← Back
CWE-79

46,217 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (46,217)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Grafana
1Piechart Panel
Nov 21, 2024
Feb 6, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Pie Chart Panel plugin through 2019-01-02 for Grafana is vulnerable to XSS via legend data or tooltip data. When a chart is included in a Grafana dashboard, this vulnerability could allow an attacker to gain remote u...Show more
The Pie Chart Panel plugin through 2019-01-02 for Grafana is vulnerable to XSS via legend data or tooltip data. When a chart is included in a Grafana dashboard, this vulnerability could allow an attacker to gain remote unauthenticated access to the dashboard.Show less
1Modx
1Modx Revolution
Nov 21, 2024
Feb 6, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
MODX Revolution through v2.7.0-pl allows XSS via User Settings such as Description.
1Modx
1Modx Revolution
Nov 21, 2024
Feb 6, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
MODX Revolution through v2.7.0-pl allows XSS via an extended user field such as Container name or Attribute name.
1Modx
1Modx Revolution
Nov 21, 2024
Feb 6, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
MODX Revolution through v2.7.0-pl allows XSS via a document resource (such as pagetitle), which is mishandled during an Update action, a Quick Edit action, or the viewing of manager logs.
1Modx
1Modx Revolution
Nov 21, 2024
Feb 6, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
MODX Revolution through v2.7.0-pl allows XSS via the User Photo field.
1Jenkins
1Warnings Next Generation
Jun 17, 2026
Feb 6, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A cross-site scripting vulnerability exists in Jenkins Warnings Next Generation Plugin 1.0.1 and earlier in src/main/java/io/jenkins/plugins/analysis/core/model/DetailsTableModel.java, src/main/java/io/jenkins/plugins/an...Show more
A cross-site scripting vulnerability exists in Jenkins Warnings Next Generation Plugin 1.0.1 and earlier in src/main/java/io/jenkins/plugins/analysis/core/model/DetailsTableModel.java, src/main/java/io/jenkins/plugins/analysis/core/model/SourceDetail.java, src/main/java/io/jenkins/plugins/analysis/core/model/SourcePrinter.java, src/main/java/io/jenkins/plugins/analysis/core/util/Sanitizer.java, src/main/java/io/jenkins/plugins/analysis/warnings/DuplicateCodeScanner.java that allows attackers with the ability to control warnings parser input to have Jenkins render arbitrary HTML.Show less
2Jenkins
Redhat
2Config File Provider
Openshift Container Platform
Jun 17, 2026
Feb 6, 2019
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
An cross-site scripting vulnerability exists in Jenkins Config File Provider Plugin 3.4.1 and earlier in src/main/resources/lib/configfiles/configfiles.jelly that allows attackers with permission to define shared configu...Show more
An cross-site scripting vulnerability exists in Jenkins Config File Provider Plugin 3.4.1 and earlier in src/main/resources/lib/configfiles/configfiles.jelly that allows attackers with permission to define shared configuration files to execute arbitrary JavaScript when a user attempts to delete the shared configuration file.Show less
2Jenkins
Redhat
2Blue Ocean
Openshift Container Platform
Jun 17, 2026
Feb 6, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
An cross-site scripting vulnerability exists in Jenkins Blue Ocean Plugins 1.10.1 and earlier in blueocean-commons/src/main/java/io/jenkins/blueocean/commons/stapler/Export.java, blueocean-commons/src/main/java/io/jenkin...Show more
An cross-site scripting vulnerability exists in Jenkins Blue Ocean Plugins 1.10.1 and earlier in blueocean-commons/src/main/java/io/jenkins/blueocean/commons/stapler/Export.java, blueocean-commons/src/main/java/io/jenkins/blueocean/commons/stapler/export/ExportConfig.java, blueocean-commons/src/main/java/io/jenkins/blueocean/commons/stapler/export/JSONDataWriter.java, blueocean-rest-impl/src/main/java/io/jenkins/blueocean/service/embedded/UserStatePreloader.java, blueocean-web/src/main/resources/io/jenkins/blueocean/PageStatePreloadDecorator/header.jelly that allows attackers with permission to edit a user's description in Jenkins to have Blue Ocean render arbitrary HTML when using it as that user.Show less
1Broadcom
1Automic Workload Automation
Jun 17, 2026
Feb 6, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Insufficient output sanitization in the Automic Web Interface (AWI), in CA Automic Workload Automation 12.0 to 12.2, allow attackers to potentially conduct persistent cross site scripting (XSS) attacks via a crafted obje...Show more
Insufficient output sanitization in the Automic Web Interface (AWI), in CA Automic Workload Automation 12.0 to 12.2, allow attackers to potentially conduct persistent cross site scripting (XSS) attacks via a crafted object.Show less
1Parallax Scroll Project
1Parallax Scroll
Jun 17, 2026
Feb 5, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In the Parallax Scroll (aka adamrob-parallax-scroll) plugin before 2.1 for WordPress, includes/adamrob-parralax-shortcode.php allows XSS via the title text. ("parallax" has a spelling change within the PHP filename.)
