← Back
CWE-79

46,217 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (46,217)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Prometheus
Redhat
2Openshift Container Platform
Prometheus
Jun 17, 2026
Mar 26, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A stored, DOM based, cross-site scripting (XSS) flaw was found in Prometheus before version 2.7.1. An attacker could exploit this by convincing an authenticated user to visit a crafted URL on a Prometheus server, allowin...Show more
A stored, DOM based, cross-site scripting (XSS) flaw was found in Prometheus before version 2.7.1. An attacker could exploit this by convincing an authenticated user to visit a crafted URL on a Prometheus server, allowing for the execution and persistent storage of arbitrary scripts.Show less
1Control Webpanel
1Webpanel
Jun 17, 2026
Mar 26, 2019
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
CentOS-WebPanel.com (aka CWP) CentOS Web Panel through 0.9.8.763 is vulnerable to Stored/Persistent XSS for the "Package Name" field via the add_package module parameter.
1Sir
1Gnuboard
Nov 21, 2024
Mar 25, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-Site Scripting (XSS) vulnerability in point_list.php in GNUBOARD5 before 5.3.1.6 allows remote attackers to inject arbitrary web script or HTML via the popup title parameter.
1Fortinet
1Fortiportal
Nov 21, 2024
Mar 25, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A Cross-Site Scripting vulnerability in Fortinet FortiPortal versions 4.0.0 and below allows an attacker to execute unauthorized code or commands via the applicationSearch parameter in the FortiView functionality.
1Elastic
1Kibana
Jun 17, 2026
Mar 25, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Kibana versions before 5.6.15 and 6.6.1 had a cross-site scripting (XSS) vulnerability that could allow an attacker to obtain sensitive information from or perform destructive actions on behalf of other Kibana users.
1Myadrenalin
1Adrenalin
Mar 2, 2026
Mar 25, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A Reflected Cross Site Scripting (XSS) vulnerability exists in Adrenalin HRMS 5.4.0. An attacker can input malicious JavaScript code in /RPT/SSRSDynamicEditReports.aspx via 'ReportId' parameter.
1Myadrenalin
1Adrenalin
Mar 2, 2026
Mar 25, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A Reflected Cross Site Scripting (XSS) Vulnerability was discovered in Adrenalin 5.4 HRMS Software. The user supplied input containing JavaScript is echoed back in JavaScript code in an HTML response via the LeaveEmploye...Show more
A Reflected Cross Site Scripting (XSS) Vulnerability was discovered in Adrenalin 5.4 HRMS Software. The user supplied input containing JavaScript is echoed back in JavaScript code in an HTML response via the LeaveEmployeeSearch.aspx prntFrmName or prntDDLCntrlName parameter.Show less
1Moodle
1Moodle
Jun 17, 2026
Mar 25, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A flaw was found in moodle versions 3.6 to 3.6.1, 3.5 to 3.5.3, 3.4 to 3.4.6, 3.1 to 3.1.15 and earlier unsupported versions. The /userpix/ page did not escape users' full names, which are included as text when hovering...Show more
A flaw was found in moodle versions 3.6 to 3.6.1, 3.5 to 3.5.3, 3.4 to 3.4.6, 3.1 to 3.1.15 and earlier unsupported versions. The /userpix/ page did not escape users' full names, which are included as text when hovering over profile images. Note this page is not linked to by default and its access is restricted.Show less
1Moodle
1Moodle
Jun 17, 2026
Mar 25, 2019
N/A· v4
5.4 MEDIUM· v3
4.0 MEDIUM· v2
A flaw was found in Moodle versions 3.6 to 3.6.1, 3.5 to 3.5.3, 3.4 to 3.4.6, 3.1 to 3.1.15 and earlier unsupported versions. The 'manage groups' capability did not have the 'XSS risk' flag assigned to it, but does have...Show more
A flaw was found in Moodle versions 3.6 to 3.6.1, 3.5 to 3.5.3, 3.4 to 3.4.6, 3.1 to 3.1.15 and earlier unsupported versions. The 'manage groups' capability did not have the 'XSS risk' flag assigned to it, but does have that access in certain places. Note that the capability is intended for use by trusted users, and is only assigned to teachers and managers by default.Show less
1Hp
1Arcsight Logger
Jun 17, 2026
Mar 25, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Mitigates a stored/reflected XSS issue in ArcSight Logger versions prior to 6.7.
1Gforge
1Advanced Server
Jun 17, 2026
Mar 25, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
GForge Advanced Server 6.4.4 allows XSS via the commonsearch.php words parameter, as demonstrated by a snippet/search/?words= substring.
1Phpcms
1Phpcms
Jun 17, 2026
Mar 25, 2019
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
PHPCMS 9.6.x through 9.6.3 has XSS via the mailbox (aka E-mail) field on the personal information screen.
1Cmsmadesimple
1Cms Made Simple
Jun 17, 2026
Mar 24, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
CMS Made Simple 2.2.10 has XSS via the moduleinterface.php Name field, which is reachable via an "Add a new Profile" action to the File Picker.
1Thephpleague
1Commonmark
Jun 17, 2026
Mar 24, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in the PHP League CommonMark library before 0.18.3 allows remote attackers to insert unsafe links into HTML by using double-encoded HTML entities that are not properly escaped dur...Show more
Cross-site scripting (XSS) vulnerability in the PHP League CommonMark library before 0.18.3 allows remote attackers to insert unsafe links into HTML by using double-encoded HTML entities that are not properly escaped during rendering, a different vulnerability than CVE-2018-20583.Show less
1Warfareplugins
2Social Warfare
Social Warfare Pro
Jun 17, 2026
Mar 24, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_options swp_url parameter, as exploited in the wild in March 2019. This affects Social Warfare and Social...Show more
The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_options swp_url parameter, as exploited in the wild in March 2019. This affects Social Warfare and Social Warfare Pro.Show less
1Opentext
1Opentext Portal
Nov 21, 2024
Mar 22, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in OpenText Portal 7.4.4 allows remote attackers to inject arbitrary web script or HTML via the vgnextoid parameter to a menuitem URI.
1S Cms
1S Cms
Jun 17, 2026
Mar 22, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
S-CMS PHP v1.0 has XSS in 4.edu.php via the S_id parameter.
1Yop Poll
1Yop Poll
Jun 17, 2026
Mar 22, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The yop-poll plugin before 6.0.3 for WordPress has wp-admin/admin.php?page=yop-polls&action=view-votes poll_id XSS.
13cx
1Live Chat
Jun 17, 2026
Mar 22, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The wp-live-chat-support plugin before 8.0.18 for WordPress has wp-admin/admin.php?page=wplivechat-menu-gdpr-page term XSS.
1Codecabin
1Wp Go Maps
Jun 17, 2026
Mar 22, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The wp-google-maps plugin before 7.10.43 for WordPress has XSS via the wp-admin/admin.php PATH_INFO.