← Back
CWE-79

46,263 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (46,263)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Seagate
1Nas Os
Nov 21, 2024
May 13, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Missing HTTPOnly flag on session cookies in the Seagate NAS OS version 4.3.15.1 web application allows attackers to steal session tokens via cross-site scripting.
1Seagate
1Nas Os
Nov 21, 2024
May 13, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-site scripting in filebrowser in Seagate NAS OS version 4.3.15.1 allows attackers to execute JavaScript via uploaded file names.
1Seagate
1Nas Os
Nov 21, 2024
May 13, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting in API error pages in Seagate NAS OS version 4.3.15.1 allows attackers to execute JavaScript via URL path names.
1Magazine3
1Amp For Wp
Nov 21, 2024
May 13, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
ampforwp_save_steps_data in the AMP for WP plugin before 0.9.97.21 for WordPress allows stored XSS.
2Arubanetworks
Siemens
2Aruba Instant
Scalance W1750d Firmware
Jun 17, 2026
May 10, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A reflected cross-site scripting (XSS) vulnerability is present in an unauthenticated Aruba Instant web interface. An attacker could use this vulnerability to trick an IAP administrator into clicking a link which could t...Show more
A reflected cross-site scripting (XSS) vulnerability is present in an unauthenticated Aruba Instant web interface. An attacker could use this vulnerability to trick an IAP administrator into clicking a link which could then take administrative actions on the Instant cluster, or expose the session cookie for an administrative session. Workaround: Administrators should make sure they log out of the Aruba Instant UI when not actively managing the system, and should use caution clicking links from external sources while logged into the IAP administrative interface. Resolution: Fixed in Aruba Instant 4.2.4.12, 6.5.4.11, 8.3.0.6, and 8.4.0.0Show less
1Ibm
2Business Automation Workflow
Business Process Manager
Jun 17, 2026
May 10, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM Business Automation Workflow 18.0.0.0, 18.0.0.1, 18.0.0.2, and 19.0.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intend...Show more
IBM Business Automation Workflow 18.0.0.0, 18.0.0.1, 18.0.0.2, and 19.0.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 159125.Show less
1Open Xchange
1Open Xchange Appsuite
Nov 21, 2024
May 10, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
OX Software GmbH App Suite 7.8.4 and earlier is affected by: Cross Site Scripting (XSS).
1Custom Field Suite Project
1Custom Field Suite
Jun 17, 2026
May 10, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The Custom Field Suite plugin before 2.5.15 for WordPress has XSS for editors or admins.
1S9y
1Serendipity
Jun 17, 2026
May 9, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Serendipity before 2.1.5 has XSS via EXIF data that is mishandled in the templates/2k11/admin/media_choose.tpl Editor Preview feature or the templates/2k11/admin/media_items.tpl Media Library feature.
1Yuzopro
1Yuzo
Jun 17, 2026
May 9, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Yuzo Related Posts plugin 5.12.94 for WordPress has XSS because it mistakenly expects that is_admin() verifies that the request comes from an admin user (it actually only verifies that the request is for an admin pag...Show more
The Yuzo Related Posts plugin 5.12.94 for WordPress has XSS because it mistakenly expects that is_admin() verifies that the request comes from an admin user (it actually only verifies that the request is for an admin page). An unauthenticated attacker can inject a payload into the plugin settings, such as the yuzo_related_post_css_and_style setting.Show less
1Typesettercms
1Typesetter
Nov 21, 2024
May 9, 2019
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
include/admin/Menu/Ajax.php in Typesetter 5.1 has index.php/Admin/Menu/Ajax?cmd=AddHidden title XSS.
1Paloaltonetworks
1Demisto
Jun 17, 2026
May 9, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in Palo Alto Networks Demisto 4.5 build 40249 may allow an unauthenticated attacker to run arbitrary JavaScript or HTML.
1Metinfo
1Metinfo
Nov 21, 2024
May 9, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Multiple cross-site scripting (XSS) vulnerabilities in admin/index.php in Metinfo 5.3.18 allows remote attackers to inject arbitrary web script or HTML via the (1) class1 parameter or the (2) anyid parameter.
1Intelliants
1Subrion Cms
Jun 17, 2026
May 8, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Subrion CMS 4.2.1 allows _core/en/contacts/ XSS via the name, email, or phone parameter.
1Ulicms
1Ulicms
Jun 17, 2026
May 8, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Multiple cross-site scripting (XSS) vulnerabilities in UliCMS 2019.2 and 2019.1 allow remote attackers to inject arbitrary web script or HTML via the go parameter to admin/index.php, the go parameter to /admin/index.php?...Show more
Multiple cross-site scripting (XSS) vulnerabilities in UliCMS 2019.2 and 2019.1 allow remote attackers to inject arbitrary web script or HTML via the go parameter to admin/index.php, the go parameter to /admin/index.php?register=register, or the error parameter to admin/index.php?action=favicon.Show less
1Ivanti
1Connect Secure
Jun 17, 2026
May 8, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In Pulse Secure Pulse Connect Secure (PCS) 8.3.x before 8.3R7.1 and 9.0.x before 9.0R3, an XSS issue has been found on the Application Launcher page.
1Alkacon
1Opencms
Jun 17, 2026
May 8, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Alkacon OpenCMS v10.5.4 and before is affected by stored cross site scripting (XSS) in the module New User (/opencms/system/workplace/admin/accounts/user_new.jsp). This allows an attacker to insert arbitrary JavaScript a...Show more
Alkacon OpenCMS v10.5.4 and before is affected by stored cross site scripting (XSS) in the module New User (/opencms/system/workplace/admin/accounts/user_new.jsp). This allows an attacker to insert arbitrary JavaScript as user input (First Name or Last Name), which will be executed whenever the affected snippet is loaded.Show less
1Oneshield
1Oneshield Policy
Jun 17, 2026
May 8, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Persistent XSS has been found in the OneShield Policy (Dragon Core) framework before 5.1.10. Remote adversaries can inject malicious JavaScript into textboxes decorated with type string, which is subsequently stored to t...Show more
Persistent XSS has been found in the OneShield Policy (Dragon Core) framework before 5.1.10. Remote adversaries can inject malicious JavaScript into textboxes decorated with type string, which is subsequently stored to the applicable data store. This can be exploited remotely by both authenticated and unauthenticated users.Show less
1Humhub
1Humhub
Jun 17, 2026
May 8, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A cross-site scripting (XSS) vulnerability in HumHub 1.3.12 allows remote attackers to inject arbitrary web script or HTML via a /protected/vendor/codeception/codeception/tests/data/app/view/index.php POST request.
1Htmly
1Htmly
Jun 17, 2026
May 8, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Multiple cross-site scripting (XSS) vulnerabilities in HTMLy 2.7.4 allow remote attackers to inject arbitrary web script or HTML via the (1) destination parameter to delete feature; the (2) destination parameter to edit...Show more
Multiple cross-site scripting (XSS) vulnerabilities in HTMLy 2.7.4 allow remote attackers to inject arbitrary web script or HTML via the (1) destination parameter to delete feature; the (2) destination parameter to edit feature; (3) content parameter in the profile feature.Show less