CWE-79
46,217 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (46,217)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Nextscripts 1Social Networks Auto Poster Jun 17, 2026 Mar 22, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The social-networks-auto-poster-facebook-twitter-g plugin before 4.2.8 for WordPress has wp-admin/admin.php?page=nxssnap-reposter&action=edit item XSS. |
The kingcomposer plugin 2.7.6 for WordPress has wp-admin/admin.php?page=kc-mapper id XSS. |
The "Donation Plugin and Fundraising Platform" plugin before 2.3.1 for WordPress has wp-admin/edit.php csv XSS. |
1Hivewebstudios 1Font Organizer Jun 17, 2026 Mar 22, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The font-organizer plugin 2.1.1 for WordPress has wp-admin/options-general.php manage_font_id XSS. |
1Schneider Electric 11Bmxnoc0401 Firmware Bmxnoe0100 FirmwareBmxnoe0110 Firmware+8 moreNov 21, 2024 Mar 21, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 Reflected Cross-Site Scripting (nonpersistent) allows an attacker to craft a specific URL, which contains Java script that will be executed on the Schneider Electric Modicon BMXNOC0401, BMXNOE0100, BMXNOE0110, BMXNOE0110...Show more |
A Reflected Cross Site Scripting (XSS) Vulnerability was discovered in /s/adada/cfiles/upload in Humhub 1.3.10 Community Edition. The user-supplied input containing JavaScript in the filename is echoed back in JavaScript...Show more |
A Reflected Cross Site Scripting (XSS) Vulnerability was discovered in file/file/upload in Humhub 1.3.10 Community Edition. The user-supplied input containing a JavaScript payload in the filename parameter is echoed back...Show more |
1Vertrigoserv Project 1Vertrigoserv Jun 17, 2026 Mar 21, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 VertrigoServ 2.17 allows XSS via the /inc/extensions.php ext parameter. |
cgi-bin/qcmap_web_cgi on JioFi 4G M2S 1.0.2 devices has XSS and HTML injection via the mask POST parameter. |
1Opensource Classified Ads Script Project 1Opensource Classified Ads Script Jun 17, 2026 Mar 21, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 PHP Scripts Mall Opensource Classified Ads Script 3.2.2 has reflected Cross-Site Scripting (XSS) via the Search field. |
1Opensource Classified Ads Script Project 1Opensource Classified Ads Script Jun 17, 2026 Mar 21, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 PHP Scripts Mall Opensource Classified Ads Script 3.2.2 has reflected HTML injection via the Search Form. |
1Rental Bike Script Project 1Rental Bike Script Jun 17, 2026 Mar 21, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 PHP Scripts Mall Rental Bike Script 2.0.3 has HTML injection via the STREET field in the Profile Edit section. |
1Image Sharing Script Project 1Image Sharing Script Jun 17, 2026 Mar 21, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 PHP Scripts Mall Image Sharing Script 1.3.4 has HTML injection via the Search Bar. |
1Zohocorp 1Manageengine Netflow Analyzer Jun 17, 2026 Mar 21, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 XSS exists in Zoho ManageEngine Netflow Analyzer Professional v7.0.0.2 in the Administration zone "/netflow/jspui/linkdownalertConfig.jsp" file in the task parameter. |
1Zohocorp 1Manageengine Netflow Analyzer Jun 17, 2026 Mar 21, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 XSS exists in Zoho ManageEngine Netflow Analyzer Professional v7.0.0.2 in the Administration zone "/netflow/jspui/index.jsp" file in the view GET parameter or any of these POST parameters: autorefTime, section, snapshot,...Show more |
1Zohocorp 1Manageengine Netflow Analyzer Jun 17, 2026 Mar 21, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 XSS exists in Zoho ManageEngine Netflow Analyzer Professional v7.0.0.2 in the Administration zone "/netflow/jspui/editProfile.jsp" file in the userName parameter. |
1Zohocorp 1Manageengine Netflow Analyzer Jun 17, 2026 Mar 21, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 XSS exists in Zoho ManageEngine Netflow Analyzer Professional v7.0.0.2 in the Administration zone "/netflow/jspui/addMailSettings.jsp" file in the gF parameter. |
1Samsung 2Syncthru Web Service X7400gx FirmwareJun 17, 2026 Mar 21, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 XSS exists in SAMSUNG X7400GX SyncThru Web Service V6.A6.25 V11.01.05.25_08-21-2015 in "/sws.login/gnb/loginView.sws" in multiple parameters: contextpath and basedURL. |
1Samsung 2Syncthru Web Service X7400gx FirmwareJun 17, 2026 Mar 21, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 XSS exists in SAMSUNG X7400GX SyncThru Web Service V6.A6.25 V11.01.05.25_08-21-2015 in "/sws.application/information/networkinformationView.sws" in the tabName parameter. |
1Samsung 2Syncthru Web Service X7400gx FirmwareJun 17, 2026 Mar 21, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 XSS exists in SAMSUNG X7400GX SyncThru Web Service V6.A6.25 V11.01.05.25_08-21-2015 in "/sws/leftmenu.sws" in multiple parameters: ruiFw_id, ruiFw_pid, ruiFw_title. |