← Back
CWE-79

46,217 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (46,217)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Zoneminder
1Zoneminder
Jun 17, 2026
Feb 18, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
skins/classic/views/controlcap.php in ZoneMinder before 1.32.3 has XSS via the newControl array, as demonstrated by the newControl[MinTiltRange] parameter.
1Zoneminder
1Zoneminder
Jun 17, 2026
Feb 18, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
includes/database.php in ZoneMinder before 1.32.3 has XSS in the construction of SQL-ERR messages.
1Vnote Project
1Vnote
Jun 17, 2026
Feb 17, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
VNote 2.2 has XSS via a new text note.
1Ory
1Hydra
Jun 17, 2026
Feb 17, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
ORY Hydra before v1.0.0-rc.3+oryOS.9 has Reflected XSS via the oauth2/fallbacks/error error_hint parameter.
1Verydows
1Verydows
Jun 17, 2026
Feb 16, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Verydows 2.0 has XSS via the index.php?c=main a parameter, as demonstrated by an a=index[XSS] value.
1Responsive Video News Script Project
1Responsive Video News Script
Jun 17, 2026
Feb 16, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
PHP Scripts Mall Responsive Video News Script has XSS via the Search Bar. This might, for example, be leveraged for HTML injection or URL redirection.
1Ibm
2Infosphere Information Governance Catalog
Infosphere Information Server On Cloud
Nov 21, 2024
Feb 15, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM InfoSphere Information Server 11.3, 11.5, and 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality pote...Show more
IBM InfoSphere Information Server 11.3, 11.5, and 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 152159.Show less
1Sap
1Businessobjects Bi Platform
Jun 17, 2026
Feb 15, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
SAP WebIntelligence BILaunchPad, versions 4.10, 4.20, does not sufficiently encode user-controlled inputs in generated HTML reports, resulting in Cross-Site Scripting (XSS) vulnerability.
1Sap
1Disclosure Management
Jun 17, 2026
Feb 15, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
SAP Disclosure Management (before version 10.1 Stack 1301) does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.
1Sap
1Businessobjects
Jun 17, 2026
Feb 15, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Fiori Launchpad of SAP BusinessObjects, before versions 4.2 and 4.3, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.
1F5
13Big Ip Access Policy Manager
Big Ip Advanced Firewall ManagerBig Ip Analytics+10 more
Jun 17, 2026
Feb 14, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
On BIG-IP 14.0.0-14.0.0.2, 13.0.0-13.1.1.3, 12.1.0-12.1.3.7, and 11.6.0-11.6.3.2, a reflected Cross Site Scripting (XSS) vulnerability is present in an undisclosed page of the BIG-IP TMUI (Traffic Management User Interfa...Show more
On BIG-IP 14.0.0-14.0.0.2, 13.0.0-13.1.1.3, 12.1.0-12.1.3.7, and 11.6.0-11.6.3.2, a reflected Cross Site Scripting (XSS) vulnerability is present in an undisclosed page of the BIG-IP TMUI (Traffic Management User Interface) also known as the BIG-IP configuration utility.Show less
1Atlassian
2Jira
Jira Server
Nov 21, 2024
Feb 13, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The labels widget gadget in Atlassian Jira before version 7.6.11 and from version 7.7.0 before version 7.13.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability...Show more
The labels widget gadget in Atlassian Jira before version 7.6.11 and from version 7.7.0 before version 7.13.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the rendering of retrieved content from a url location that could be manipulated by the up_projectid widget preference setting.Show less
1Atlassian
2Jira
Jira Server
Nov 21, 2024
Feb 13, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The two-dimensional filter statistics gadget in Atlassian Jira before version 7.6.10, from version 7.7.0 before version 7.12.4, and from version 7.13.0 before version 7.13.1 allows remote attackers to inject arbitrary HT...Show more
The two-dimensional filter statistics gadget in Atlassian Jira before version 7.6.10, from version 7.7.0 before version 7.12.4, and from version 7.13.0 before version 7.13.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the name of a saved filter when displayed on a Jira dashboard.Show less
1Tibco
1Silver Fabric
Nov 21, 2024
Feb 13, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The SOAP Admin API component of TIBCO Software Inc.'s TIBCO Silver Fabric contains a vulnerability that may allow reflected cross-site scripting (XSS) attacks. Affected releases are TIBCO Software Inc.'s TIBCO Silver Fab...Show more
The SOAP Admin API component of TIBCO Software Inc.'s TIBCO Silver Fabric contains a vulnerability that may allow reflected cross-site scripting (XSS) attacks. Affected releases are TIBCO Software Inc.'s TIBCO Silver Fabric: versions up to and including 5.8.1.Show less
1Schoolcms
1Schoolcms
Jun 17, 2026
Feb 13, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in SchoolCMS 2.3.1. There is an XSS vulnerability via index.php?a=Index&c=Channel&m=Home&id=[XSS].
1Schoolcms
1Schoolcms
Jun 17, 2026
Feb 13, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in SchoolCMS 2.3.1. There is an XSS vulnerability via index.php?a=Index&c=Channel&m=Home&viewid=[XSS].
1Joomla
1Joomla
Jun 17, 2026
Feb 12, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in Joomla! before 3.9.3. Inadequate filtering on URL fields in various core components could lead to an XSS vulnerability.
1Joomla
1Joomla
Jun 17, 2026
Feb 12, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in Joomla! before 3.9.3. A combination of specific web server configurations, in connection with specific file types and browser-side MIME-type sniffing, causes an XSS attack vector.
1Joomla
1Joomla
Jun 17, 2026
Feb 12, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in Joomla! before 3.9.3. Inadequate checks at the Global Configuration helpurl settings allowed stored XSS.
1Joomla
1Joomla
Jun 17, 2026
Feb 12, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in Joomla! before 3.9.3. Inadequate parameter handling in JavaScript code (core.js writeDynaList) could lead to an XSS attack vector.