept an xinclude parameter in SAMLresponse XML. An attacker could use this flaw to send a URL to achieve cross-site scripting...Show more |
1Redhat 2Jboss Enterprise Application Platform Single Sign OnJun 17, 2026 Jun 12, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 It was found that a SAMLRequest containing a script could be processed by Picketlink versions shipped in Jboss Application Platform 7.2.x and 7.1.x. An attacker could use this to send a malicious script to achieve cross-...Show more |
1Microsoft 4Project Server Sharepoint Enterprise ServerSharepoint Foundation+1 moreJun 17, 2026 Jun 12, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server. An authenticated attacker could exploit the...Show more |
1Microsoft 4Project Server Sharepoint Enterprise ServerSharepoint Foundation+1 moreJun 17, 2026 Jun 12, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server. An authenticated attacker could exploit the...Show more |
1Microsoft 2Sharepoint Enterprise Server Sharepoint ServerJun 17, 2026 Jun 12, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server. An authenticated attacker could exploit the...Show more |
1Microsoft 4Project Server Sharepoint Enterprise ServerSharepoint Foundation+1 moreJun 17, 2026 Jun 12, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server. An authenticated attacker could exploit the...Show more |
All versions up to V20.18.40.R7.B1of ZTE NetNumen DAP product have an XSS vulnerability. Due to the lack of correct validation of client data in WEB applications, which results in users being hijacked. |
An issue was discovered in Joomla! before 3.9.7. The subform fieldtype does not sufficiently filter or validate input of subfields. This leads to XSS attack vectors. |