← Back
CWE-79

46,263 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (46,263)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Nih
1Ncbi Toolbox
Nov 21, 2024
May 2, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An XSS vulnerability exists in wwwblast.c in the 2.0.7 through 2.2.26 legacy versions of the NCBI ToolBox via a crafted -z1 argument.
1Lantronix
1Securelinx Spider Firmware
Nov 21, 2024
May 2, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Lantronix SecureLinx Spider (SLS) 2.2+ devices have XSS in the auth.asp login page.
1Microfocus
1Open Enterprise Server
Jun 17, 2026
May 2, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A DOM based XSS vulnerability has been identified in the Netstorage component of Open Enterprise Server (OES) allowing a remote attacker to execute javascript in the victims browser by tricking the victim into clicking o...Show more
A DOM based XSS vulnerability has been identified in the Netstorage component of Open Enterprise Server (OES) allowing a remote attacker to execute javascript in the victims browser by tricking the victim into clicking on a specially crafted link. This affects OES versions OES2015SP1, OES2018, and OES2018SP1. Older versions may be affected but were not tested as they are out of support.Show less
1Zohocorp
1Manageengine Firewall Analyzer
Jun 17, 2026
May 2, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The user defined DNS name in Zoho ManageEngine Firewall Analyzer before 12.3 Build 123224 is vulnerable to stored XSS attacks.
1Apache
1Uimaducc
Jun 17, 2026
May 1, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
This vulnerability relates to the user's browser processing of DUCC webpage input data.The javascript comprising Apache UIMA DUCC (<= 2.2.2) which runs in the user's browser does not sufficiently filter user supplied inp...Show more
This vulnerability relates to the user's browser processing of DUCC webpage input data.The javascript comprising Apache UIMA DUCC (<= 2.2.2) which runs in the user's browser does not sufficiently filter user supplied inputs, which may result in unintended execution of user supplied javascript code.Show less
1Philips
1Tasy Emr
Jun 17, 2026
May 1, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
In Philips Tasy EMR, Tasy EMR Versions 3.02.1744 and prior, the software incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
1Ibm
1Sterling B2b Integrator
Jun 17, 2026
May 1, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM Sterling B2B Integrator 6.0.0.0 and 6.0.0.1 Standard Edition is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended function...Show more
IBM Sterling B2B Integrator 6.0.0.0 and 6.0.0.1 Standard Edition is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 159946.Show less
1Ibm
1Planning Analytics
Nov 21, 2024
May 1, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM Planning Analytics 2.0 through 2.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leadin...Show more
IBM Planning Analytics 2.0 through 2.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 153177.Show less
1Apache
1Archiva
Jun 17, 2026
Apr 30, 2019
N/A· v4
6.5 MEDIUM· v3
5.5 MEDIUM· v2
In Apache Archiva before 2.2.4, it may be possible to store malicious XSS code into central configuration entries, i.e. the logo URL. The vulnerability is considered as minor risk, as only users with admin role can chang...Show more
In Apache Archiva before 2.2.4, it may be possible to store malicious XSS code into central configuration entries, i.e. the logo URL. The vulnerability is considered as minor risk, as only users with admin role can change the configuration, or the communication between the browser and the Archiva server must be compromised.Show less
8Barco
BlackboxCrestron+5 more
12Am 100 Firmware
Am 101 FirmwareHd Wireless Presentation System Firmware+9 more
Jun 17, 2026
Apr 30, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
The Crestron AM-100 firmware 1.6.0.2, Crestron AM-101 firmware 2.7.0.1, Barco wePresent WiPG-1000P firmware 2.3.0.10, Barco wePresent WiPG-1600W before firmware 2.4.1.19, Extron ShareLink 200/250 firmware 2.0.3.4, Teq AV...Show more
