CWE-79
46,217 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (46,217)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Total.js CMS 12.0.0 has XSS related to themes/admin/views/index.html (item.message) and themes/admin/public/ui.js (column.format). |
In MISP before 2.4.105, the app/View/Layouts/default.ctp default layout template has a Reflected XSS vulnerability. |
Cross-Site Scripting (XSS) vulnerability in newwinform.php in GNUBOARD5 before 5.3.1.6 allows remote attackers to inject arbitrary web script or HTML via the popup title parameter. |
Sitemagic CMS v4.4 has XSS in SMFiles/FrmUpload.class.php via the filename parameter. |
1Microfocus 1Solutions Business Manager Nov 21, 2024 Mar 27, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Reflected cross site script issue in Micro Focus Solutions Business Manager (SBM) (formerly Serena Business Manager (SBM)) versions prior to 11.5. |
phpFK lite has XSS via the faq.php, members.php, or search.php query string or the user.php user parameter. |
1Kinagacms Project 1Kinagacms Jun 17, 2026 Mar 27, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Cross-site scripting vulnerability in KinagaCMS versions prior to 6.5 allows remote authenticated attackers to inject arbitrary web script or HTML via unspecified vectors. |
A vulnerability was found in moodle before versions 3.6.3, 3.5.5, 3.4.8 and 3.1.17. Users with the "login as other users" capability (such as administrators/managers) can access other users' Dashboards, but the JavaScrip...Show more |
1Redhat 2Jboss Enterprise Application Platform Single Sign OnNov 21, 2024 Mar 27, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 A cross-site scripting (XSS) vulnerability was found in the JBoss Management Console versions before 7.1.6.CR1, 7.1.6.GA. Users with roles that can create objects in the application can exploit this to attack other privi...Show more |
Snipe-IT before 4.6.14 has XSS, as demonstrated by log_meta values and the user's last name in the API. |
In Select2 through 4.0.5, as used in Snipe-IT and other products, rich selectlists allow XSS. This affects use cases with Ajax remote data loading when HTML templates are used to display listbox data. |
The Expedition Migration tool 1.1.8 and earlier may allow an authenticated attacker to run arbitrary JavaScript or HTML in the RADIUS server settings. |
The Expedition Migration tool 1.1.8 and earlier may allow an authenticated attacker to run arbitrary JavaScript or HTML in the LDAP server settings. |
The Expedition Migration tool 1.1.8 and earlier may allow an authenticated attacker to run arbitrary JavaScript or HTML in the User Mapping Settings for account name of admin user. |
1Cmsmadesimple 1Cms Made Simple Jun 17, 2026 Mar 26, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 CMS Made Simple 2.2.10 has XSS via the myaccount.php "Email Address" field, which is reachable via the "My Preferences -> My Account" section. |
1Cmsmadesimple 1Cms Made Simple Jun 17, 2026 Mar 26, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 CMS Made Simple 2.2.10 has XSS via the 'moduleinterface.php' Name field, which is reachable via an "Add Category" action to the "Site Admin Settings - News module" section. |
1Cmsmadesimple 1Cms Made Simple Jun 17, 2026 Mar 26, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 CMS Made Simple 2.2.10 has a Self-XSS vulnerability via the Layout Design Manager "Name" field, which is reachable via a "Create a new Template" action to the Design Manager. |
A cross-site scripting (XSS) vulnerability in ressource view in core/modules/resource/RESOURCEVIEW.php in Wikindx prior to version 5.7.0 allows remote attackers to inject arbitrary web script or HTML via the id parameter...Show more |
1Tibco 2Data Science For Aws Spotfire Data ScienceJun 17, 2026 Mar 26, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 The application server component of TIBCO Software Inc.'s TIBCO Data Science for AWS, and TIBCO Spotfire Data Science contains a persistent cross-site scripting vulnerability that theoretically allows an authenticated us...Show more |
3Debian DrupalFedoraproject3Debian Linux DrupalFedoraJun 17, 2026 Mar 26, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 In Drupal 7 versions prior to 7.65; Drupal 8.6 versions prior to 8.6.13;Drupal 8.5 versions prior to 8.5.14. Under certain circumstances the File module/subsystem allows a malicious user to upload a file that can trigger...Show more |