← Back
CWE-79

46,168 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (46,168)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Modx
1Evolution Cms
Nov 21, 2024
Dec 28, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Evolution CMS 1.4.x allows XSS via the page weblink title parameter to the manager/ URI.
1Jupo
1Mezzanine
Nov 21, 2024
Dec 28, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Mezzanine CMS v4.3.1 allows XSS via the /admin/blog/blogcategory/add/?_to_field=id&_popup=1 title parameter at admin/blog/blogpost/add/.
1Getkirby
1Kirby
Nov 21, 2024
Dec 28, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Kirby v2.5.12 allows XSS by using the "site files" Add option to upload an SVG file.
1Douco
1Douphp
Nov 21, 2024
Dec 28, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
An issue was discovered in DouCo DouPHP 1.5 20181221. admin/nav.php?rec=update has XSS via the nav_name parameter.
1Douco
1Douphp
Nov 21, 2024
Dec 28, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
An issue was discovered in DouCo DouPHP 1.5 20181221. admin/product_category.php?rec=update has XSS via the cat_name parameter.
1Douco
1Douphp
Nov 21, 2024
Dec 28, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
An issue was discovered in DouCo DouPHP 1.5 20181221. admin/mobile.php?rec=system&act=update has XSS via the mobile_name parameter.
1Douco
1Douphp
Nov 21, 2024
Dec 28, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
An issue was discovered in DouCo DouPHP 1.5 20181221. admin/article_category.php?rec=update has XSS via the cat_name parameter.
1Douco
1Douphp
Nov 21, 2024
Dec 28, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
An issue was discovered in DouCo DouPHP 1.5 20181221. admin/article.php?rec=update has XSS via the title parameter.
1Douco
1Douphp
Nov 21, 2024
Dec 28, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
An issue was discovered in DouCo DouPHP 1.5 20181221. admin/show.php?rec=update has XSS via the show_name parameter.
1Douco
1Douphp
Nov 21, 2024
Dec 28, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
An issue was discovered in DouCo DouPHP 1.5 20181221. admin/product.php?rec=update has XSS via the name parameter.
1Douco
1Douphp
Nov 21, 2024
Dec 28, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
An issue was discovered in DouCo DouPHP 1.5 20181221. admin/system.php?rec=update has XSS via the site_name parameter.
1Douco
1Douphp
Nov 21, 2024
Dec 28, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
An issue was discovered in DouCo DouPHP 1.5 20181221. admin/page.php?rec=edit has XSS via the page_name parameter.
1Website Seller Script Project
1Website Seller Script
Nov 21, 2024
Dec 28, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
PHP Scripts Mall Website Seller Script 2.0.5 has XSS via a Profile field such as Company Address, a related issue to CVE-2018-15896.
1Peel
1Peel Shopping
Nov 21, 2024
Dec 28, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Peel shopping peel-shopping_9_1_0 version contains a Cross Site Scripting (XSS) vulnerability that can result in an authenticated user injecting java script code in the "Site Name EN" parameter. This attack appears to be...Show more
Peel shopping peel-shopping_9_1_0 version contains a Cross Site Scripting (XSS) vulnerability that can result in an authenticated user injecting java script code in the "Site Name EN" parameter. This attack appears to be exploitable if the malicious user has access to the administration account.Show less
1Battelle
1V2i Hub
Nov 21, 2024
Dec 28, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Battelle V2I Hub 2.5.1 is vulnerable to cross-site scripting, caused by improper validation of user-supplied input by api/SystemConfigActions.php?action=add and the index.php script. A remote attacker could exploit this...Show more
Battelle V2I Hub 2.5.1 is vulnerable to cross-site scripting, caused by improper validation of user-supplied input by api/SystemConfigActions.php?action=add and the index.php script. A remote attacker could exploit this vulnerability using the parameterName or _login_username parameter in a specially-crafted URL to execute script in a victim's Web browser within the security context of the hosting Web site, once the URL is clicked. An attacker could use this vulnerability to steal the victim's cookie-based authentication credentials.Show less
1Urlchatbox
1Chat Anywhere
Nov 21, 2024
Dec 27, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Chat Anywhere extension 2.4.0 for Chrome allows XSS via crafted use of <<a> in a message, because a danmuWrapper DIV element in chatbox-only\danmu.js is outside the scope of a Content Security Policy (CSP).
11234n
1Minicms
Nov 21, 2024
Dec 27, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
MiniCMS V1.10 has XSS via the mc-admin/post-edit.php query string, a related issue to CVE-2018-10296 and CVE-2018-16233.
1Dolibarr
1Dolibarr
Nov 21, 2024
Dec 26, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Dolibarr ERP/CRM through 8.0.3 has /exports/export.php?datatoexport= XSS.
1Rockwellautomation
1Powermonitor 1000 Firmware
Nov 21, 2024
Dec 26, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Rockwell Automation Allen-Bradley PowerMonitor 1000 all versions. A remote attacker could inject arbitrary code into a targeted user’s web browser to gain access to the affected device.
1Metinfo
1Metinfo
Nov 21, 2024
Dec 26, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
MetInfo 6.x through 6.1.3 has XSS via the /admin/login/login_check.php url_array[] parameter.