← Back
CWE-79

46,168 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (46,168)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Zohocorp
1Manageengine Adselfservice Plus
Nov 21, 2024
Dec 26, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Zoho ManageEngine ADSelfService Plus 5.7 before build 5702 has XSS in the employee search feature.
1Zohocorp
1Manageengine Adselfservice Plus
Nov 21, 2024
Dec 26, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Zoho ManageEngine ADSelfService Plus 5.7 before build 5702 has XSS in the self-update layout implementation.
1Qnap
1Q'center Virtual Appliance
Nov 21, 2024
Dec 26, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in Q'center Virtual Appliance 1.8.1014 and earlier versions could allow remote attackers to inject Javascript code in the compromised application, a different vulnerability than C...Show more
Cross-site scripting (XSS) vulnerability in Q'center Virtual Appliance 1.8.1014 and earlier versions could allow remote attackers to inject Javascript code in the compromised application, a different vulnerability than CVE-2018-0723.Show less
1Qnap
1Q'center Virtual Appliance
Nov 21, 2024
Dec 26, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in Q'center Virtual Appliance 1.8.1014 and earlier versions could allow remote attackers to inject Javascript code in the compromised application, a different vulnerability than C...Show more
Cross-site scripting (XSS) vulnerability in Q'center Virtual Appliance 1.8.1014 and earlier versions could allow remote attackers to inject Javascript code in the compromised application, a different vulnerability than CVE-2018-0724.Show less
1S Cms
1S Cms
Nov 21, 2024
Dec 26, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in S-CMS 3.0. It allows XSS via the admin/demo.php T_id parameter.
1Cmsmadesimple
1Cms Made Simple
Nov 21, 2024
Dec 25, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
There is a reflected XSS vulnerability in the CMS Made Simple 2.2.8 admin/myaccount.php. This vulnerability is triggered upon an attempt to modify a user's mailbox with the wrong format. The response contains the user's...Show more
There is a reflected XSS vulnerability in the CMS Made Simple 2.2.8 admin/myaccount.php. This vulnerability is triggered upon an attempt to modify a user's mailbox with the wrong format. The response contains the user's previously entered email address.Show less
1Jsmol2wp Project
1Jsmol2wp
Nov 21, 2024
Dec 25, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in the JSmol2WP plugin 1.07 for WordPress. A cross-site scripting (XSS) vulnerability allows remote attackers to inject arbitrary web script or HTML via the jsmol.php data parameter.
174cms
174cms
Nov 21, 2024
Dec 25, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in 74cms v4.2.111. upload/index.php?c=resume&a=resume_list has XSS via the key parameter.
1Frog Cms Project
1Frog Cms
Nov 21, 2024
Dec 25, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Frog CMS 0.9.5 has XSS via the Database name field to the /install/index.php URI.
1Synology
1Diskstation Manager
Jun 17, 2026
Dec 24, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-site scripting (XSS) vulnerability in info.cgi in Synology DiskStation Manager (DSM) before 6.1.6-15266 allows remote attackers to inject arbitrary web script or HTML via the host parameter.
1Synology
1Router Manager
Jun 17, 2026
Dec 24, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-site scripting (XSS) vulnerability in info.cgi in Synology Router Manager (SRM) before 1.1.7-6941 allows remote attackers to inject arbitrary web script or HTML via the host parameter.
1Craftcms
1Craft Cms
Nov 21, 2024
Dec 24, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
index.php?p=admin/actions/entries/save-entry in Craft CMS 3.0.25 allows XSS by saving a new title from the console tab.
1Technicolor
1Dpc3928sl Firmware
Nov 21, 2024
Dec 23, 2018
N/A· v4
4.7 MEDIUM· v3
2.6 LOW· v2
Technicolor DPC3928SL D3928SL-PSIP-13-A010-c3420r55105-160428a devices allow XSS via a Cross Protocol Injection attack with setSSID of 1.3.6.1.4.1.4413.2.2.2.1.18.1.2.1.1.3.10001.
1Tendacn
1Adsl Firmware
Nov 21, 2024
Dec 23, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Tenda ADSL modem routers 1.0.1 allow XSS via the hostname of a DHCP client.
1Tp Link
1Td W8961nd Firmware
Nov 21, 2024
Dec 23, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
TP-Link TD-W8961ND devices allow XSS via the hostname of a DHCP client.
1The Sz
1Netchat
Nov 21, 2024
Dec 23, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
SZ NetChat before 7.9 has XSS in the MyName input field of the Options module. Attackers are able to inject commands to compromise the enabled HTTP server web frontend.
1Barracuda
1Message Archiver
Nov 21, 2024
Dec 23, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Barracuda Message Archiver 2018 has XSS in the error_msg exception-handling value for the ldap_user parameter to the cgi-mod/ldap_load_entry.cgi module. The injection point of the issue is the Add_Update module.
1Averta
1Master Slider
Nov 21, 2024
Dec 23, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The Master Slider plugin 3.2.7 and 3.5.1 for WordPress has XSS via the wp-admin/admin-ajax.php Name input field of the MSPanel.Settings value on Callback.
1Wstmart
1Wstmart
Nov 21, 2024
Dec 22, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The "mall some commodity details: commodity consultation" component in WSTMart 2.0.8_181212 has stored XSS via the consultContent parameter, as demonstrated by the index.php/home/goodsconsult/add.html URI.
1Evernote
1Evernote
Nov 21, 2024
Dec 22, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Markdown component in Evernote (Chinese) before 8.3.2 on macOS allows stored XSS, aka MAC-832.