← Back
CWE-79

46,217 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (46,217)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Zoneminder
1Zoneminder
Jun 17, 2026
Feb 4, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Self - Stored Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, allowing an attacker to execute HTML or JavaScript code via a vulnerable 'Host' parameter value in the view console (console.php) because prop...Show more
Self - Stored Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, allowing an attacker to execute HTML or JavaScript code via a vulnerable 'Host' parameter value in the view console (console.php) because proper filtration is omitted. This relates to the index.php?view=monitor Host Name field.Show less
1Zoneminder
1Zoneminder
Jun 17, 2026
Feb 4, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Reflected Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, as multiple views under web/skins/classic/views insecurely utilize $_REQUEST['PHP_SELF'], without applying any proper filtration.
1Kanboard
1Kanboard
Jun 17, 2026
Feb 4, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
app/Core/Paginator.php in Kanboard before 1.2.8 has XSS in pagination sorting.
1M Server Project
1M Server
Nov 21, 2024
Feb 1, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A XSS vulnerability was found in module m-server <1.4.2 that allows malicious Javascript code or HTML to be executed, due to the lack of escaping for special characters in folder names.
1Html Pages Project
1Html Pages
Nov 21, 2024
Feb 1, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A XSS vulnerability was found in html-page <=2.1.1 that allows malicious Javascript code to be executed in the user's browser due to the absence of sanitization of the paths before rendering.
1Public Project
1Public
Nov 21, 2024
Feb 1, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A XSS vulnerability was found in module public <0.1.4 that allows malicious Javascript code to run in the browser, due to the absence of sanitization of the file/folder names before rendering.
1Typora
1Typora
Jun 17, 2026
Jan 31, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
typora through 0.9.64 has XSS, with resultant remote command execution, during inline rendering of a mathematical formula.
1Typora
1Typora
Jun 17, 2026
Jan 31, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
typora through 0.9.63 has XSS, with resultant remote command execution, during block rendering of a mathematical formula.
1Media File Manager Project
1Media File Manager
Nov 21, 2024
Jan 31, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Media File Manager plugin 1.4.2 for WordPress allows XSS via the dir parameter of an mrelocator_getdir action to the wp-admin/admin-ajax.php URI.
1Netscape
1Enterprise Server
Nov 21, 2024
Jan 31, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
servlet/SnoopServlet (a servlet installed by default) in Netscape Enterprise 3.63 has reflected XSS via an arbitrary parameter=[XSS] in the query string. A remote unauthenticated attacker could potentially exploit this v...Show more
servlet/SnoopServlet (a servlet installed by default) in Netscape Enterprise 3.63 has reflected XSS via an arbitrary parameter=[XSS] in the query string. A remote unauthenticated attacker could potentially exploit this vulnerability to supply malicious HTML or JavaScript code to a vulnerable web application, which is then reflected back to the victim and executed by the web browser. NOTE: this product is discontinued.Show less
1Ibm
1I
Jun 17, 2026
Jan 31, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
IBM I 7.2 and 7.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclo...Show more
IBM I 7.2 and 7.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 156164.Show less
1Cross Reference Project
1Cross Reference
Jun 17, 2026
Jan 31, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in the Cross Reference Add-on 36 for Google Docs. Stored XSS in the preview boxes in the configuration panel may allow a malicious user to use both label text and references text to inject arbitra...Show more
An issue was discovered in the Cross Reference Add-on 36 for Google Docs. Stored XSS in the preview boxes in the configuration panel may allow a malicious user to use both label text and references text to inject arbitrary JavaScript code (via SCRIPT elements, event handlers, etc.). Since this code is stored by the plugin, the attacker may be able to target anyone who opens the configuration panel of the plugin.Show less
1Labkey
1Labkey Server
Jun 17, 2026
Jan 30, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Reflected cross-site scripting (XSS) vulnerability in LabKey Server Community Edition before 18.3.0-61806.763 allows an unauthenticated remote attacker to inject arbitrary javascript via the onerror parameter in the /__r...Show more
Reflected cross-site scripting (XSS) vulnerability in LabKey Server Community Edition before 18.3.0-61806.763 allows an unauthenticated remote attacker to inject arbitrary javascript via the onerror parameter in the /__r2/query endpoints.Show less
1Paloaltonetworks
1Pan Os
Jun 17, 2026
Jan 30, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The PAN-OS management web interface in PAN-OS 7.1.21 and earlier, PAN-OS 8.0.14 and earlier, and PAN-OS 8.1.5 and earlier, may allow an unauthenticated attacker to inject arbitrary JavaScript or HTML.
1Paloaltonetworks
1Pan Os
Jun 17, 2026
Jan 30, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The PAN-OS external dynamics lists in PAN-OS 7.1.21 and earlier, PAN-OS 8.0.14 and earlier, and PAN-OS 8.1.5 and earlier, may allow an attacker that is authenticated in Next Generation Firewall with write privileges to E...Show more
The PAN-OS external dynamics lists in PAN-OS 7.1.21 and earlier, PAN-OS 8.0.14 and earlier, and PAN-OS 8.1.5 and earlier, may allow an attacker that is authenticated in Next Generation Firewall with write privileges to External Dynamic List configuration to inject arbitrary JavaScript or HTML.Show less
1Freshrss
1Freshrss
Nov 21, 2024
Jan 30, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Multiple cross-site scripting (XSS) vulnerabilities in GET requests in FreshRSS 1.11.1 allow remote attackers to inject arbitrary web script or HTML via the (1) c parameter or (2) a parameter.
1Open Xchange
1Open Xchange Appsuite
Nov 21, 2024
Jan 30, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
OX App Suite 7.8.4 and earlier allows Directory Traversal.
1Croogo
1Croogo
Jun 17, 2026
Jan 29, 2019
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
A stored-self XSS exists in Croogo through v3.0.5, allowing an attacker to execute HTML or JavaScript code in a vulnerable Title field to /admin/file-manager/attachments/edit/4.
1Atutor
1Atutor
Jun 17, 2026
Jan 29, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A stored-self XSS exists in ATutor through v2.2.4, allowing an attacker to execute HTML or JavaScript code in a vulnerable Real Name field to /mods/_core/users/admins/my_edit.php.
1Croogo
1Croogo
Jun 17, 2026
Jan 29, 2019
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
A stored-self XSS exists in Croogo through v3.0.5, allowing an attacker to execute HTML or JavaScript code in a vulnerable Title field to /admin/blocks/blocks/edit/8.