CWE-79
46,168 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (46,168)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Siemens 4Scalance S602 Firmware Scalance S612 FirmwareScalance S623 Firmware+1 moreNov 21, 2024 Dec 13, 2018 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 A vulnerability has been identified in SCALANCE S602 (All versions < V4.0.1.1), SCALANCE S612 (All versions < V4.0.1.1), SCALANCE S623 (All versions < V4.0.1.1), SCALANCE S627-2M (All versions < V4.0.1.1). The integrated...Show more |
IBM Security Access Manager Appliance 9.0.1.0, 9.0.2.0, 9.0.3.0, 9.0.4.0, and 9.0.5.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering...Show more |
1Codection 1Import Users From Csv With Meta Nov 21, 2024 Dec 12, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The codection "Import users from CSV with meta" plugin before 1.12.1 for WordPress allows XSS via the value of a cell. |
1Microsoft 1Sharepoint Enterprise Server Jun 17, 2026 Dec 12, 2018 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft Office SharePoint XSS Vulnera...Show more |
Cross site scripting vulnerability in eDirectory prior to 9.1 SP2 |
Cross site scripting vulnerability in iManager prior to 3.1 SP2. |
1Microsoft 1Windows Azure Pack Rollup Jun 17, 2026 Dec 12, 2018 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 A Cross-site Scripting (XSS) vulnerability exists when Windows Azure Pack does not properly sanitize user-provided input, aka "Windows Azure Pack Cross Site Scripting Vulnerability." This affects Windows Azure Pack Rollu...Show more |
A cross site scripting vulnerability exists when Microsoft Dynamics NAV does not properly sanitize a specially crafted web request to an affected Dynamics NAV server, aka "Microsoft Dynamics NAV Cross Site Scripting Vuln...Show more |
SAP Commerce does not sufficiently validate user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability in storefronts that are based on the product. Fixed in versions (SAP Hybris Commerce, versions 6.2...Show more |
1Sap 1Netweaver Application Server Java Nov 21, 2024 Dec 11, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 SAP NetWeaver AS Java Web Container service does not validate against whitelist the HTTP host header which can result in HTTP Host Header Manipulation or Cross-Site Scripting (XSS) vulnerability. This is fixed in version...Show more |
TRACE method is enabled in SAP Business One Service Layer . Attacker can use XST (Cross Site Tracing) attack if frontend applications that are using Service Layer has a XSS vulnerability. This has been fixed in SAP Busin...Show more |
1Sap 2Marketing Sapscore Marketing UicuanNov 21, 2024 Dec 11, 2018 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 SAP Marketing (UICUAN (1.20, 1.30, 1.40), SAPSCORE (1.13, 1.14)) does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. |
2Debian Phpmyadmin2Debian Linux PhpmyadminNov 21, 2024 Dec 11, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 In phpMyAdmin before 4.8.4, an XSS vulnerability was found in the navigation tree, where an attacker can deliver a payload to a user through a crafted database/table name. |
1Ibm 1Curam Social Program Management Nov 21, 2024 Dec 11, 2018 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 IBM Curam Social Program Management 6.0.5, 6.1.1, 6.2.0, 7.0.1, and 7.0.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended...Show more |
Nucleus CMS 3.70 allows HTML Injection via the index.php body parameter. |
Blackcat CMS 1.3.2 allows XSS via the willkommen.php?lang=DE page title at backend/pages/modify.php. |
1Ibm 1Curam Social Program Management Nov 21, 2024 Dec 10, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 IBM Curam Social Program Management 7.0.3 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context...Show more |
SEMCMS 3.5 has XSS via the first text box to the SEMCMS_Main.php URI. |
PHPCMF 4.1.3 has XSS via the first input field to the index.php?s=member&c=register&m=index URI. |
DomainMOD 4.11.01 has XSS via the assets/add/category.php Category Name or Stakeholder field. |