CWE-79
46,217 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (46,217)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Juniper 1Advanced Threat Prevention Jun 17, 2026 Jan 15, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 A persistent cross-site scripting (XSS) vulnerability in the Zone configuration of Juniper ATP may allow authenticated user to inject arbitrary script and steal sensitive data and credentials from a web administration se...Show more |
1Juniper 1Advanced Threat Prevention Jun 17, 2026 Jan 15, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 A persistent cross-site scripting (XSS) vulnerability in RADIUS configuration menu of Juniper ATP may allow authenticated user to inject arbitrary script and steal sensitive data and credentials from a web administration...Show more |
1Juniper 1Advanced Threat Prevention Jun 17, 2026 Jan 15, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 A persistent cross-site scripting (XSS) vulnerability in the Email Collectors menu of Juniper ATP may allow authenticated user to inject arbitrary script and steal sensitive data and credentials from a web administration...Show more |
1Juniper 1Advanced Threat Prevention Jun 17, 2026 Jan 15, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 A persistent cross-site scripting (XSS) vulnerability in the Golden VM menu of Juniper ATP may allow authenticated user to inject arbitrary script and steal sensitive data and credentials from a web administration sessio...Show more |
1Juniper 1Advanced Threat Prevention Jun 17, 2026 Jan 15, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 A persistent cross-site scripting (XSS) vulnerability in the file upload menu of Juniper ATP may allow an authenticated user to inject arbitrary scripts and steal sensitive data and credentials from a web administration...Show more |
1Cisco 1Identity Services Engine Software Nov 21, 2024 Jan 15, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the...Show more |
IBM SPSS Analytic Server 3.1.1.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to cre...Show more |
1Cisco 1Identity Services Engine Software Nov 21, 2024 Jan 15, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the we...Show more |
LimeSurvey before 2.72.4 has Stored XSS by using the Continue Later (aka Resume later) feature to enter an email address, which is mishandled in the admin panel. |
1Premiumwpsuite 1Easy Redirect Manager Jun 17, 2026 Jan 15, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The Premium WP Suite Easy Redirect Manager plugin 28.07-17 for WordPress has XSS via a crafted GET request that is mishandled during log viewing at the templates/admin/redirect-log.php URI. |
XSS exists in JPress v1.0.4 via Markdown input, or Markdown input with the code input option. |
1Ibm 1Security Identity Manager Nov 21, 2024 Jan 14, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 IBM Security Identity Manager 6.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to...Show more |
CubeCart 6.2.2 has Reflected XSS via a /{ADMIN-FILE}/ query string. |
2Redhat Theforeman2Katello SatelliteNov 21, 2024 Jan 13, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 A cross-site scripting (XSS) flaw was found in the katello component of Satellite. An attacker with privilege to create/edit organizations and locations is able to execute a XSS attacks against other users through the Su...Show more |
1Citysearch / Hotfrog / Gelbeseiten Clone Script Project 1Citysearch / Hotfrog / Gelbeseiten Clone Script Jun 17, 2026 Jan 13, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 PHP Scripts Mall Citysearch / Hotfrog / Gelbeseiten Clone Script 2.0.1 has Reflected XSS via the srch parameter, as demonstrated by restaurants-details.php. |
Cross-site scripting vulnerability in WordPress plugin spam-byebye 2.2.1 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. |
Frog CMS 0.9.5 allows XSS via the forgot password page (aka the /admin/?/login/forgot URI). |
1Cisco 1Telepresence Management Suite Nov 21, 2024 Jan 11, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 A vulnerability in the web-based management interface of Cisco TelePresence Management Suite (TMS) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-...Show more |
1Cisco 1Webex Business Suite Nov 21, 2024 Jan 10, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 A vulnerability in the MyWebex component of Cisco Webex Business Suite could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack. The vulnerability is due to insufficient validation o...Show more |
Bodhi 2.9.0 and lower is vulnerable to cross-site scripting resulting in code injection caused by incorrect validation of bug titles. |