← Back
CWE-79

46,263 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (46,263)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Wso2
1Dashboard Server
Jun 17, 2026
May 14, 2019
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
An issue was discovered in WSO2 Dashboard Server 2.0.0. It is possible to inject a JavaScript payload that will be stored in the database and then displayed and executed on the same page, aka XSS.
1Ipbrick
1Ipbrick Os
Nov 21, 2024
May 13, 2019
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
An issue was discovered in the administration page in IPBRICK OS 6.3. There are multiple XSS vulnerabilities.
1Bibliosoft
1Bibliopac
Nov 21, 2024
May 13, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in BIBLIOsoft BIBLIOpac 2008 allows remote attackers to inject arbitrary web script or HTML via the db or action parameter to to bin/wxis.exe/bibliopac/.
1Gridea
1Gridea
Jun 17, 2026
May 13, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Gridea v0.8.0 has an XSS vulnerability through which the Nodejs module can be called to achieve arbitrary code execution, as demonstrated by child_process.exec and the "<img src=# onerror='eval(new Buffer(" substring.
1Control Webpanel
1Webpanel
Jun 17, 2026
May 13, 2019
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.793 (Free/Open Source Version), 0.9.8.753 (Pro) and 0.9.8.807 (Pro) is vulnerable to Reflected XSS for the "Domain" field on the "DNS Functions > "Add DNS Zone" screen...Show more
CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.793 (Free/Open Source Version), 0.9.8.753 (Pro) and 0.9.8.807 (Pro) is vulnerable to Reflected XSS for the "Domain" field on the "DNS Functions > "Add DNS Zone" screen.Show less
1Mythemeshop
1Launcher
Jun 17, 2026
May 13, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Multiple stored cross-site scripting (XSS) in the MyThemeShop Launcher plugin 1.0.8 for WordPress allow remote authenticated users to inject arbitrary web script or HTML via fields as follows: (1) Title, (2) Favicon, (3)...Show more
Multiple stored cross-site scripting (XSS) in the MyThemeShop Launcher plugin 1.0.8 for WordPress allow remote authenticated users to inject arbitrary web script or HTML via fields as follows: (1) Title, (2) Favicon, (3) Meta Description, (4) Subscribe Form (Name field label, Last name field label, Email field label), (5) Contact Form (Name field label and Email field label), and (6) Social Links (Facebook Page URL, Twitter Page URL, Instagram Page URL, YouTube Page URL, Linkedin Page URL, Google+ Page URL, RSS URL).Show less
1Vegadesign
1Profiledesign Cms
Jun 17, 2026
May 13, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Multiple cross-site scripting (XSS) vulnerabilities in ProfileDesign CMS v6.0.2.5 allows remote attackers to inject arbitrary web script or HTML via the (1) page, (2) gbs, (3) side, (4) id, (5) imgid, (6) cat, or (7) ord...Show more
Multiple cross-site scripting (XSS) vulnerabilities in ProfileDesign CMS v6.0.2.5 allows remote attackers to inject arbitrary web script or HTML via the (1) page, (2) gbs, (3) side, (4) id, (5) imgid, (6) cat, or (7) orderby parameter.Show less
1Remarkable Project
1Remarkable
Jun 17, 2026
May 13, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In remarkable 1.7.1, lib/parser_inline.js mishandles URL filtering, which allows attackers to trigger XSS via unprintable characters, as demonstrated by a \x0ejavascript: URL.
1Mycolorway
1Simditor
Nov 21, 2024
May 13, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Simditor through 2.3.21 allows DOM XSS via an onload attribute within a malformed SVG element.
1Kieranoshea
1Calendar
Nov 21, 2024
May 13, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The Kieran O'Shea Calendar plugin before 1.3.11 for WordPress has Stored XSS via the event_title parameter in a wp-admin/admin.php?page=calendar add action, or the category name during category creation at the wp-admin/a...Show more
The Kieran O'Shea Calendar plugin before 1.3.11 for WordPress has Stored XSS via the event_title parameter in a wp-admin/admin.php?page=calendar add action, or the category name during category creation at the wp-admin/admin.php?page=calendar-categories URI.Show less
1Evernote
1Evernote
Nov 21, 2024
May 13, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Evernote 6.15 on Windows has an incorrectly repaired stored XSS vulnerability. An attacker can use this XSS issue to inject Node.js code under Present mode. After a victim opens an affected note under Present mode, the a...Show more
Evernote 6.15 on Windows has an incorrectly repaired stored XSS vulnerability. An attacker can use this XSS issue to inject Node.js code under Present mode. After a victim opens an affected note under Present mode, the attacker can read the victim's files and achieve remote execution command on the victim's computer.Show less
1Typesettercms
1Typesetter
Nov 21, 2024
May 13, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Typesetter 5.1 allows XSS via the index.php/Admin LABEL parameter during new page creation.
1Typesettercms
1Typesetter
Nov 21, 2024
May 13, 2019
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
index.php/Admin/Classes in Typesetter 5.1 allows XSS via the description of a new class name.
1Typesettercms
1Typesetter
Nov 21, 2024
May 13, 2019
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
index.php/Admin/Uploaded in Typesetter 5.1 allows XSS via an SVG file with JavaScript in a SCRIPT element.
1Getkirby
1Kirby
Nov 21, 2024
May 13, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
panel/pages/home/edit in Kirby v2.5.12 allows XSS via the title of a new page.
1Getkirby
1Kirby
Nov 21, 2024
May 13, 2019
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Kirby V2.5.12 is prone to a Persistent XSS attack via the Title of the "Site options" in the admin panel dashboard dropdown.
1Xerox
1Colorqube 8580 Firmware
Nov 21, 2024
May 13, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) in the web interface of the Xerox ColorQube 8580 allows remote persistent injection of custom HTML / JavaScript code.
1Asus
1Rt Ac3200 Firmware
Nov 21, 2024
May 13, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting in appGet.cgi on ASUS RT-AC3200 version 3.0.0.4.382.50010 allows attackers to execute JavaScript via the "hook" URL parameter.
1Seagate
1Nas Os
Nov 21, 2024
May 13, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting in Application Manager in Seagate NAS OS version 4.3.15.1 allows attackers to execute JavaScript via multiple application metadata fields: Short Description, Publisher Name, Publisher Contact, or Web...Show more
Cross-site scripting in Application Manager in Seagate NAS OS version 4.3.15.1 allows attackers to execute JavaScript via multiple application metadata fields: Short Description, Publisher Name, Publisher Contact, or Website URL.Show less
1Seagate
1Nas Os
Nov 21, 2024
May 13, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-site scripting in filebrowser in Seagate NAS OS version 4.3.15.1 allows attackers to execute JavaScript via directory names.