← Back
CWE-79

46,168 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (46,168)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Siemens
4Scalance S602 Firmware
Scalance S612 FirmwareScalance S623 Firmware+1 more
Nov 21, 2024
Dec 13, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A vulnerability has been identified in SCALANCE S602 (All versions < V4.0.1.1), SCALANCE S612 (All versions < V4.0.1.1), SCALANCE S623 (All versions < V4.0.1.1), SCALANCE S627-2M (All versions < V4.0.1.1). The integrated...Show more
A vulnerability has been identified in SCALANCE S602 (All versions < V4.0.1.1), SCALANCE S612 (All versions < V4.0.1.1), SCALANCE S623 (All versions < V4.0.1.1), SCALANCE S627-2M (All versions < V4.0.1.1). The integrated web server could allow Cross-Site Scripting (XSS) attacks if unsuspecting users are tricked into accessing a malicious link. User interaction is required for a successful exploitation. The user must be logged into the web interface in order for the exploitation to succeed. At the stage of publishing this security advisory no public exploitation is known.Show less
1Ibm
1Security Access Manager
Nov 21, 2024
Dec 13, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM Security Access Manager Appliance 9.0.1.0, 9.0.2.0, 9.0.3.0, 9.0.4.0, and 9.0.5.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering...Show more
IBM Security Access Manager Appliance 9.0.1.0, 9.0.2.0, 9.0.3.0, 9.0.4.0, and 9.0.5.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 144726.Show less
1Codection
1Import Users From Csv With Meta
Nov 21, 2024
Dec 12, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The codection "Import users from CSV with meta" plugin before 1.12.1 for WordPress allows XSS via the value of a cell.
1Microsoft
1Sharepoint Enterprise Server
Jun 17, 2026
Dec 12, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft Office SharePoint XSS Vulnera...Show more
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft Office SharePoint XSS Vulnerability." This affects Microsoft SharePoint.Show less
1Microfocus
1Edirectory
Nov 21, 2024
Dec 12, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross site scripting vulnerability in eDirectory prior to 9.1 SP2
1Microfocus
1Imanager
Nov 21, 2024
Dec 12, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross site scripting vulnerability in iManager prior to 3.1 SP2.
1Microsoft
1Windows Azure Pack Rollup
Jun 17, 2026
Dec 12, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A Cross-site Scripting (XSS) vulnerability exists when Windows Azure Pack does not properly sanitize user-provided input, aka "Windows Azure Pack Cross Site Scripting Vulnerability." This affects Windows Azure Pack Rollu...Show more
A Cross-site Scripting (XSS) vulnerability exists when Windows Azure Pack does not properly sanitize user-provided input, aka "Windows Azure Pack Cross Site Scripting Vulnerability." This affects Windows Azure Pack Rollup 13.1.Show less
1Microsoft
1Dynamics Nav
Jun 17, 2026
Dec 12, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A cross site scripting vulnerability exists when Microsoft Dynamics NAV does not properly sanitize a specially crafted web request to an affected Dynamics NAV server, aka "Microsoft Dynamics NAV Cross Site Scripting Vuln...Show more
A cross site scripting vulnerability exists when Microsoft Dynamics NAV does not properly sanitize a specially crafted web request to an affected Dynamics NAV server, aka "Microsoft Dynamics NAV Cross Site Scripting Vulnerability." This affects Microsoft Dynamics NAV.Show less
1Sap
1Hybris
Nov 21, 2024
Dec 11, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
SAP Commerce does not sufficiently validate user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability in storefronts that are based on the product. Fixed in versions (SAP Hybris Commerce, versions 6.2...Show more
SAP Commerce does not sufficiently validate user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability in storefronts that are based on the product. Fixed in versions (SAP Hybris Commerce, versions 6.2, 6.3, 6.4, 6.5, 6.6, 6.7).Show less
1Sap
1Netweaver Application Server Java
Nov 21, 2024
Dec 11, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
SAP NetWeaver AS Java Web Container service does not validate against whitelist the HTTP host header which can result in HTTP Host Header Manipulation or Cross-Site Scripting (XSS) vulnerability. This is fixed in version...Show more
SAP NetWeaver AS Java Web Container service does not validate against whitelist the HTTP host header which can result in HTTP Host Header Manipulation or Cross-Site Scripting (XSS) vulnerability. This is fixed in versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50.Show less
1Sap
1Business One On Hana
Nov 21, 2024
Dec 11, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
TRACE method is enabled in SAP Business One Service Layer . Attacker can use XST (Cross Site Tracing) attack if frontend applications that are using Service Layer has a XSS vulnerability. This has been fixed in SAP Busin...Show more
TRACE method is enabled in SAP Business One Service Layer . Attacker can use XST (Cross Site Tracing) attack if frontend applications that are using Service Layer has a XSS vulnerability. This has been fixed in SAP Business One Service Layer (B1_ON_HANA, versions 9.2, 9.3).Show less
1Sap
2Marketing Sapscore
Marketing Uicuan
Nov 21, 2024
Dec 11, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
SAP Marketing (UICUAN (1.20, 1.30, 1.40), SAPSCORE (1.13, 1.14)) does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.
2Debian
Phpmyadmin
2Debian Linux
Phpmyadmin
Nov 21, 2024
Dec 11, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In phpMyAdmin before 4.8.4, an XSS vulnerability was found in the navigation tree, where an attacker can deliver a payload to a user through a crafted database/table name.
1Ibm
1Curam Social Program Management
Nov 21, 2024
Dec 11, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM Curam Social Program Management 6.0.5, 6.1.1, 6.2.0, 7.0.1, and 7.0.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended...Show more
IBM Curam Social Program Management 6.0.5, 6.1.1, 6.2.0, 7.0.1, and 7.0.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 152529.Show less
1Nucleuscms
1Nucleus Cms
Nov 21, 2024
Dec 10, 2018
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Nucleus CMS 3.70 allows HTML Injection via the index.php body parameter.
1Blackcat Cms
1Blackcat Cms
Nov 21, 2024
Dec 10, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Blackcat CMS 1.3.2 allows XSS via the willkommen.php?lang=DE page title at backend/pages/modify.php.
1Ibm
1Curam Social Program Management
Nov 21, 2024
Dec 10, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
IBM Curam Social Program Management 7.0.3 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context...Show more
IBM Curam Social Program Management 7.0.3 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site. IBM X-force ID: 144951.Show less
1Sem Cms
1Semcms
Nov 21, 2024
Dec 10, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
SEMCMS 3.5 has XSS via the first text box to the SEMCMS_Main.php URI.
1Phpcmf
1Phpcmf
Nov 21, 2024
Dec 10, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
PHPCMF 4.1.3 has XSS via the first input field to the index.php?s=member&c=register&m=index URI.
1Domainmod
1Domainmod
Nov 21, 2024
Dec 10, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
DomainMOD 4.11.01 has XSS via the assets/add/category.php Category Name or Stakeholder field.