← Back
CWE-79

46,217 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (46,217)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Semcosoft
1Semcosoft
Nov 21, 2024
Feb 23, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A reflected Cross-Site scripting (XSS) vulnerability in SEMCO Semcosoft 5.3 allows remote attackers to inject arbitrary web scripts or HTML via the username parameter to the Login Form.
1Mopcms
1Mopcms
Jun 17, 2026
Feb 22, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An XSS vulnerability was discovered in MOPCMS through 2018-11-30. There is persistent XSS that allows remote attackers to inject arbitrary web script or HTML via the form[name] parameter in a mod=column request, as demon...Show more
An XSS vulnerability was discovered in MOPCMS through 2018-11-30. There is persistent XSS that allows remote attackers to inject arbitrary web script or HTML via the form[name] parameter in a mod=column request, as demonstrated by the /mopcms/X0AZgf(index).php?mod=column&ac=list&menuid=28&ac=add&menuid=29 URI.Show less
1Cisco
1Unity Connection
Jun 17, 2026
Feb 21, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A vulnerability in the Security Assertion Markup Language (SAML) single sign-on (SSO) interface of Cisco Unity Connection could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack aga...Show more
A vulnerability in the Security Assertion Markup Language (SAML) single sign-on (SSO) interface of Cisco Unity Connection could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device. The vulnerability is due to insufficient validation of user-supplied input by the interface of an affected device. An attacker could exploit this vulnerability by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information. Version 12.5 is affected.Show less
1Cisco
1Hyperflex Hx Data Platform
Jun 17, 2026
Feb 21, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A vulnerability in the web-based management interface of Cisco HyperFlex software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management...Show more
A vulnerability in the web-based management interface of Cisco HyperFlex software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected system. The vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of an affected system. An attacker could exploit this vulnerability by persuading a user of the interface to click a maliciously crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information. Versions prior to 3.5(1a) are affected.Show less
1Ibm
1Security Identity Governance And Intelligence
Nov 21, 2024
Feb 21, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
IBM Security Identity Governance and Intelligence 5.2 through 5.2.4.1 Virtual Appliance is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus alterin...Show more
IBM Security Identity Governance and Intelligence 5.2 through 5.2.4.1 Virtual Appliance is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 153427.Show less
1Altn
1Mdaemon
Jun 17, 2026
Feb 21, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
MDaemon Webmail 14.x through 18.x before 18.5.2 has XSS (issue 2 of 2).
1Altn
1Mdaemon
Jun 17, 2026
Feb 21, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
MDaemon Webmail 14.x through 18.x before 18.5.2 has XSS (issue 1 of 2).
1Splunk
1Splunk
Jun 17, 2026
Feb 21, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Splunk Web in Splunk Enterprise 6.5.x before 6.5.5, 6.4.x before 6.4.9, 6.3.x before 6.3.12, 6.2.x before 6.2.14, 6.1.x before 6.1.14, and 6.0.x before 6.0.15 and Splunk Light before 6.6.0 has Persistent XSS, aka SPL-138...Show more
Splunk Web in Splunk Enterprise 6.5.x before 6.5.5, 6.4.x before 6.4.9, 6.3.x before 6.3.12, 6.2.x before 6.2.14, 6.1.x before 6.1.14, and 6.0.x before 6.0.15 and Splunk Light before 6.6.0 has Persistent XSS, aka SPL-138827.Show less
1Netgate
1Haproxy
Jun 17, 2026
Feb 20, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The HAProxy package before 0.59_16 for pfSense has XSS via the desc (aka Description) or table_actionsaclN parameter, related to haproxy_listeners.php and haproxy_listeners_edit.php.
4F5
GetbootstrapRedhat+1 more
16Big Ip Access Policy Manager
Big Ip Advanced Firewall ManagerBig Ip Analytics+13 more
Jun 17, 2026
Feb 20, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In Bootstrap before 3.4.1 and 4.3.x before 4.3.1, XSS is possible in the tooltip or popover data-template attribute.
1Atlassian
2Crucible
Fisheye
Nov 21, 2024
Feb 20, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The Edit upload resource for a review in Atlassian Fisheye and Crucible before version 4.7.0 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the wbuser par...Show more
The Edit upload resource for a review in Atlassian Fisheye and Crucible before version 4.7.0 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the wbuser parameter.Show less
1Atlassian
2Crucible
Fisheye
Nov 21, 2024
Feb 20, 2019
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The administrative linker functionality in Atlassian Fisheye and Crucible before version 4.7.0 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the href par...Show more
The administrative linker functionality in Atlassian Fisheye and Crucible before version 4.7.0 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the href parameter.Show less
4Debian
FedoraprojectGoogle+1 more
6Chrome
Debian LinuxEnterprise Linux Desktop+3 more
Jun 17, 2026
Feb 19, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
A missing case for handling special schemes in permission request checks in Extensions in Google Chrome prior to 72.0.3626.81 allowed an attacker who convinced a user to install a malicious extension to bypass extension...Show more
A missing case for handling special schemes in permission request checks in Extensions in Google Chrome prior to 72.0.3626.81 allowed an attacker who convinced a user to install a malicious extension to bypass extension permission checks for privileged pages via a crafted Chrome Extension.Show less
1Tautulli
1Tautulli
Jun 17, 2026
Feb 19, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
data/interfaces/default/history.html in Tautulli 2.1.26 has XSS via a crafted Plex username that is mishandled when constructing the History page.
1O Dyn
1Collabtive
Jun 17, 2026
Feb 19, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Collabtive 3.1 allows XSS via the manageuser.php?action=profile id parameter.
1Wtcms Project
1Wtcms
Jun 17, 2026
Feb 18, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in WTCMS 1.0. It has stored XSS via the third text box (for the website statistics code).
1Txjia
1Imcat
Jun 17, 2026
Feb 18, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
imcat 4.5 has Stored XSS via the root/run/adm.php fm[instop][note] parameter.
1Phpmywind
1Phpmywind
Jun 17, 2026
Feb 18, 2019
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
admin/default.php in PHPMyWind v5.5 has XSS via an HTTP Host header.
1Cmseasy
1Cmseasy
Jun 17, 2026
Feb 18, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In CmsEasy 7.0, there is XSS via the ckplayer.php autoplay parameter.
1Cmseasy
1Cmseasy
Jun 17, 2026
Feb 18, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In CmsEasy 7.0, there is XSS via the ckplayer.php url parameter.