← Back
CWE-79

46,217 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (46,217)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Paloaltonetworks
1Expedition Migration Tool
Jun 17, 2026
Apr 9, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The Expedition Migration tool 1.1.6 and earlier may allow an authenticated attacker to run arbitrary JavaScript or HTML in the User Mapping Settings.
1Hp
1Integrated Lights Out 5 Firmware
Jun 17, 2026
Apr 9, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A remote Cross-Site Scripting in HPE iLO 5 Web User Interface vulnerability was identified in HPE Integrated Lights-Out 5 (iLO 5) for Gen10 ProLiant Servers earlier than version v1.40.
1Wpape
1Ape Gallery
Jun 17, 2026
Apr 9, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The wpape APE GALLERY plugin 1.6.14 for WordPress has stored XSS via the classGallery.php getCategories function.
1Odoo
1Odoo
Nov 21, 2024
Apr 9, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting vulnerability in the Discuss App of Odoo Community 12.0 and earlier, and Odoo Enterprise 12.0 and earlier allows remote attackers to inject arbitrary web script in the browser of an internal user of...Show more
Cross-site scripting vulnerability in the Discuss App of Odoo Community 12.0 and earlier, and Odoo Enterprise 12.0 and earlier allows remote attackers to inject arbitrary web script in the browser of an internal user of the system by tricking them into inviting a follower on a document with a crafted name.Show less
1Zyxel
1Nas326 Firmware
Jun 17, 2026
Apr 9, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
An XSS vulnerability in the Zyxel NAS 326 version 5.21 and below allows a remote authenticated attacker to inject arbitrary JavaScript or HTML via the user, group, and file-share description fields.
1Microsoft
2Lync Server
Skype For Business Server
Jun 17, 2026
Apr 9, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A spoofing vulnerability exists when a Lync Server or Skype for Business Server does not properly sanitize a specially crafted request, aka 'Skype for Business and Lync Spoofing Vulnerability'.
1Microsoft
2Sharepoint Enterprise Server
Sharepoint Foundation
Jun 17, 2026
Apr 9, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office SharePoint XSS Vulnera...Show more
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office SharePoint XSS Vulnerability'.Show less
1Microsoft
1Team Foundation Server
Jun 17, 2026
Apr 9, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A Cross-site Scripting (XSS) vulnerability exists when Team Foundation Server does not properly sanitize user provided input, aka 'Team Foundation Server Cross-site Scripting Vulnerability'.
2Fedoraproject
Khanacademy
2Fedora
Simple Markdown
Jun 17, 2026
Apr 9, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
simple-markdown.js in Khan Academy simple-markdown before 0.4.4 allows XSS via a data: or vbscript: URI.
2Cacti
Debian
2Cacti
Debian Linux
Jun 17, 2026
Apr 8, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
In clearFilter() in utilities.php in Cacti before 1.2.3, no escaping occurs before printing out the value of the SNMP community string (SNMP Options) in the View poller cache, leading to XSS.
1Materializecss
1Materialize
Jun 17, 2026
Apr 8, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In Materialize through 1.0.0, XSS is possible via the Toast feature.
1Materializecss
1Materialize
Jun 17, 2026
Apr 8, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In Materialize through 1.0.0, XSS is possible via the Autocomplete feature.
1Materializecss
1Materialize
Jun 17, 2026
Apr 8, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In Materialize through 1.0.0, XSS is possible via the Tooltip feature.
1Osisoft
1Pi Vision
Nov 21, 2024
Apr 8, 2019
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
OSIsoft PI Vision, versions PI Vision 2017, and PI Vision 2017 R2, The application contains a cross-site scripting vulnerability where displays that reference AF elements and attributes containing JavaScript are affected...Show more
OSIsoft PI Vision, versions PI Vision 2017, and PI Vision 2017 R2, The application contains a cross-site scripting vulnerability where displays that reference AF elements and attributes containing JavaScript are affected. This vulnerability requires the ability of authorized AF users to store JavaScript in AF elements and attributes.Show less
1Parsedown
1Parsedown
Jun 17, 2026
Apr 6, 2019
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
Parsedown before 1.7.2, when safe mode is used and HTML markup is disabled, might allow attackers to execute arbitrary JavaScript code if a script (already running on the affected page) executes the contents of any eleme...Show more
Parsedown before 1.7.2, when safe mode is used and HTML markup is disabled, might allow attackers to execute arbitrary JavaScript code if a script (already running on the affected page) executes the contents of any element with a specific class. This occurs because spaces are permitted in code block infostrings, which interferes with the intended behavior of a single class name beginning with the language- substring.Show less
2Debian
Roundup Tracker
2Debian Linux
Roundup
Jun 17, 2026
Apr 6, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Roundup 1.6 allows XSS via the URI because frontends/roundup.cgi and roundup/cgi/wsgi_handler.py mishandle 404 errors.
1Salicru
1Slc 20 Cube3(5)
Jun 17, 2026
Apr 5, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A reflected HTML injection vulnerability on Salicru SLC-20-cube3(5) devices running firmware version cs121-SNMP v4.54.82.130611 allows remote attackers to inject arbitrary HTML elements via a /DataLog.csv?log= or /AlarmL...Show more
A reflected HTML injection vulnerability on Salicru SLC-20-cube3(5) devices running firmware version cs121-SNMP v4.54.82.130611 allows remote attackers to inject arbitrary HTML elements via a /DataLog.csv?log= or /AlarmLog.csv?log= or /waitlog.cgi?name= or /chart.shtml?data= or /createlog.cgi?name= request.Show less
1Salesagility
1Suitecrm
Nov 21, 2024
Apr 5, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An XSS combined with CSRF vulnerability discovered in SalesAgility SuiteCRM 7.x before 7.8.24 and 7.10.x before 7.10.11 leads to cookie stealing, aka session hijacking. This issue affects the "add dashboard pages" featur...Show more
An XSS combined with CSRF vulnerability discovered in SalesAgility SuiteCRM 7.x before 7.8.24 and 7.10.x before 7.10.11 leads to cookie stealing, aka session hijacking. This issue affects the "add dashboard pages" feature where users can receive a malicious attack through a phished URL, with script executed.Show less
1Cisco
2Rv320 Firmware
Rv325 Firmware
Jun 17, 2026
Apr 4, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A vulnerability in the Online Help web service of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting (XSS) attack...Show more
A vulnerability in the Online Help web service of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the service. The vulnerability exists because the Online Help web service of an affected device insufficiently validates user-supplied input. An attacker could exploit this vulnerability by persuading a user of the service to click a malicious link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected service or access sensitive browser-based information.This vulnerability affects Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers running firmware releases prior to 1.4.2.22.Show less
1Apple
5Icloud
Iphone OsItunes+2 more
Nov 21, 2024
Apr 3, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A cross-site scripting issue existed in Safari. This issue was addressed with improved URL validation. This issue affected versions prior to iOS 12.1, watchOS 5.1, Safari 12.0.1, iTunes 12.9.1, iCloud for Windows 7.8.