CWE-79
46,217 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (46,217)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Samsung 2Syncthru Web Service X7400gx FirmwareJun 17, 2026 Mar 21, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 XSS exists in SAMSUNG X7400GX SyncThru Web Service V6.A6.25 V11.01.05.25_08-21-2015 in "/sws/swsAlert.sws" in multiple parameters: flag, frame, func, and Nfunc. |
1Ericsson 1Active Library Explorer Jun 17, 2026 Mar 21, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 XSS exists in Ericsson Active Library Explorer (ALEX) 14.3 in multiple parameters in the "/cgi-bin/alexserv" servlet, as demonstrated by the DB, FN, fn, or id parameter. |
XSS and/or a Client Side URL Redirect exists in OpenText Documentum Webtop 5.3 SP2. The parameter startat in "/webtop/help/en/default.htm" is vulnerable. |
1Wpsupportplus 1Wp Support Plus Responsive Ticket System Jun 17, 2026 Mar 21, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 A stored cross-site scripting (XSS) vulnerability in the submit_ticket.php module in the WP Support Plus Responsive Ticket System plugin 9.1.1 for WordPress allows remote attackers to inject arbitrary web script or HTML...Show more |
InvoicePlane 1.5 has stored XSS via the index.php/invoices/ajax/save invoice_password parameter, aka the "PDF password" field to the "Create Invoice" option. The XSS payload is rendered at an index.php/invoices/view/## U...Show more |
1Wso2 3Api Manager Identity ServerIdentity Server As Key ManagerNov 21, 2024 Mar 21, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 An issue was discovered in WSO2 API Manager 2.1.0 and 2.6.0. Reflected XSS exists in the carbon part of the product. |
An issue was discovered in WSO2 API Manager 2.1.0 and 2.6.0. A DOM-based XSS exists in the store part of the product. |
1Basic B2b Script Project 1Basic B2b Script Nov 21, 2024 Mar 21, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 PHP Scripts Mall Basic B2B Script 2.0.9 has HTML injection via the First Name or Last Name field. |
1Entrepreneur Job Portal Script Project 1Entrepreneur Job Portal Script Nov 21, 2024 Mar 21, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 PHP Scripts Mall Entrepreneur Job Portal Script 3.0.1 has stored Cross-Site Scripting (XSS) via the Full Name field. |
1Entrepreneur Job Portal Script Project 1Entrepreneur Job Portal Script Nov 21, 2024 Mar 21, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 PHP Scripts Mall Entrepreneur Job Portal Script 3.0.1 has HTML injection via the Search Bar. |
1Chartered Accountant \ 1 Auditor Website Project Nov 21, 2024 Mar 21, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 PHP Scripts Mall Chartered Accountant : Auditor Website 2.0.1 has HTML injection via the First Name field. |
1Advance B2b Script Project 1Advance B2b Script Nov 21, 2024 Mar 21, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 PHP Scripts Mall Advance B2B Script 2.1.4 has stored Cross-Site Scripting (XSS) via the FIRST NAME or LAST NAME field. |
1Consumer Reviews Script Project 1Consumer Reviews Script Nov 21, 2024 Mar 21, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 PHP Scripts Mall Consumer Reviews Script 4.0.3 has HTML injection via the search box. |
bin/statistics in TWiki 6.0.2 allows cross-site scripting (XSS) via the webs parameter. |
AbanteCart 1.2.12 has reflected cross-site scripting (XSS) via the sort parameter, as demonstrated by a /apparel--accessories?sort= substring. |
Zenphoto 1.4.14 has multiple cross-site scripting (XSS) vulnerabilities via different URL parameters. |
1Podcastgenerator 1Podcast Generator Nov 21, 2024 Mar 21, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Podcast Generator 2.7 has stored cross-site scripting (XSS) via the URL addcategory parameter. |
SolarWinds Serv-U FTP Server 15.1.6.25 has reflected cross-site scripting (XSS) in the Web management interface via URL path and HTTP POST parameter. |
Microweber 1.0.8 has reflected cross-site scripting (XSS) vulnerabilities. |
1Hms Networks 8Netbiter Ec150 Firmware Netbiter Ec250 FirmwareNetbiter Lc310 Firmware+5 moreNov 21, 2024 Mar 21, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 HMS Industrial Networks Netbiter WS100 3.30.5 devices and previous have reflected XSS in the login form. |