← Back
CWE-79

46,265 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (46,265)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Jenkins
1Electricflow
Jun 17, 2026
Jun 11, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A reflected cross site scripting vulnerability in Jenkins ElectricFlow Plugin 1.1.6 and earlier allowed attackers able to control the output of the ElectricFlow API to inject arbitrary HTML and JavaScript in job configur...Show more
A reflected cross site scripting vulnerability in Jenkins ElectricFlow Plugin 1.1.6 and earlier allowed attackers able to control the output of the ElectricFlow API to inject arbitrary HTML and JavaScript in job configuration forms containing post-build steps provided by this plugin.Show less
1Jenkins
1Electricflow
Jun 17, 2026
Jun 11, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A stored cross site scripting vulnerability in Jenkins ElectricFlow Plugin 1.1.5 and earlier allowed attackers able to configure jobs in Jenkins or control the output of the ElectricFlow API to inject arbitrary HTML and...Show more
A stored cross site scripting vulnerability in Jenkins ElectricFlow Plugin 1.1.5 and earlier allowed attackers able to configure jobs in Jenkins or control the output of the ElectricFlow API to inject arbitrary HTML and JavaScript in the plugin-provided output on build status pages.Show less
1Fatfreecrm
1Fat Free Crm
Jun 17, 2026
Jun 10, 2019
N/A· v4
5.4 MEDIUM· v3
4.3 MEDIUM· v2
HTML Injection has been discovered in the v0.19.0 version of the Fat Free CRM product via an authenticated request to the /comments URI. NOTE: the vendor disputes the significance of this report because some HTML formatt...Show more
HTML Injection has been discovered in the v0.19.0 version of the Fat Free CRM product via an authenticated request to the /comments URI. NOTE: the vendor disputes the significance of this report because some HTML formatting (such as with an H1 element) is allowed, but there is a XSS protection mechanism.Show less
1Pix Link
1Lv Wr09 Firmware
Jun 17, 2026
Jun 10, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
XSS on the PIX-Link Repeater/Router LV-WR09 with firmware v28K.MiniRouter.20180616 allows attackers to steal credentials without being connected to the network. The attack vector is a crafted ESSID.
1Moxa
1Awk 3121 Firmware
Nov 21, 2024
Jun 7, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered on Moxa AWK-3121 1.19 devices. It provides functionality so that an administrator can change the name of the device. However, the same functionality allows an attacker to execute XSS by injecting...Show more
An issue was discovered on Moxa AWK-3121 1.19 devices. It provides functionality so that an administrator can change the name of the device. However, the same functionality allows an attacker to execute XSS by injecting an XSS payload. The POST parameter "iw_board_deviceName" is susceptible to this injection.Show less
1Moxa
1Awk 3121 Firmware
Nov 21, 2024
Jun 7, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered on Moxa AWK-3121 1.14 devices. The session cookie "Password508" does not have an HttpOnly flag. This allows an attacker who is able to execute a cross-site scripting attack to steal the cookie ver...Show more
An issue was discovered on Moxa AWK-3121 1.14 devices. The session cookie "Password508" does not have an HttpOnly flag. This allows an attacker who is able to execute a cross-site scripting attack to steal the cookie very easily.Show less
1Maccms
1Maccms
Nov 21, 2024
Jun 7, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Maccms through 8.0 allows XSS via the site_keywords field to index.php?m=system-config because of tpl/module/system.php and tpl/html/system_config.html, related to template/paody/html/vod_index.html.
1Phome
1Empirecms
Nov 21, 2024
Jun 7, 2019
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
admin\db\DoSql.php in EmpireCMS through 7.5 allows XSS via crafted SQL syntax to admin/admin.php.
1Enttec
4Datagate Mk2 Firmware
E Streamer Mk2 FirmwarePixelator Firmware+1 more
Jun 17, 2026
Jun 7, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A number of stored XSS vulnerabilities have been identified in the web configuration feature in ENTTEC Datagate Mk2 70044_update_05032019-482 that could allow an unauthenticated threat actor to inject malicious code dire...Show more
A number of stored XSS vulnerabilities have been identified in the web configuration feature in ENTTEC Datagate Mk2 70044_update_05032019-482 that could allow an unauthenticated threat actor to inject malicious code directly into the application. This affects, for example, the Profile Description field in JSON data to the Profile Editor.Show less
1Ibm
3Intelligent Operations Center
Intelligent Operations Center For Emergency ManagementWater Operations For Waternamics
Jun 17, 2026
Jun 7, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM Intelligent Operations Center (IOC) 5.1.0 through 5.2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality...Show more
IBM Intelligent Operations Center (IOC) 5.1.0 through 5.2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 157015.Show less
1Cloudera
1Cloudera Manager
Jun 17, 2026
Jun 7, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
This CVE relates to an unspecified cross site scripting vulnerability in Cloudera Manager.
1Mybb
1Mybb
Jun 17, 2026
Jun 6, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
MyBB 1.8.19 has XSS in the resetpassword function.
1Vtiger
1Vtiger Crm
Jun 17, 2026
Jun 6, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
vtiger CRM 7.0.1 is affected by one reflected Cross-Site Scripting (XSS) vulnerability affecting version 7.0.1 and probably prior versions. This vulnerability could allow remote unauthenticated attackers to inject arbitr...Show more
vtiger CRM 7.0.1 is affected by one reflected Cross-Site Scripting (XSS) vulnerability affecting version 7.0.1 and probably prior versions. This vulnerability could allow remote unauthenticated attackers to inject arbitrary web script or HTML via index.php?module=Contacts&view=List (app parameter).Show less
1Api Based Travel Booking Project
1Api Based Travel Booking
Jun 17, 2026
Jun 6, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in PHP Scripts Mall API Based Travel Booking 3.4.7. There is Reflected XSS via the flight-results.php d2 parameter.
1Chartered Accountant \
1 Auditor Website Project
Jun 17, 2026
Jun 6, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
PHP Scripts Mall Chartered Accountant : Auditor Website 2.0.1 has Stored XSS in the Profile Update page via the My Name field.
1Investment Mlm Software Project
1Investment Mlm Software
Jun 17, 2026
Jun 6, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
An issue was discovered in PHP Scripts Mall Investment MLM Software 2.0.2. Stored XSS was found in the the My Profile Section. This is due to lack of sanitization in the Edit Name section.
1Qualiteam
1X Cart
Jun 17, 2026
Jun 6, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
X-Cart V5 is vulnerable to XSS via the CategoryFilter2 parameter.
1Chartkick Project
1Chartkick
Jun 17, 2026
Jun 6, 2019
N/A· v4
4.7 MEDIUM· v3
2.6 LOW· v2
The Chartkick gem through 3.1.0 for Ruby allows XSS.
1Primasystems
1Flexair
Jun 17, 2026
Jun 5, 2019
N/A· v4
9.0 CRITICAL· v3
3.5 LOW· v2
Prima Systems FlexAir, Versions 2.3.38 and prior. Parameters sent to scripts are not properly sanitized before being returned to the user, which may allow an attacker to execute arbitrary code in a user’s browser session...Show more
Prima Systems FlexAir, Versions 2.3.38 and prior. Parameters sent to scripts are not properly sanitized before being returned to the user, which may allow an attacker to execute arbitrary code in a user’s browser session in context of an affected site.Show less
1Cmsmadesimple
1Cms Made Simple
Jun 17, 2026
Jun 5, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
CMS Made Simple 2.2.10 has XSS via the m1_name parameter in "Add Article" under Content -> Content Manager -> News.