The Crestron AM-100 firmware 1.6.0.2, Crestron AM-101 firmware 2.7.0.1, Barco wePresent WiPG-1000P firmware 2.3.0.10, Barco wePresent WiPG-1600W before firmware 2.4.1.19, Extron ShareLink 200/250 firmware 2.0.3.4, Teq AV IT WIPS710 firmware 1.1.0.7, SHARP PN-L703WA firmware 1.4.2.3, Optoma WPS-Pro firmware 1.0.0.5, Blackbox HD WPS firmware 1.0.0.5, InFocus LiteShow3 firmware 1.0.16, and InFocus LiteShow4 2.0.0.7 are vulnerable to command injection via the file_transfer.cgi HTTP endpoint. A remote, unauthenticated attacker can use this vulnerability to execute operating system commands as root.Show less
1Crestron
2Am 100 Firmware
Am 101 Firmware
Jun 17, 2026
Apr 30, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 are vulnerable to command injection via SNMP OID iso.3.6.1.4.1.3212.100.3.2.14.1. A remote, unauthenticated attacker can use this vulnerability to ex...Show more
Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 are vulnerable to command injection via SNMP OID iso.3.6.1.4.1.3212.100.3.2.14.1. A remote, unauthenticated attacker can use this vulnerability to execute operating system commands as root.Show less
1Crestron
2Am 100 Firmware
Am 101 Firmware
Jun 17, 2026
Apr 30, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 are vulnerable to command injection via SNMP OID iso.3.6.1.4.1.3212.100.3.2.9.3. A remote, unauthenticated attacker can use this vulnerability to exe...Show more
Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 are vulnerable to command injection via SNMP OID iso.3.6.1.4.1.3212.100.3.2.9.3. A remote, unauthenticated attacker can use this vulnerability to execute operating system commands as root.Show less
1Directadmin
1Directadmin
Jun 17, 2026
Apr 30, 2019
N/A· v4
6.1 MEDIUM· v3
6.8 MEDIUM· v2
The FileManager in InfinitumIT DirectAdmin through v1.561 has XSS via CMD_FILE_MANAGER, CMD_SHOW_USER, and CMD_SHOW_RESELLER; an attacker can bypass the CSRF protection with this, and take over the administration panel.
1Polarisft
1Intellect Core Banking
Nov 21, 2024
Apr 30, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
An issue was discovered in the Core and Portal modules in Polaris FT Intellect Core Banking 9.7.1. Reflected XSS exists with an authenticated session via the Customerid, formName, FrameId, or MODE parameter.
1Atlassian
8Application Links
Confluence Data CenterConfluence Server+5 more
Nov 21, 2024
Apr 30, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Application Links before version 5.0.11, from version 5.1.0 before 5.2.10, from version 5.3.0 before 5.3.6, from version 5.4.0 before 5.4.12, and from version 6.0.0 before 6.0.4 allows remote attackers to inject arbitrar...Show more
Application Links before version 5.0.11, from version 5.1.0 before 5.2.10, from version 5.3.0 before 5.3.6, from version 5.4.0 before 5.4.12, and from version 6.0.0 before 6.0.4 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the applinkStartingUrl parameter. The product is used as a plugin in various Atlassian products where the following are affected: Confluence before version 6.15.2, Crucible before version 4.7.0, Crowd before version 3.4.3, Fisheye before version 4.7.0, Jira before version 7.13.3 and 8.x before 8.1.0.Show less
1Nodebb
1Nodebb
Nov 21, 2024
Apr 30, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Controllers.outgoing in controllers/index.js in NodeBB before 0.7.3 has outgoing XSS.
1Ibm
1Jazz Reporting Service
Nov 21, 2024
Apr 29, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM Jazz Reporting Service (JRS) 6.0 through 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentia...Show more
IBM Jazz Reporting Service (JRS) 6.0 through 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 155006.Show less
1Oculus
1Oculus Browser
Jun 17, 2026
Apr 29, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A remote web page could inject arbitrary HTML code into the Oculus Browser UI, allowing an attacker to spoof UI and potentially execute code. This affects the Oculus Browser starting from version 5.2.7 until 5.7.11.
1Webidsupport
1Webid
Jun 17, 2026
Apr 29, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
WeBid 1.2.2 has reflected XSS via the id parameter to admin/deletenews.php, admin/editbannersuser.php, admin/editfaqscategory.php, or admin/excludeuser.php, or the offset parameter to admin/edituser.php.
1Esotalk
1Esotalk
Nov 21, 2024
Apr 29, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
esoTalk 1.0.0g4 has XSS via the PATH_INFO to the conversations/ URI.