← Back
CWE-79

46,265 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (46,265)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Apcupsd
Netgate
2Apcupsd
Pfsense
Jun 17, 2026
Jun 3, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Apcupsd 0.3.91_5, as used in pfSense through 2.4.4-RELEASE-p3 and other products, has an XSS issue in apcupsd_status.php.
1Veronalabs
1Wp Statistics
Jun 17, 2026
Jun 3, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The WP Statistics plugin through 12.6.5 for Wordpress has stored XSS in includes/class-wp-statistics-pages.php. This is related to an account with the Editor role creating a post with a title that contains JavaScript, to...Show more
The WP Statistics plugin through 12.6.5 for Wordpress has stored XSS in includes/class-wp-statistics-pages.php. This is related to an account with the Editor role creating a post with a title that contains JavaScript, to attack an admin user.Show less
1Pydio
1Pydio
Jun 17, 2026
May 31, 2019
N/A· v4
7.3 HIGH· v3
4.9 MEDIUM· v2
It is possible for an attacker with regular user access to the web application of Pydio through 8.2.2 to trick an administrator user into opening a link shared through the application, that in turn opens a shared file th...Show more
It is possible for an attacker with regular user access to the web application of Pydio through 8.2.2 to trick an administrator user into opening a link shared through the application, that in turn opens a shared file that contains JavaScript code (that is executed in the context of the victim user to obtain sensitive information such as session identifiers and perform actions on behalf of him/her).Show less
1Pydio
1Pydio
Jun 17, 2026
May 31, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A stored XSS vulnerability exists in the web application of Pydio through 8.2.2 that can be exploited by levering the file upload and file preview features of the application. An authenticated attacker can upload an HTML...Show more
A stored XSS vulnerability exists in the web application of Pydio through 8.2.2 that can be exploited by levering the file upload and file preview features of the application. An authenticated attacker can upload an HTML file containing JavaScript code and afterwards a file preview URL can be used to access the uploaded file. If a malicious user shares an uploaded HTML file containing JavaScript code with another user of the application, and tricks an authenticated victim into accessing a URL that results in the HTML code being interpreted by the web browser, then the included JavaScript code is executed under the context of the victim user session.Show less
1Jenkins
1Warnings Next Generation
Jun 17, 2026
May 31, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A cross-site scripting vulnerability in Jenkins Warnings NG Plugin 5.0.0 and earlier allowed attacker with Job/Configure permission to inject arbitrary JavaScript in build overview pages.
1Phprelativepath Project
1Phprelativepath
Jun 17, 2026
May 31, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An XSS vulnerability exists in PHPRelativePath (aka Relative Path) through 1.0.2 via the RelativePath.Example1.php path parameter.
1Synacor
1Zimbra Collaboration Suite
Nov 21, 2024
May 30, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Synacor Zimbra Mail Client 8.6 before 8.6.0 Patch 5 has XSS via the error/warning dialog and email body content in Zimbra.
1Synacor
1Zimbra Collaboration Server
Nov 21, 2024
May 30, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Synacor Zimbra Collaboration Server 8.x before 8.7.0 has Reflected XSS in admin console.
1Synacor
1Zimbra Collaboration Suite
Nov 21, 2024
May 30, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
There is a Persistent XSS vulnerability in the briefcase component of Synacor Zimbra Collaboration Suite (ZCS) Zimbra Web Client (ZWC) 8.8.8 before 8.8.8 Patch 7 and 8.8.9 before 8.8.9 Patch 1.
1Synacor
1Zimbra Collaboration Suite
Nov 21, 2024
May 30, 2019
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Synacor Zimbra Admin UI in Zimbra Collaboration Suite before 8.8.0 beta 2 has Persistent XSS via mail addrs.
1Webport
1Web Port
Jun 17, 2026
May 30, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Web Port 1.19.1 allows XSS via the /log type parameter.
1Webport
1Web Port
Jun 17, 2026
May 30, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Web Port 1.19.1 allows XSS via the /access/setup type parameter.
1Synacor
1Zimbra Collaboration Suite
Nov 21, 2024
May 29, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
mailboxd component in Synacor Zimbra Collaboration Suite 8.6, 8.7 before 8.7.11 Patch 7, and 8.8 before 8.8.10 Patch 2 has Persistent XSS.
1Synacor
1Zimbra Collaboration Suite
Nov 21, 2024
May 29, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Synacor Zimbra Collaboration Suite Collaboration before 8.8.11 has XSS in the AJAX and html web clients.
1Netgate
1Pfsense
Jun 17, 2026
May 29, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In pfSense 2.4.4-p3, a stored XSS vulnerability occurs when attackers inject a payload into the Name or Description field via an acme_accountkeys_edit.php action. The vulnerability occurs due to input validation errors.
1Adobe
1Experience Manager Forms
Jun 17, 2026
May 29, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Adobe Experience Manager Forms versions 6.2, 6.3 and 6.4 have a stored cross-site scripting vulnerability. Successful exploitation could lead to sensitive information disclosure.
1Ibm
1Jazz Reporting Service
Jun 17, 2026
May 29, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM Jazz Reporting Service 6.0 through 6.0.6.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially...Show more
IBM Jazz Reporting Service 6.0 through 6.0.6.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 158974.Show less
1Ibm
1Cognos Analytics
Jun 17, 2026
May 29, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM Cognos Analytics 11.0, 11.1.0, and 11.1.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially l...Show more
IBM Cognos Analytics 11.0, 11.1.0, and 11.1.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 158335.Show less
1Ibm
1Spectrum Control
Jun 17, 2026
May 29, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
IBM Tivoli Storage Productivity Center 5.2.13 through 5.3.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionali...Show more
IBM Tivoli Storage Productivity Center 5.2.13 through 5.3.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 158333.Show less
1Apache
1Tomcat
Jun 17, 2026
May 28, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The SSI printenv command in Apache Tomcat 9.0.0.M1 to 9.0.0.17, 8.5.0 to 8.5.39 and 7.0.0 to 7.0.93 echoes user provided data without escaping and is, therefore, vulnerable to XSS. SSI is disabled by default. The printen...Show more
The SSI printenv command in Apache Tomcat 9.0.0.M1 to 9.0.0.17, 8.5.0 to 8.5.39 and 7.0.0 to 7.0.93 echoes user provided data without escaping and is, therefore, vulnerable to XSS. SSI is disabled by default. The printenv command is intended for debugging and is unlikely to be present in a production website.Show less