← Back
CWE-79

46,217 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (46,217)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Upcoming Events Project
1Upcoming Events
Jun 17, 2026
Mar 11, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An XSS issue was discovered in upcoming_events.php in the Upcoming Events plugin before 1.33 for MyBB via a crafted name for an event.
1Codepeople
1Contact Form Email
Jun 17, 2026
Mar 10, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Contact Form Email plugin before 1.2.66 for WordPress allows wp-admin/admin.php item XSS, related to cp_admin_int_edition.inc.php in the "custom edition area."
1Stackstorm
1Stackstorm
Jun 17, 2026
Mar 9, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In st2web in StackStorm Web UI before 2.9.3 and 2.10.x before 2.10.3, it is possible to bypass the CORS protection mechanism via a "null" origin value, potentially leading to XSS.
1Dilicms
1Dilicms
Jun 17, 2026
Mar 7, 2019
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
An issue was discovered in DiliCMS 2.4.0. There is a Stored XSS Vulnerability in the third textbox (aka site logo) of "System setting->site setting" of admin/index.php, aka site_logo.
1Dilicms
1Dilicms
Jun 17, 2026
Mar 7, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
An issue was discovered in DiliCMS 2.4.0. There is a Stored XSS Vulnerability in the second textbox of "System setting->site setting" of admin/index.php, aka site_domain.
1Dilicms
1Dilicms
Jun 17, 2026
Mar 7, 2019
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
An issue was discovered in DiliCMS 2.4.0. There is a Stored XSS Vulnerability in the first textbox of "System setting->site setting" of admin/index.php, aka site_name.
1Phpmywind
1Phpmywind
Jun 17, 2026
Mar 7, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in PHPMyWind 5.5. The method parameter of the data/api/oauth/connect.php page has a reflected Cross-site Scripting (XSS) vulnerability.
1Phpmywind
1Phpmywind
Jun 17, 2026
Mar 7, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in PHPMyWind 5.5. The username parameter of the /install/index.php page has a stored Cross-site Scripting (XSS) vulnerability, as demonstrated by admin/login.php.
1Wuzhicms
1Wuzhicms
May 5, 2025
Mar 7, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
WUZHI CMS 4.1.0 has stored XSS via the "Extension module" "SMS in station" field under the index.php?m=core URI.
1Wuzhicms
1Wuzhicms
May 5, 2025
Mar 7, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
WUZHI CMS 4.1.0 has stored XSS via the "Membership Center" "I want to ask" "detailed description" field under the index.php?m=member URI.
1Zrlog
1Zrlog
Nov 21, 2024
Mar 7, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in ZrLog 2.0.3. There is stored XSS in the file upload area via a crafted attached/file/ pathname.
1Zzcms
1Zzcms
Nov 21, 2024
Mar 7, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
XSS exists in zzcms v8.3 via the /uploadimg_form.php noshuiyin parameter.
1Dolibarr
1Dolibarr
Nov 21, 2024
Mar 7, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in Dolibarr through 7.0.0. There is Stored XSS in expensereport/card.php in the expense reports plugin via the comments parameter, or a public or private note.
1Ucms Project
1Ucms
Nov 21, 2024
Mar 7, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in UCMS 1.4.6. There is XSS in the title bar, as demonstrated by a do=list request.
1Hyphp
1Hybbs
Nov 21, 2024
Mar 7, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An issue was found in HYBBS through 2016-03-08. There is an XSS vulnerablity via an article title to post.html.
1Simplemachines
1Simple Machines Forum
Nov 21, 2024
Mar 7, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Simple Machines Forum (SMF) 2.0.4 allows XSS via the index.php?action=pm;sa=settings;save sa parameter.
1Tibco
3Jasperreports Server
JaspersoftJaspersoft Reporting And Analytics
Nov 21, 2024
Mar 7, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The repository component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server for ActiveMatrix BPM, TIBCO Jaspersoft for AWS with Multi-Tenancy, TI...Show more
The repository component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server for ActiveMatrix BPM, TIBCO Jaspersoft for AWS with Multi-Tenancy, TIBCO Jaspersoft Reporting and Analytics for AWS contains a persistent cross site scripting vulnerability. Affected releases are TIBCO Software Inc.'s TIBCO JasperReports Server: versions up to and including 6.3.4; 6.4.0; 6.4.1; 6.4.2; 6.4.3; 7.1.0, TIBCO JasperReports Server Community Edition: versions up to and including 7.1.0, TIBCO JasperReports Server for ActiveMatrix BPM: versions up to and including 6.4.3, TIBCO Jaspersoft for AWS with Multi- Tenancy versions up to and including 7.1.0, and TIBCO Jaspersoft Reporting and Analytics for AWS: versions up to and including 7.1.0.Show less
1Pivotal Software
1Operations Manager
Jun 17, 2026
Mar 7, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Pivotal Operations Manager, 2.1.x versions prior to 2.1.20, 2.2.x versions prior to 2.2.16, 2.3.x versions prior to 2.3.10, 2.4.x versions prior to 2.4.3, contains a reflected cross site scripting vulnerability. A remote...Show more
Pivotal Operations Manager, 2.1.x versions prior to 2.1.20, 2.2.x versions prior to 2.2.16, 2.3.x versions prior to 2.3.10, 2.4.x versions prior to 2.4.3, contains a reflected cross site scripting vulnerability. A remote user that is able to convince an Operations Manager user to interact with malicious content could execute arbitrary JavaScript in the user's browser.Show less
1Personal Video Collection Script Project
1Personal Video Collection Script
Jun 17, 2026
Mar 6, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
PHP Scripts Mall Personal Video Collection Script 4.0.4 has Stored XSS via the "Update profile" feature.
1Ibm
2Websphere Application Server
Websphere Virtual Enterprise
Jun 17, 2026
Mar 6, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially le...Show more
IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 155946.Show less