← Back
CWE-79

46,217 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (46,217)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Systrome
3Cumilon Isg 600c Firmware
Cumilon Isg 600h FirmwareCumilon Isg 800w Firmware
Nov 21, 2024
Mar 21, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered on Systrome ISG-600C, ISG-600H, and ISG-800W 1.1-R2.1_TRUNK-20180914.bin devices. There is CSRF via /ui/?g=obj_keywords_add and /ui/?g=obj_keywords_addsave with resultant XSS because of a lack of...Show more
An issue was discovered on Systrome ISG-600C, ISG-600H, and ISG-800W 1.1-R2.1_TRUNK-20180914.bin devices. There is CSRF via /ui/?g=obj_keywords_add and /ui/?g=obj_keywords_addsave with resultant XSS because of a lack of csrf token validation.Show less
1Ens
1Webgalamb
Nov 21, 2024
Mar 21, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
wg7.php in Webgalamb 7.0 makes opportunistic calls to htmlspecialchars() instead of using a templating engine with proper contextual encoding. Because it is possible to insert arbitrary strings into the database, any Jav...Show more
wg7.php in Webgalamb 7.0 makes opportunistic calls to htmlspecialchars() instead of using a templating engine with proper contextual encoding. Because it is possible to insert arbitrary strings into the database, any JavaScript could be executed by the administrator, leading to XSS.Show less
1Simplenia
1Pages
Nov 21, 2024
Mar 21, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Simplenia Pages plugin 2.6.0 for Atlassian Bitbucket Server has XSS.
1Webmin
1Webmin
Nov 21, 2024
Mar 21, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Webmin 1.890 has XSS via /config.cgi?webmin, the /shell/index.cgi history parameter, /shell/index.cgi?stripped=1, or the /webminlog/search.cgi uall or mall parameter.
1Controlbyweb
1X 320m I Firmware
Nov 21, 2024
Mar 21, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A stored cross-site scripting (XSS) issue was discovered in ControlByWeb X-320M-I Web-Enabled Instrumentation-Grade Data Acquisition module 1.05 with firmware revision v1.05. An authenticated user can inject arbitrary sc...Show more
A stored cross-site scripting (XSS) issue was discovered in ControlByWeb X-320M-I Web-Enabled Instrumentation-Grade Data Acquisition module 1.05 with firmware revision v1.05. An authenticated user can inject arbitrary script via setup.html in the web interface.Show less
1Advanced Comment System Project
1Advanced Comment System
Nov 21, 2024
Mar 21, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
internal/advanced_comment_system/index.php and internal/advanced_comment_system/admin.php in Advanced Comment System, version 1.0, contain a reflected cross-site scripting vulnerability via ACS_path. A remote unauthentic...Show more
internal/advanced_comment_system/index.php and internal/advanced_comment_system/admin.php in Advanced Comment System, version 1.0, contain a reflected cross-site scripting vulnerability via ACS_path. A remote unauthenticated attacker could potentially exploit this vulnerability to supply malicious HTML or JavaScript code to a vulnerable web application, which is then reflected back to the victim and executed by the web browser. The product is discontinued.Show less
1Ibm
1Mq
Nov 21, 2024
Mar 21, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM WebSphere MQ 9.0.2, 9.0.3, 9.0.4, 9.0.5, 9.1.0.0, and 9.1.0.1 console is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended...Show more
IBM WebSphere MQ 9.0.2, 9.0.3, 9.0.4, 9.0.5, 9.1.0.0, and 9.1.0.1 console is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 150661.Show less
1Layerbb
1Layerbb
Nov 21, 2024
Mar 21, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
LayerBB 1.1.1 allows XSS via the titles of conversations (PMs).
1Printeron
1Printeron
Nov 21, 2024
Mar 21, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
PrinterOn Enterprise 4.1.4 suffers from multiple authenticated stored XSS vulnerabilities via the (1) "Machine Host Name" or "Server Serial Number" field in the clustering configuration, (2) "name" field in the Edit Grou...Show more
PrinterOn Enterprise 4.1.4 suffers from multiple authenticated stored XSS vulnerabilities via the (1) "Machine Host Name" or "Server Serial Number" field in the clustering configuration, (2) "name" field in the Edit Group configuration, (3) "Rule Name" field in the Access Control configuration, (4) "Service Name" in the Service Configuration, or (5) First Name or Last Name field in the Edit Account configuration.Show less
1Coyoapp
1Coyo
Nov 21, 2024
Mar 21, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
COYO 9.0.8, 10.0.11 and 12.0.4 has cross-site scripting (XSS) via URLs used by "iFrame" widgets.