1F5
1Big Ip Access Policy Manager
Jun 17, 2026
Feb 5, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
On BIG-IP APM 14.0.0 to 14.0.0.4, 13.0.0 to 13.1.1.3 and 12.1.0 to 12.1.3.7, a reflected cross-site scripting (XSS) vulnerability exists in the resource information page for authenticated users when a full webtop is conf...Show more
On BIG-IP APM 14.0.0 to 14.0.0.4, 13.0.0 to 13.1.1.3 and 12.1.0 to 12.1.3.7, a reflected cross-site scripting (XSS) vulnerability exists in the resource information page for authenticated users when a full webtop is configured on the BIG-IP APM system.Show less
1Phpmywind
1Phpmywind
Jun 17, 2026
Feb 5, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in PHPMyWind 5.5. The GetQQ function in include/func.class.php allows XSS via the cfg_qqcode parameter. This can be exploited via CSRF.
1Rukovoditel
1Rukovoditel
Jun 17, 2026
Feb 5, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Rukovoditel before 2.4.1 allows XSS.
1Opt Net
1Ng Netms
Jun 17, 2026
Feb 4, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
OPT/NET BV NG-NetMS version v3.6-2 and earlier versions contains a Cross Site Scripting (XSS) vulnerability in /js/libs/jstree/demo/filebrowser/index.php page. The "id" and "operation" GET parameters can be used to injec...Show more
OPT/NET BV NG-NetMS version v3.6-2 and earlier versions contains a Cross Site Scripting (XSS) vulnerability in /js/libs/jstree/demo/filebrowser/index.php page. The "id" and "operation" GET parameters can be used to inject arbitrary JavaScript which is returned in the page's response that can result in Cross-site scripting.This attack appear to be exploitable via network connectivity.Show less
1Chamilo
1Chamilo Lms
Jun 17, 2026
Feb 4, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Chamilo Chamilo-lms version 1.11.8 and earlier contains a Cross Site Scripting (XSS) vulnerability in main/messages/new_message.php, main/social/personal_data.php, main/inc/lib/TicketManager.php, main/ticket/ticket_detai...Show more
Chamilo Chamilo-lms version 1.11.8 and earlier contains a Cross Site Scripting (XSS) vulnerability in main/messages/new_message.php, main/social/personal_data.php, main/inc/lib/TicketManager.php, main/ticket/ticket_details.php that can result in a message being sent to the Administrator with the XSS to steal cookies. A ticket can be created with a XSS payload in the subject field. This attack appears to be exploitable via <svg/onload=alert(1)> as the payload user on the Subject field. This makes it possible to obtain the cookies of all users that have permission to view the tickets. This vulnerability appears to have been fixed in 1.11.x after commit 33e2692a37b5b6340cf5bec1a84e541460983c03.Show less
1Phpipam
1Phpipam
Jun 17, 2026
Feb 4, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
phpIPAM version 1.3.2 and earlier contains a Cross Site Scripting (XSS) vulnerability in subnet-scan-telnet.php that can result in executing code in victims browser. This attack appears to be exploitable via victim visit...Show more
phpIPAM version 1.3.2 and earlier contains a Cross Site Scripting (XSS) vulnerability in subnet-scan-telnet.php that can result in executing code in victims browser. This attack appears to be exploitable via victim visits link crafted by an attacker. This vulnerability appears to have been fixed in 1.4.Show less
1Jspmyadmin
1Jspmyadmin2
Jun 17, 2026
Feb 4, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
yugandhargangu JspMyAdmin2 version 1.0.6 and earlier contains a Cross Site Scripting (XSS) vulnerability in sidebar and table data that can result in Database fields aren't properly sanitized and allow code injection (Cr...Show more
yugandhargangu JspMyAdmin2 version 1.0.6 and earlier contains a Cross Site Scripting (XSS) vulnerability in sidebar and table data that can result in Database fields aren't properly sanitized and allow code injection (Cross-Site Scripting). This attack appears to be exploitable via the payload needs to be stored in the database and the victim must see the db value in question.Show less
1Freebsd
1Cvsweb
Nov 21, 2024
Feb 4, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
FreeBSD CVSweb version 2.x contains a Cross Site Scripting (XSS) vulnerability in all pages that can result in limited impact--CVSweb is anonymous & read-only. It might impact other sites on same domain. This attack appe...Show more
FreeBSD CVSweb version 2.x contains a Cross Site Scripting (XSS) vulnerability in all pages that can result in limited impact--CVSweb is anonymous & read-only. It might impact other sites on same domain. This attack appears to be exploitable via victim must load specially crafted url. This vulnerability appears to have been fixed in 3.x.Show less
1Zoneminder
1Zoneminder
Jun 17, 2026
Feb 4, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Self - Stored Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, as the view 'state' (aka Run State) (state.php) does no input validation to the value supplied to the 'New State' (aka newState) field, allowi...Show more
Self - Stored Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, as the view 'state' (aka Run State) (state.php) does no input validation to the value supplied to the 'New State' (aka newState) field, allowing an attacker to execute HTML or JavaScript code.Show less
1Zoneminder
1Zoneminder
Jun 17, 2026
Feb 4, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Reflected Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, allowing an attacker to execute HTML or JavaScript code via a vulnerable 'newMonitor[V4LCapturesPerFrame]' parameter value in the view monitor (mo...Show more
Reflected Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, allowing an attacker to execute HTML or JavaScript code via a vulnerable 'newMonitor[V4LCapturesPerFrame]' parameter value in the view monitor (monitor.php) because proper filtration is omitted.Show less