CWE-79
46,217 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (46,217)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Paloaltonetworks 1Expedition Migration Tool Jun 17, 2026 Apr 9, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 The Expedition Migration tool 1.1.6 and earlier may allow an authenticated attacker to run arbitrary JavaScript or HTML in the User Mapping Settings. |
1Hp 1Integrated Lights Out 5 Firmware Jun 17, 2026 Apr 9, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 A remote Cross-Site Scripting in HPE iLO 5 Web User Interface vulnerability was identified in HPE Integrated Lights-Out 5 (iLO 5) for Gen10 ProLiant Servers earlier than version v1.40. |
The wpape APE GALLERY plugin 1.6.14 for WordPress has stored XSS via the classGallery.php getCategories function. |
Cross-site scripting vulnerability in the Discuss App of Odoo Community 12.0 and earlier, and Odoo Enterprise 12.0 and earlier allows remote attackers to inject arbitrary web script in the browser of an internal user of...Show more |
An XSS vulnerability in the Zyxel NAS 326 version 5.21 and below allows a remote authenticated attacker to inject arbitrary JavaScript or HTML via the user, group, and file-share description fields. |
1Microsoft 2Lync Server Skype For Business ServerJun 17, 2026 Apr 9, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 A spoofing vulnerability exists when a Lync Server or Skype for Business Server does not properly sanitize a specially crafted request, aka 'Skype for Business and Lync Spoofing Vulnerability'. |
1Microsoft 2Sharepoint Enterprise Server Sharepoint FoundationJun 17, 2026 Apr 9, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office SharePoint XSS Vulnera...Show more |
1Microsoft 1Team Foundation Server Jun 17, 2026 Apr 9, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 A Cross-site Scripting (XSS) vulnerability exists when Team Foundation Server does not properly sanitize user provided input, aka 'Team Foundation Server Cross-site Scripting Vulnerability'. |
2Fedoraproject Khanacademy2Fedora Simple MarkdownJun 17, 2026 Apr 9, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 simple-markdown.js in Khan Academy simple-markdown before 0.4.4 allows XSS via a data: or vbscript: URI. |
In clearFilter() in utilities.php in Cacti before 1.2.3, no escaping occurs before printing out the value of the SNMP community string (SNMP Options) in the View poller cache, leading to XSS. |
In Materialize through 1.0.0, XSS is possible via the Toast feature. |
In Materialize through 1.0.0, XSS is possible via the Autocomplete feature. |
In Materialize through 1.0.0, XSS is possible via the Tooltip feature. |
OSIsoft PI Vision, versions PI Vision 2017, and PI Vision 2017 R2, The application contains a cross-site scripting vulnerability where displays that reference AF elements and attributes containing JavaScript are affected...Show more |
Parsedown before 1.7.2, when safe mode is used and HTML markup is disabled, might allow attackers to execute arbitrary JavaScript code if a script (already running on the affected page) executes the contents of any eleme...Show more |
2Debian Roundup Tracker2Debian Linux RoundupJun 17, 2026 Apr 6, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Roundup 1.6 allows XSS via the URI because frontends/roundup.cgi and roundup/cgi/wsgi_handler.py mishandle 404 errors. |
A reflected HTML injection vulnerability on Salicru SLC-20-cube3(5) devices running firmware version cs121-SNMP v4.54.82.130611 allows remote attackers to inject arbitrary HTML elements via a /DataLog.csv?log= or /AlarmL...Show more |
An XSS combined with CSRF vulnerability discovered in SalesAgility SuiteCRM 7.x before 7.8.24 and 7.10.x before 7.10.11 leads to cookie stealing, aka session hijacking. This issue affects the "add dashboard pages" featur...Show more |
1Cisco 2Rv320 Firmware Rv325 FirmwareJun 17, 2026 Apr 4, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 A vulnerability in the Online Help web service of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting (XSS) attack...Show more |
1Apple 5Icloud Iphone OsItunes+2 moreNov 21, 2024 Apr 3, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 A cross-site scripting issue existed in Safari. This issue was addressed with improved URL validation. This issue affected versions prior to iOS 12.1, watchOS 5.1, Safari 12.0.1, iTunes 12.9.1, iCloud for Windows 7.8. |