← Back
CWE-79

46,168 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (46,168)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Grafana
1Grafana
Nov 21, 2024
Dec 20, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Grafana version confirmed for 5.2.4 and 5.3.0 contains a Cross Site Scripting (XSS) vulnerability in Influxdb and Graphite query editor that can result in Running arbitrary js code in victims browser.. This attack appear...Show more
Grafana version confirmed for 5.2.4 and 5.3.0 contains a Cross Site Scripting (XSS) vulnerability in Influxdb and Graphite query editor that can result in Running arbitrary js code in victims browser.. This attack appear to be exploitable via Authenticated user must click on the input field where the payload was previously inserted..Show less
1Backdropcms
1Backdrop Cms
Nov 21, 2024
Dec 20, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Backdrop CMS version 1.11.0 and earlier contains a Cross Site Scripting (XSS) vulnerability in Sanitization of custom class names used on blocks and layouts. that can result in Execution of JavaScript from an unexpected...Show more
Backdrop CMS version 1.11.0 and earlier contains a Cross Site Scripting (XSS) vulnerability in Sanitization of custom class names used on blocks and layouts. that can result in Execution of JavaScript from an unexpected source.. This attack appear to be exploitable via A user must be directed to an affected page while logged in.. This vulnerability appears to have been fixed in 1.11.1 and later.Show less
1Pulsesecure
1Virtual Traffic Manager
Nov 21, 2024
Dec 20, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A stored cross-site scripting (XSS) vulnerability in the web administration user interface of Pulse Secure Virtual Traffic Manager may allow a remote authenticated attacker to inject web script or HTML via a crafted webs...Show more
A stored cross-site scripting (XSS) vulnerability in the web administration user interface of Pulse Secure Virtual Traffic Manager may allow a remote authenticated attacker to inject web script or HTML via a crafted website and steal sensitive data and credentials. Affected releases are Pulse Secure Virtual Traffic Manager 9.9 versions prior to 9.9r2 and 10.4r1.Show less
1Emetrotel
1Xain
Nov 21, 2024
Dec 20, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An XSS issue was discovered in Steve Pallen Xain before 0.6.2 via the order parameter.
1Statamic
1Statamic
Nov 21, 2024
Dec 19, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Statamic 2.10.3 allows XSS via First Name or Last Name to the /users URI in an 'Add new user' request.
1Cmsmadesimple
1Cms Made Simple
Nov 21, 2024
Dec 19, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
CMS Made Simple 2.2.8 allows XSS via an uploaded SVG document, a related issue to CVE-2017-16798.
1Zurmo
1Zurmo
Nov 21, 2024
Dec 19, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Zurmo 3.2.4 allows HTML Injection via an admin's use of HTML in the report section, a related issue to CVE-2018-19506.
1Cmsimple
1Cmsimple
Nov 21, 2024
Dec 19, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
CMSimple 4.7.5 has XSS via an admin's upload of an SVG file at a ?userfiles&subdir=userfiles/images/flags/ URI.
1Cmsimple
1Cmsimple
Nov 21, 2024
Dec 19, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
CMSimple 4.7.5 has XSS via an admin's use of a ?file=config&action=array URI.
1Zurmo
1Zurmo
Nov 21, 2024
Dec 19, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Zurmo 3.2.4 has XSS via an admin's use of the name parameter in the reports section, aka the app/index.php/reports/default/details?id=1 URI.
1Apache
1Nifi
Nov 21, 2024
Dec 19, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The message-page.jsp error page used the value of the HTTP request header X-ProxyContextPath without sanitization, resulting in a reflected XSS attack. Mitigation: The fix to correctly parse and sanitize the request attr...Show more
The message-page.jsp error page used the value of the HTTP request header X-ProxyContextPath without sanitization, resulting in a reflected XSS attack. Mitigation: The fix to correctly parse and sanitize the request attribute value was applied on the Apache NiFi 1.8.0 release. Users running a prior 1.x release should upgrade to the appropriate release.Show less
1Bolt
1Bolt Cms
Nov 21, 2024
Dec 17, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Bolt CMS <3.6.2 allows XSS via text input click preview button as demonstrated by the Title field of a Configured and New Entry.
1Artica
1Integria Ims
Nov 21, 2024
Dec 17, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Artica Integria IMS 5.0.83 has XSS via the search_string parameter.
1Ibm
1Security Guardium
Nov 21, 2024
Dec 17, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM Security Guardium 10 and 10.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to cr...Show more
IBM Security Guardium 10 and 10.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 152082.Show less
1Ibm
1Security Guardium
Nov 21, 2024
Dec 17, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM Security Guardium 10.0 and 10.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to...Show more
IBM Security Guardium 10.0 and 10.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 152080.Show less
1Nagios
1Nagios Xi
Nov 21, 2024
Dec 17, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in Nagios XI before 5.5.8. The rss_url parameter of rss_dashlet/magpierss/scripts/magpie_slashbox.php is not filtered, resulting in an XSS vulnerability.
1Nagios
1Nagios Xi
Nov 21, 2024
Dec 17, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in Nagios XI before 5.5.8. The url parameter of rss_dashlet/magpierss/scripts/magpie_simple.php is not filtered, resulting in an XSS vulnerability.
1Infovista
1Vistaportal
Nov 21, 2024
Dec 17, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross Site Scripting exists in InfoVista VistaPortal SE Version 5.1 (build 51029). The page "/VPortal/mgtconsole/SharedCriteria.jsp" has reflected XSS via the ConnPoolName or GroupId parameter.
1Infovista
1Vistaportal
Nov 21, 2024
Dec 17, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross Site Scripting exists in InfoVista VistaPortal SE Version 5.1 (build 51029). The page "/VPortal/mgtconsole/SecurityPolicies.jsp" has reflected XSS via the ConnPoolName parameter.
1Infovista
1Vistaportal
Nov 21, 2024
Dec 17, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross Site Scripting exists in InfoVista VistaPortal SE Version 5.1 (build 51029). The page "/VPortal/mgtconsole/Roles.jsp" has reflected XSS via the ConnPoolName parameter.