CWE-79
46,265 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (46,265)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Apcupsd Netgate2Apcupsd PfsenseJun 17, 2026 Jun 3, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Apcupsd 0.3.91_5, as used in pfSense through 2.4.4-RELEASE-p3 and other products, has an XSS issue in apcupsd_status.php. |
The WP Statistics plugin through 12.6.5 for Wordpress has stored XSS in includes/class-wp-statistics-pages.php. This is related to an account with the Editor role creating a post with a title that contains JavaScript, to...Show more |
It is possible for an attacker with regular user access to the web application of Pydio through 8.2.2 to trick an administrator user into opening a link shared through the application, that in turn opens a shared file th...Show more |
A stored XSS vulnerability exists in the web application of Pydio through 8.2.2 that can be exploited by levering the file upload and file preview features of the application. An authenticated attacker can upload an HTML...Show more |
1Jenkins 1Warnings Next Generation Jun 17, 2026 May 31, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 A cross-site scripting vulnerability in Jenkins Warnings NG Plugin 5.0.0 and earlier allowed attacker with Job/Configure permission to inject arbitrary JavaScript in build overview pages. |
1Phprelativepath Project 1Phprelativepath Jun 17, 2026 May 31, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 An XSS vulnerability exists in PHPRelativePath (aka Relative Path) through 1.0.2 via the RelativePath.Example1.php path parameter. |
1Synacor 1Zimbra Collaboration Suite Nov 21, 2024 May 30, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Synacor Zimbra Mail Client 8.6 before 8.6.0 Patch 5 has XSS via the error/warning dialog and email body content in Zimbra. |
1Synacor 1Zimbra Collaboration Server Nov 21, 2024 May 30, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Synacor Zimbra Collaboration Server 8.x before 8.7.0 has Reflected XSS in admin console. |
1Synacor 1Zimbra Collaboration Suite Nov 21, 2024 May 30, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 There is a Persistent XSS vulnerability in the briefcase component of Synacor Zimbra Collaboration Suite (ZCS) Zimbra Web Client (ZWC) 8.8.8 before 8.8.8 Patch 7 and 8.8.9 before 8.8.9 Patch 1. |
1Synacor 1Zimbra Collaboration Suite Nov 21, 2024 May 30, 2019 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 Synacor Zimbra Admin UI in Zimbra Collaboration Suite before 8.8.0 beta 2 has Persistent XSS via mail addrs. |
Web Port 1.19.1 allows XSS via the /log type parameter. |
Web Port 1.19.1 allows XSS via the /access/setup type parameter. |
1Synacor 1Zimbra Collaboration Suite Nov 21, 2024 May 29, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 mailboxd component in Synacor Zimbra Collaboration Suite 8.6, 8.7 before 8.7.11 Patch 7, and 8.8 before 8.8.10 Patch 2 has Persistent XSS. |
1Synacor 1Zimbra Collaboration Suite Nov 21, 2024 May 29, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Synacor Zimbra Collaboration Suite Collaboration before 8.8.11 has XSS in the AJAX and html web clients. |
In pfSense 2.4.4-p3, a stored XSS vulnerability occurs when attackers inject a payload into the Name or Description field via an acme_accountkeys_edit.php action. The vulnerability occurs due to input validation errors. |
1Adobe 1Experience Manager Forms Jun 17, 2026 May 29, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Adobe Experience Manager Forms versions 6.2, 6.3 and 6.4 have a stored cross-site scripting vulnerability. Successful exploitation could lead to sensitive information disclosure. |
IBM Jazz Reporting Service 6.0 through 6.0.6.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially...Show more |
IBM Cognos Analytics 11.0, 11.1.0, and 11.1.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially l...Show more |
IBM Tivoli Storage Productivity Center 5.2.13 through 5.3.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionali...Show more |
The SSI printenv command in Apache Tomcat 9.0.0.M1 to 9.0.0.17, 8.5.0 to 8.5.39 and 7.0.0 to 7.0.93 echoes user provided data without escaping and is, therefore, vulnerable to XSS. SSI is disabled by default. The printen...Show more |