CWE-79
46,263 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (46,263)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
An issue was discovered in app/webroot/js/misp.js in MISP before 2.4.107. There is persistent XSS via image names in titles, as demonstrated by a screenshot. |
An issue was discovered in app/View/Elements/Events/View/value_field.ctp in MISP before 2.4.107. There is persistent XSS via link type attributes with javascript:// links. |
A persistent XSS issue was discovered in app/View/Helper/CommandHelper.php in MISP before 2.4.107. JavaScript can be included in the discussion interface, and can be triggered by clicking on the link. |
cgi-bin/qcmap_web_cgi on JioFi 4 jmr1140 Amtel_JMR1140_R12.07 devices has POST based reflected XSS via the Page parameter. No sanitization is performed for user input data. |
Rukovoditel through 2.4.1 allows XSS via a URL that lacks a module=users%2flogin substring. |
1Zohocorp 1Manageengine Netflow Analyzer Jun 17, 2026 May 7, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 XSS exists in Zoho ManageEngine Netflow Analyzer Professional v7.0.0.2 in the Administration zone "/netflow/jspui/linkdownalertConfig.jsp" file in the autorefTime or graphTypes parameter. |
1Zohocorp 1Manageengine Netflow Analyzer Jun 17, 2026 May 7, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 XSS exists in Zoho ManageEngine Netflow Analyzer Professional v7.0.0.2 in the Administration zone "/netflow/jspui/linkdownalertConfig.jsp" file in the groupDesc, groupName, groupID, or task parameter. |
1Alliedtelesis 18100l/8 Firmware Nov 21, 2024 May 7, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Allied Telesis 8100L/8 devices allow XSS via the edit-ipv4_interface.php vlanid or subnet_mask parameter. |
1Sonatype 1Nexus Repository Manager Jun 17, 2026 May 7, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Sonatype Nexus Repository Manager 2.x before 2.14.13 allows XSS. |
1Coppermine Gallery 1Coppermine Photo Gallery Nov 21, 2024 May 7, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 ecard.php in Coppermine Photo Gallery (CPG) 1.5.46 has XSS via the sender_name, recipient_email, greetings, or recipient_name parameter. |
An issue was discovered in Mahara 17.10 before 17.10.8, 18.04 before 18.04.4, and 18.10 before 18.10.1. The collection title is vulnerable to Cross Site Scripting (XSS) due to not escaping it when viewing the collection'...Show more |
1Sierrawireless 1Airlink Es450 Firmware Nov 21, 2024 May 6, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 An exploitable cross-site scripting vulnerability exists in the ACEManager ping_result.cgi functionality of Sierra Wireless AirLink ES450 FW 4.9.3. A specially crafted HTTP ping request can cause reflected javascript cod...Show more |
ImpressCMS 1.3.10 has XSS via the PATH_INFO to htdocs/install/index.php, htdocs/install/page_langselect.php, or htdocs/install/page_modcheck.php. |
The labels gadget in Jira before version 7.13.2, and from version 8.0.0 before version 8.0.2 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the jql parame...Show more |
The WallboardServlet resource in Jira before version 7.13.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the cyclePeriod parameter. |
1Cisco 1Prime Collaboration Assurance Jun 17, 2026 May 3, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 A vulnerability in the web-based management interface of Cisco Prime Collaboration Assurance (PCA) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-...Show more |
A vulnerability in the web-based management interface of Cisco Prime Network Registrar could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based interf...Show more |
1Cisco 1Application Policy Infrastructure Controller Jun 17, 2026 May 3, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 A vulnerability in the web-based management interface of Cisco Application Policy Infrastructure Controller (APIC) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a us...Show more |
1Cisco 3Adaptive Security Appliance Software Firepower Threat DefenseSecure Firewall Threat DefenseAug 11, 2026 May 3, 2019 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 Multiple vulnerabilities in the WebVPN service of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to conduct a cross-site s...Show more |
An issue was discovered in Open XDMoD through 7.5.0. html/gui/general/login.php has Reflected XSS via the xd_user_formal_name parameter. |