CWE-79
46,263 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (46,263)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
EmpireCMS 7.5.0 has XSS via the from parameter to e/member/doaction.php, as demonstrated by a CSRF payload that changes the dynamic page template. The attacker can choose to resend the e/template/member/regsend.php regis...Show more |
XSS exists in the Kiboko Hostel plugin before 1.1.4 for WordPress. |
ColdFusion versions Update 1 and earlier, Update 7 and earlier, and Update 15 and earlier have a cross site scripting vulnerability. Successful exploitation could lead to information disclosure . |
1Heidelberg 1Prinect Archiver Jun 17, 2026 May 24, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 A Reflected Cross Site Scripting (XSS) Vulnerability was discovered in Heidelberg Prinect Archiver v2013 release 1.0. |
An issue was discovered in Eventum 3.5.0. /htdocs/post_note.php has XSS via the garlic_prefix parameter. |
1Zohocorp 1Manageengine Adselfservice Plus Jun 17, 2026 May 24, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 In Zoho ManageEngine ADSelfService Plus 5.x through 5704, an authorization.do cross-site Scripting (XSS) vulnerability allows for an unauthenticated manipulation of the JavaScript code by injecting the HTTP form paramete...Show more |
1Quest 1Kace Systems Management Appliance Jun 17, 2026 May 24, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in Quest KACE Systems Management Appliance before 9.1. The script at /service/kbot_service_notsoap.php is vulnerable to unauthenticated reflected XSS when user-supplied input to the METHOD GET par...Show more |
Insufficient sanitization of the query parameter in templates/html/search_opensearch.php could lead to reflected cross-site scripting or iframe injection. |
Samsung SCX-824 printers allow a reflected Cross-Site-Scripting (XSS) vulnerability that can be triggered by using the "print from file" feature, as demonstrated by the sws/swsAlert.sws?popupid=successMsg msg parameter. |
TP-Link TL-WR840N v5 00000005 devices allow XSS via the network name. The attacker must log into the router by breaking the password and going to the admin login page by THC-HYDRA to get the network name. With an XSS pay...Show more |
2Drupal Prestashop2Drupal PrestashopJun 17, 2026 May 24, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 In PrestaShop 1.7.5.2, the shop_country parameter in the install/index.php installation script/component is affected by Reflected XSS. Exploitation by a malicious actor requires the user to follow the initial stages of t...Show more |
XSS exists in Shave before 2.5.3 because output encoding is mishandled during the overwrite of an HTML element. |
1Computrols 1Computrols Building Automation System Jun 17, 2026 May 23, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Computrols CBAS 18.0.0 allows Unauthenticated Reflected Cross-Site Scripting vulnerabilities in the login page and password reset page via the username GET parameter. |
1Westermo 3Dr 250 Firmware Dr 260 FirmwareMr 260 FirmwareNov 21, 2024 May 23, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 XSS exists in the /cmdexec/cmdexe?cmd= function in Westermo DR-250 Pre-5162 and DR-260 Pre-5162 routers. |
1Zohocorp 1Manageengine Opmanager Nov 21, 2024 May 23, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 An issue was discovered in ZOHO ManageEngine OpManager 12.2. By adding a Google Map to the application, an authenticated user can upload an HTML file. This HTML file is then rendered in various locations of the applicati...Show more |
1Open Xchange 1Open Xchange Appsuite Nov 21, 2024 May 23, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 OX Software GmbH OX App Suite 7.8.4 and earlier is affected by: Cross Site Scripting (XSS). |
1Zohocorp 1Manageengine Applications Manager Nov 21, 2024 May 23, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 In Zoho ManageEngine Application Manager 13.1 Build 13100, an authenticated user, with administrative privileges, has the ability to add a widget on any dashboard. This widget can be a "Utility Widget" with a "Custom HTM...Show more |
1Open Xchange 1Open Xchange Appsuite Nov 21, 2024 May 23, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Open-Xchange GmbH OX App Suite 7.8.3 and earlier is affected by: Cross Site Scripting (XSS). |
1Open Xchange 1Open Xchange Appsuite Nov 21, 2024 May 23, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 OX Software GmbH OX App Suite 7.8.4 and earlier is affected by: Cross Site Scripting (XSS). |
1Open Xchange 1Open Xchange Appsuite Nov 21, 2024 May 23, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Open-Xchange GmbH OX App Suite 7.8.4 and earlier is affected by: Cross Site Scripting (XSS). |