1Mybb
1Ban List
Nov 21, 2024
Mar 21, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
In the Ban List plugin 1.0 for MyBB, any forum user with mod privileges can ban users and input an XSS payload into the ban reason, which is executed on the bans.php page.
1Mybb
1Trash Bin
Nov 21, 2024
Mar 21, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Trash Bin plugin 1.1.3 for MyBB has cross-site scripting (XSS) via a thread subject and a cross-site request forgery (CSRF) via a post subject.
1Dnnsoftware
1Dotnetnuke
Nov 21, 2024
Mar 21, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
DNN (formerly DotNetNuke) 9.1.1 allows cross-site scripting (XSS) via XML.
1Open Xchange
1Open Xchange Appsuite
Nov 21, 2024
Mar 21, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
OX App Suite 7.8.4 and earlier allows XSS. Internal reference: 58742 (Bug ID)
1Bose
1Soundtouch
Nov 21, 2024
Mar 21, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in the Bose Soundtouch app 18.1.4 for iOS. There is no frontend input validation of the device name. A malicious device name can execute JavaScript on the registered Bose User Account if a speaker...Show more
An issue was discovered in the Bose Soundtouch app 18.1.4 for iOS. There is no frontend input validation of the device name. A malicious device name can execute JavaScript on the registered Bose User Account if a speaker has been connected to the app.Show less
1Audiocodes
1420hd Ip Phone Firmware
Nov 21, 2024
Mar 21, 2019
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
AudioCodes IP phone 420HD devices using firmware version 2.2.12.126 allow XSS.
1Moxa
5Oncell G3100v2 Firmware
Oncell G3111 FirmwareOncell G3151 Firmware+2 more
Nov 21, 2024
Mar 21, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Moxa G3100V2 Series, editions prior to Version 2.8, and OnCell G3111/G3151/G3211/G3251 Series, editions prior to Version 1.7 allows a reflected cross-site scripting attack which may allow an attacker to execute arbitrary...Show more
Moxa G3100V2 Series, editions prior to Version 2.8, and OnCell G3111/G3151/G3211/G3251 Series, editions prior to Version 1.7 allows a reflected cross-site scripting attack which may allow an attacker to execute arbitrary script code in the user’s browser within the trust relationship between their browser and the server.Show less
1Phamm
1Phamm
Nov 21, 2024
Mar 17, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Phamm (aka PHP LDAP Virtual Hosting Manager) 0.6.8 allows XSS via the login page (the /public/main.php action parameter).
1Netdata
1Netdata
Jun 17, 2026
Mar 15, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Netdata web application through 1.13.0 allows remote attackers to inject their own malicious HTML code into an imported snapshot, aka HTML Injection. Successful exploitation will allow attacker-supplied HTML to run i...Show more
The Netdata web application through 1.13.0 allows remote attackers to inject their own malicious HTML code into an imported snapshot, aka HTML Injection. Successful exploitation will allow attacker-supplied HTML to run in the context of the affected browser, potentially allowing the attacker to steal authentication credentials or to control how the site is rendered to the user. NOTE: the vendor disputes the risk because there is a clear warning next to the button for importing a snapshotShow less
1Cobham
2Satcom Sailor 800 Firmware
Satcom Sailor 900 Firmware
Nov 21, 2024
Mar 15, 2019
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Cobham Satcom Sailor 800 and 900 devices contained persistent XSS, which required administrative access to exploit. The vulnerability was exploitable by acquiring a copy of the device's configuration file, inserting an X...Show more
Cobham Satcom Sailor 800 and 900 devices contained persistent XSS, which required administrative access to exploit. The vulnerability was exploitable by acquiring a copy of the device's configuration file, inserting an XSS payload into a relevant field (e.g., Satellite name), and then restoring the malicious configuration file.Show less