← Back
CWE-79

46,217 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (46,217)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Totaljs
1Total.js Cms
Jun 17, 2026
Mar 28, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Total.js CMS 12.0.0 has XSS related to themes/admin/views/index.html (item.message) and themes/admin/public/ui.js (column.format).
2Misp
Misp Project
2Misp
Misp
Jun 22, 2026
Mar 28, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In MISP before 2.4.105, the app/View/Layouts/default.ctp default layout template has a Reflected XSS vulnerability.
1Sir
1Gnuboard
Nov 21, 2024
Mar 27, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-Site Scripting (XSS) vulnerability in newwinform.php in GNUBOARD5 before 5.3.1.6 allows remote attackers to inject arbitrary web script or HTML via the popup title parameter.
1Sitemagic
1Sitemagic
Jun 17, 2026
Mar 27, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Sitemagic CMS v4.4 has XSS in SMFiles/FrmUpload.class.php via the filename parameter.
1Microfocus
1Solutions Business Manager
Nov 21, 2024
Mar 27, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Reflected cross site script issue in Micro Focus Solutions Business Manager (SBM) (formerly Serena Business Manager (SBM)) versions prior to 11.5.
1Frank Karau
1Phpfk
Nov 21, 2024
Mar 27, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
phpFK lite has XSS via the faq.php, members.php, or search.php query string or the user.php user parameter.
1Kinagacms Project
1Kinagacms
Jun 17, 2026
Mar 27, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting vulnerability in KinagaCMS versions prior to 6.5 allows remote authenticated attackers to inject arbitrary web script or HTML via unspecified vectors.
1Moodle
1Moodle
Jun 17, 2026
Mar 27, 2019
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
A vulnerability was found in moodle before versions 3.6.3, 3.5.5, 3.4.8 and 3.1.17. Users with the "login as other users" capability (such as administrators/managers) can access other users' Dashboards, but the JavaScrip...Show more
A vulnerability was found in moodle before versions 3.6.3, 3.5.5, 3.4.8 and 3.1.17. Users with the "login as other users" capability (such as administrators/managers) can access other users' Dashboards, but the JavaScript those other users may have added to their Dashboard was not being escaped when being viewed by the user logging in on their behalf.Show less
1Redhat
2Jboss Enterprise Application Platform
Single Sign On
Nov 21, 2024
Mar 27, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A cross-site scripting (XSS) vulnerability was found in the JBoss Management Console versions before 7.1.6.CR1, 7.1.6.GA. Users with roles that can create objects in the application can exploit this to attack other privi...Show more
A cross-site scripting (XSS) vulnerability was found in the JBoss Management Console versions before 7.1.6.CR1, 7.1.6.GA. Users with roles that can create objects in the application can exploit this to attack other privileged users.Show less
1Snipeitapp
1Snipe It
Jun 17, 2026
Mar 27, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Snipe-IT before 4.6.14 has XSS, as demonstrated by log_meta values and the user's last name in the API.
1Select2
1Select2
Nov 21, 2024
Mar 27, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In Select2 through 4.0.5, as used in Snipe-IT and other products, rich selectlists allow XSS. This affects use cases with Ajax remote data loading when HTML templates are used to display listbox data.
1Paloaltonetworks
1Expedition
Jun 17, 2026
Mar 26, 2019
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The Expedition Migration tool 1.1.8 and earlier may allow an authenticated attacker to run arbitrary JavaScript or HTML in the RADIUS server settings.
1Paloaltonetworks
1Expedition
Jun 17, 2026
Mar 26, 2019
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The Expedition Migration tool 1.1.8 and earlier may allow an authenticated attacker to run arbitrary JavaScript or HTML in the LDAP server settings.
1Paloaltonetworks
1Expedition
Jun 17, 2026
Mar 26, 2019
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The Expedition Migration tool 1.1.8 and earlier may allow an authenticated attacker to run arbitrary JavaScript or HTML in the User Mapping Settings for account name of admin user.
1Cmsmadesimple
1Cms Made Simple
Jun 17, 2026
Mar 26, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
CMS Made Simple 2.2.10 has XSS via the myaccount.php "Email Address" field, which is reachable via the "My Preferences -> My Account" section.
1Cmsmadesimple
1Cms Made Simple
Jun 17, 2026
Mar 26, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
CMS Made Simple 2.2.10 has XSS via the 'moduleinterface.php' Name field, which is reachable via an "Add Category" action to the "Site Admin Settings - News module" section.
1Cmsmadesimple
1Cms Made Simple
Jun 17, 2026
Mar 26, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
CMS Made Simple 2.2.10 has a Self-XSS vulnerability via the Layout Design Manager "Name" field, which is reachable via a "Create a new Template" action to the Design Manager.
1Wikindx Project
1Wikindx
Jun 17, 2026
Mar 26, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A cross-site scripting (XSS) vulnerability in ressource view in core/modules/resource/RESOURCEVIEW.php in Wikindx prior to version 5.7.0 allows remote attackers to inject arbitrary web script or HTML via the id parameter...Show more
A cross-site scripting (XSS) vulnerability in ressource view in core/modules/resource/RESOURCEVIEW.php in Wikindx prior to version 5.7.0 allows remote attackers to inject arbitrary web script or HTML via the id parameter.Show less
1Tibco
2Data Science For Aws
Spotfire Data Science
Jun 17, 2026
Mar 26, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The application server component of TIBCO Software Inc.'s TIBCO Data Science for AWS, and TIBCO Spotfire Data Science contains a persistent cross-site scripting vulnerability that theoretically allows an authenticated us...Show more
The application server component of TIBCO Software Inc.'s TIBCO Data Science for AWS, and TIBCO Spotfire Data Science contains a persistent cross-site scripting vulnerability that theoretically allows an authenticated user to gain access to all the capabilities of the web interface available to more privileged users. Affected releases are TIBCO Software Inc.'s TIBCO Data Science for AWS: versions up to and including 6.4.0, and TIBCO Spotfire Data Science: versions up to and including 6.4.0.Show less
3Debian
DrupalFedoraproject
3Debian Linux
DrupalFedora
Jun 17, 2026
Mar 26, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
In Drupal 7 versions prior to 7.65; Drupal 8.6 versions prior to 8.6.13;Drupal 8.5 versions prior to 8.5.14. Under certain circumstances the File module/subsystem allows a malicious user to upload a file that can trigger...Show more
In Drupal 7 versions prior to 7.65; Drupal 8.6 versions prior to 8.6.13;Drupal 8.5 versions prior to 8.5.14. Under certain circumstances the File module/subsystem allows a malicious user to upload a file that can trigger a cross-site scripting (XSS) vulnerability.Show less