← Back
CWE-79

46,217 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (46,217)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Apple
5Icloud
Iphone OsItunes+2 more
Nov 21, 2024
Apr 3, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A logic issue was addressed with improved validation. This issue affected versions prior to iOS 12.1, watchOS 5.1, Safari 12.0.1, iTunes 12.9.1, iCloud for Windows 7.8.
1Apple
5Icloud
Iphone OsItunes+2 more
Nov 21, 2024
Apr 3, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A cross-site scripting issue existed in Safari. This issue was addressed with improved URL validation. This issue affected versions prior to iOS 12, tvOS 12, Safari 12, iTunes 12.9 for Windows, iCloud for Windows 7.7.
1Apple
5Icloud
Iphone OsItunes+2 more
Nov 21, 2024
Apr 3, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A cross-site scripting issue existed in Safari. This issue was addressed with improved URL validation. This issue affected versions prior to iOS 12, tvOS 12, Safari 12, iTunes 12.9 for Windows, iCloud for Windows 7.7.
1Buttle Project
1Buttle
Jun 17, 2026
Apr 3, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
XSS in buttle npm package version 0.2.0 causes execution of attacker-provided code in the victim's browser when an attacker creates an arbitrary file on the server.
1Centos Webpanel
1Centos Web Panel
Jun 17, 2026
Apr 3, 2019
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
CentOS Web Panel (CWP) 0.9.8.789 is vulnerable to Stored/Persistent XSS for the "Name Server 1" and "Name Server 2" fields via a "DNS Functions" "Edit Nameservers IPs" action.
1Ibm
1Doors Next Generation
Nov 21, 2024
Apr 3, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM DOORS Next Generation (DNG/RRC) 5.0 through 5.0.3 and 6.0 through 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intend...Show more
IBM DOORS Next Generation (DNG/RRC) 5.0 through 5.0.3 and 6.0 through 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 152737.Show less
1Ibm
1Doors Next Generation
Nov 21, 2024
Apr 3, 2019
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
IBM DOORS Next Generation (DNG/RRC) 5.0 through 5.0.3 and 6.0 through 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intend...Show more
IBM DOORS Next Generation (DNG/RRC) 5.0 through 5.0.3 and 6.0 through 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 147710.Show less
1Open Emr
1Openemr
Nov 21, 2024
Apr 2, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A vulnerability in flashcanvas.swf in OpenEMR before 5.0.1 Patch 6 could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack on a targeted system.
1Dlink
1Dsl 3782 Firmware
Nov 21, 2024
Apr 1, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A stored XSS vulnerability exists in the web interface on D-Link DSL-3782 devices with firmware 1.01 that allows authenticated attackers to inject a JavaScript or HTML payload inside the ACL page. The injected payload wo...Show more
A stored XSS vulnerability exists in the web interface on D-Link DSL-3782 devices with firmware 1.01 that allows authenticated attackers to inject a JavaScript or HTML payload inside the ACL page. The injected payload would be executed in a user's browser when "/cgi-bin/New_GUI/Acl.asp" is requested.Show less
1Overit
1Geocall
Jun 17, 2026
Apr 1, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Multiple XSS vulnerabilities were discovered in OverIT Geocall 6.3 before build 2:346977.
1Synology
1Diskstation Manager
Jan 14, 2025
Apr 1, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-site scripting (XSS) vulnerability in Control Panel SSO Settings in Synology DiskStation Manager (DSM) before 6.2.1-23824 allows remote authenticated users to inject arbitrary web script or HTML via the URL paramet...Show more
Cross-site scripting (XSS) vulnerability in Control Panel SSO Settings in Synology DiskStation Manager (DSM) before 6.2.1-23824 allows remote authenticated users to inject arbitrary web script or HTML via the URL parameter.Show less
1Synology
1Diskstation Manager
Jan 14, 2025
Apr 1, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-site scripting (XSS) vulnerability in SYNO.Core.PersonalNotification.Event in Synology DiskStation Manager (DSM) before 6.1.4-15217-3 allows remote authenticated users to inject arbitrary web script or HTML via the...Show more
Cross-site scripting (XSS) vulnerability in SYNO.Core.PersonalNotification.Event in Synology DiskStation Manager (DSM) before 6.1.4-15217-3 allows remote authenticated users to inject arbitrary web script or HTML via the package parameter.Show less
1Wolfcms
1Wolf Cms
Jun 17, 2026
Mar 30, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Wolf CMS v0.8.3.1 is affected by cross site scripting (XSS) in the module Add Snippet (/?/admin/snippet/add). This allows an attacker to insert arbitrary JavaScript as user input, which will be executed whenever the affe...Show more
Wolf CMS v0.8.3.1 is affected by cross site scripting (XSS) in the module Add Snippet (/?/admin/snippet/add). This allows an attacker to insert arbitrary JavaScript as user input, which will be executed whenever the affected snippet is loaded.Show less
1Mybb
1Mybb
Nov 21, 2024
Mar 29, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A reflected XSS vulnerability in the ModCP Profile Editor in MyBB before 1.8.20 allows remote attackers to inject JavaScript via the 'username' parameter.
1Harmistechnology
1Je Messenger
Jun 17, 2026
Mar 29, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
An issue was discovered in the Harmis JE Messenger component 1.2.2 for Joomla!. It is possible to craft messages in a way that JavaScript gets executed on the side of the receiving user when the message is opened, aka XS...Show more
An issue was discovered in the Harmis JE Messenger component 1.2.2 for Joomla!. It is possible to craft messages in a way that JavaScript gets executed on the side of the receiving user when the message is opened, aka XSS.Show less
1Online Lottery Php Readymade Script Project
1Online Lottery Php Readymade Script
Jun 17, 2026
Mar 29, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
PHP Scripts Mall Online Lottery PHP Readymade Script 1.7.0 has Reflected Cross-site Scripting (XSS) via the err value in a .ico picture upload.
1Apache
1Jspwiki
Jun 17, 2026
Mar 28, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In Apache JSPWiki 2.9.0 to 2.11.0.M2, a carefully crafted URL could execute javascript on another user's session. No information could be saved on the server or jspwiki database, nor would an attacker be able to execute...Show more
In Apache JSPWiki 2.9.0 to 2.11.0.M2, a carefully crafted URL could execute javascript on another user's session. No information could be saved on the server or jspwiki database, nor would an attacker be able to execute js on someone else's browser; only on its own browser.Show less
1Nagios
1Nagios Xi
Jun 17, 2026
Mar 28, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in Nagios XI before 5.5.11 allows attackers to inject arbitrary web script or HTML via the xiwindow parameter.
1Jenkins
1Lockable Resources
Jun 17, 2026
Mar 28, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A cross site scripting vulnerability in Jenkins Lockable Resources Plugin 2.4 and earlier allows attackers able to control resource names to inject arbitrary JavaScript in web pages rendered by the plugin.
1Nagios
1Nagios Xi
Jun 17, 2026
Mar 28, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Command injection in Nagios XI before 5.5.11 allows an authenticated users to execute arbitrary remote commands via a new autodiscovery job.