← Back
CWE-79

46,263 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (46,263)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Phome
1Empirecms
Jun 17, 2026
May 27, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
EmpireCMS 7.5.0 has XSS via the from parameter to e/member/doaction.php, as demonstrated by a CSRF payload that changes the dynamic page template. The attacker can choose to resend the e/template/member/regsend.php regis...Show more
EmpireCMS 7.5.0 has XSS via the from parameter to e/member/doaction.php, as demonstrated by a CSRF payload that changes the dynamic page template. The attacker can choose to resend the e/template/member/regsend.php registered activation mail page.Show less
1Kibokolabs
1Hostel
Jun 17, 2026
May 27, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
XSS exists in the Kiboko Hostel plugin before 1.1.4 for WordPress.
1Adobe
1Coldfusion
Jun 17, 2026
May 24, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
ColdFusion versions Update 1 and earlier, Update 7 and earlier, and Update 15 and earlier have a cross site scripting vulnerability. Successful exploitation could lead to information disclosure .
1Heidelberg
1Prinect Archiver
Jun 17, 2026
May 24, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A Reflected Cross Site Scripting (XSS) Vulnerability was discovered in Heidelberg Prinect Archiver v2013 release 1.0.
1Eventum Project
1Eventum
Nov 21, 2024
May 24, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in Eventum 3.5.0. /htdocs/post_note.php has XSS via the garlic_prefix parameter.
1Zohocorp
1Manageengine Adselfservice Plus
Jun 17, 2026
May 24, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In Zoho ManageEngine ADSelfService Plus 5.x through 5704, an authorization.do cross-site Scripting (XSS) vulnerability allows for an unauthenticated manipulation of the JavaScript code by injecting the HTTP form paramete...Show more
In Zoho ManageEngine ADSelfService Plus 5.x through 5704, an authorization.do cross-site Scripting (XSS) vulnerability allows for an unauthenticated manipulation of the JavaScript code by injecting the HTTP form parameter adscsrf. An attacker can use this to capture a user's AD self-service password reset and MFA token.Show less
1Quest
1Kace Systems Management Appliance
Jun 17, 2026
May 24, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in Quest KACE Systems Management Appliance before 9.1. The script at /service/kbot_service_notsoap.php is vulnerable to unauthenticated reflected XSS when user-supplied input to the METHOD GET par...Show more
An issue was discovered in Quest KACE Systems Management Appliance before 9.1. The script at /service/kbot_service_notsoap.php is vulnerable to unauthenticated reflected XSS when user-supplied input to the METHOD GET parameter is processed by the web application. Since the application does not properly validate and sanitize this parameter, it is possible to place arbitrary script code into the context of the same page.Show less
1Doxygen
1Doxygen
Nov 21, 2024
May 24, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Insufficient sanitization of the query parameter in templates/html/search_opensearch.php could lead to reflected cross-site scripting or iframe injection.
1Samsung
1Scx 824 Firmware
Jun 17, 2026
May 24, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Samsung SCX-824 printers allow a reflected Cross-Site-Scripting (XSS) vulnerability that can be triggered by using the "print from file" feature, as demonstrated by the sws/swsAlert.sws?popupid=successMsg msg parameter.
1Tp Link
1Tl Wr840n Firmware
Jun 17, 2026
May 24, 2019
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
TP-Link TL-WR840N v5 00000005 devices allow XSS via the network name. The attacker must log into the router by breaking the password and going to the admin login page by THC-HYDRA to get the network name. With an XSS pay...Show more
TP-Link TL-WR840N v5 00000005 devices allow XSS via the network name. The attacker must log into the router by breaking the password and going to the admin login page by THC-HYDRA to get the network name. With an XSS payload, the network name changed automatically and the internet connection was disconnected. All the users become disconnected from the internet.Show less
2Drupal
Prestashop
2Drupal
Prestashop
Jun 17, 2026
May 24, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In PrestaShop 1.7.5.2, the shop_country parameter in the install/index.php installation script/component is affected by Reflected XSS. Exploitation by a malicious actor requires the user to follow the initial stages of t...Show more
In PrestaShop 1.7.5.2, the shop_country parameter in the install/index.php installation script/component is affected by Reflected XSS. Exploitation by a malicious actor requires the user to follow the initial stages of the setup (accepting terms and conditions) before executing the malicious link.Show less
1Dollarshaveclub
1Shave
Jun 17, 2026
May 24, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
XSS exists in Shave before 2.5.3 because output encoding is mishandled during the overwrite of an HTML element.
1Computrols
1Computrols Building Automation System
Jun 17, 2026
May 23, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Computrols CBAS 18.0.0 allows Unauthenticated Reflected Cross-Site Scripting vulnerabilities in the login page and password reset page via the username GET parameter.
1Westermo
3Dr 250 Firmware
Dr 260 FirmwareMr 260 Firmware
Nov 21, 2024
May 23, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
XSS exists in the /cmdexec/cmdexe?cmd= function in Westermo DR-250 Pre-5162 and DR-260 Pre-5162 routers.
1Zohocorp
1Manageengine Opmanager
Nov 21, 2024
May 23, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
An issue was discovered in ZOHO ManageEngine OpManager 12.2. By adding a Google Map to the application, an authenticated user can upload an HTML file. This HTML file is then rendered in various locations of the applicati...Show more
An issue was discovered in ZOHO ManageEngine OpManager 12.2. By adding a Google Map to the application, an authenticated user can upload an HTML file. This HTML file is then rendered in various locations of the application. JavaScript inside the uploaded HTML is also interpreted by the application. Thus, an attacker can inject a malicious JavaScript payload inside the HTML file and upload it to the application.Show less
1Open Xchange
1Open Xchange Appsuite
Nov 21, 2024
May 23, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
OX Software GmbH OX App Suite 7.8.4 and earlier is affected by: Cross Site Scripting (XSS).
1Zohocorp
1Manageengine Applications Manager
Nov 21, 2024
May 23, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In Zoho ManageEngine Application Manager 13.1 Build 13100, an authenticated user, with administrative privileges, has the ability to add a widget on any dashboard. This widget can be a "Utility Widget" with a "Custom HTM...Show more
In Zoho ManageEngine Application Manager 13.1 Build 13100, an authenticated user, with administrative privileges, has the ability to add a widget on any dashboard. This widget can be a "Utility Widget" with a "Custom HTML or Text" field. Once this widget is created, it will be loaded on the dashboard where it was added. An attacker can abuse this functionality by creating a "Utility Widget" that contains malicious JavaScript code, aka XSS.Show less
1Open Xchange
1Open Xchange Appsuite
Nov 21, 2024
May 23, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Open-Xchange GmbH OX App Suite 7.8.3 and earlier is affected by: Cross Site Scripting (XSS).
1Open Xchange
1Open Xchange Appsuite
Nov 21, 2024
May 23, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
OX Software GmbH OX App Suite 7.8.4 and earlier is affected by: Cross Site Scripting (XSS).
1Open Xchange
1Open Xchange Appsuite
Nov 21, 2024
May 23, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Open-Xchange GmbH OX App Suite 7.8.4 and earlier is affected by: Cross Site Scripting (XSS).