← Back
CWE-79

46,168 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (46,168)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Domainmod
1Domainmod
Nov 21, 2024
Dec 10, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
DomainMOD 4.11.01 has XSS via the assets/add/ssl-provider-account.php username field.
1Domainmod
1Domainmod
Nov 21, 2024
Dec 10, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
DomainMOD 4.11.01 has XSS via the assets/add/ssl-provider.php SSL Provider Name or SSL Provider URL field.
1Phpok
1Phpok
Nov 21, 2024
Dec 10, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in PHPok v5.0.055. There is a Stored XSS vulnerability via the title parameter to api.php?c=post&f=save (reachable via the index.php?id=book URI).
1Theforeman
1Foreman
Nov 21, 2024
Dec 7, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
A cross-site scripting (XSS) flaw was found in the foreman component of satellite. An attacker with privilege to create entries using the Hosts, Monitor, Infrastructure, or Administer Menus is able to execute a XSS attac...Show more
A cross-site scripting (XSS) flaw was found in the foreman component of satellite. An attacker with privilege to create entries using the Hosts, Monitor, Infrastructure, or Administer Menus is able to execute a XSS attacks against other users, possibly leading to malicious code execution and extraction of the anti-CSRF token of higher privileged users. Foreman before 1.18.3, 1.19.1, and 1.20.0 are vulnerable.Show less
1Zenitel
1Ip Stationweb Firmware
Nov 21, 2024
Dec 6, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Zenitel Norway IP-StationWeb before 4.2.3.9 allows stored XSS via the Display Name for Station Status or Account Settings, related to the goform/zForm_save_changes sip_nick parameter. The password of alphaadmin for the a...Show more
Zenitel Norway IP-StationWeb before 4.2.3.9 allows stored XSS via the Display Name for Station Status or Account Settings, related to the goform/zForm_save_changes sip_nick parameter. The password of alphaadmin for the admin account may be used for authentication in some cases.Show less
1Zenitel
1Ip Stationweb Firmware
Nov 21, 2024
Dec 6, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Zenitel Norway IP-StationWeb before 4.2.3.9 allows reflected XSS via the goform/ PATH_INFO.
1Sales & Company Management System Project
1Sales & Company Management System
Nov 21, 2024
Dec 6, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in Sales & Company Management System (SCMS) through 2018-06-06. An email address can be modified in between the request for a validation code and the entry of the validation code, leading to stora...Show more
An issue was discovered in Sales & Company Management System (SCMS) through 2018-06-06. An email address can be modified in between the request for a validation code and the entry of the validation code, leading to storage of an XSS payload contained in the modified address.Show less
1Actiontec
1C1000a Firmware
Nov 21, 2024
Dec 6, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Persistent Cross-Site Scripting (XSS) in the advancedsetup_websiteblocking.html Website Blocking page of the Actiontec C1000A router with firmware through CAC004-31.30L.95 allows a remote attacker to inject arbitrary HTM...Show more
Persistent Cross-Site Scripting (XSS) in the advancedsetup_websiteblocking.html Website Blocking page of the Actiontec C1000A router with firmware through CAC004-31.30L.95 allows a remote attacker to inject arbitrary HTML into the Website Blocking page by inserting arbitrary HTML into the 'TodUrlAdd' URL parameter in a /urlfilter.cmd POST request.Show less
1Zohocorp
1Manageengine Opmanager
Nov 21, 2024
Dec 6, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Zoho ManageEngine OpManager 12.3 before 123237 has XSS in the domain controller.
1Pixelimity
1Pixelimity
Nov 21, 2024
Dec 6, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Pixelimity 1.0 has Persistent XSS via the admin/portfolio.php data[title] parameter, as demonstrated by a crafted onload attribute of an SVG element.
1Domainmod
1Domainmod
Nov 21, 2024
Dec 6, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
DomainMOD through 4.11.01 has XSS via the assets/edit/host.php Web Host Name or Web Host URL field.
1Domainmod
1Domainmod
Nov 21, 2024
Dec 6, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
DomainMOD through 4.11.01 has XSS via the assets/add/dns.php Profile Name or notes field.
1Domainmod
1Domainmod
Nov 21, 2024
Dec 6, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
DomainMOD through 4.11.01 has XSS via the assets/add/registrar-accounts.php UserName, Reseller ID, or notes field.
1Symantec
1Norton Password Manager
Nov 21, 2024
Dec 6, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Norton Password Manager for Android (formerly Norton Identity Safe) may be susceptible to a cross site scripting (XSS) exploit, which is a type of issue that can enable attackers to inject client-side scripts into web pa...Show more
Norton Password Manager for Android (formerly Norton Identity Safe) may be susceptible to a cross site scripting (XSS) exploit, which is a type of issue that can enable attackers to inject client-side scripts into web pages viewed by other users. A cross-site scripting vulnerability may be used by attackers to potentially bypass access controls such as the same-origin policy.Show less
1Ibm
1Financial Transaction Manager
Nov 21, 2024
Dec 6, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM Financial Transaction Manager for Digital Payments for Multi-Platform 3.0.0, 3.0.2, and 3.0.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI th...Show more
IBM Financial Transaction Manager for Digital Payments for Multi-Platform 3.0.0, 3.0.2, and 3.0.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 151329.Show less
1Domainmod
1Domainmod
Nov 21, 2024
Dec 6, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
DomainMOD through 4.11.01 has XSS via the admin/dw/add-server.php DisplayName, HostName, or UserName field.
1Adiscon
1Loganalyzer
Nov 21, 2024
Dec 5, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
login.php in Adiscon LogAnalyzer before 4.1.7 has XSS via the Login Button Referer field.
1Ibm
1Qradar Incident Forensics
Nov 21, 2024
Dec 5, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM QRadar SIEM 7.2 and 7.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credenti...Show more
IBM QRadar SIEM 7.2 and 7.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 147707.Show less
1Gitlab
1Gitlab
Nov 21, 2024
Dec 4, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in GitLab Community and Enterprise Edition before 11.2.7, 11.3.x before 11.3.8, and 11.4.x before 11.4.3. It has XSS.
1Spidercontrol
1Scada Webserver
Nov 21, 2024
Dec 4, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Reflected cross-site scripting (non-persistent) in SCADA WebServer (Versions prior to 2.03.0001) could allow an attacker to send a crafted URL that contains JavaScript, which can be reflected off the web application to t...Show more
Reflected cross-site scripting (non-persistent) in SCADA WebServer (Versions prior to 2.03.0001) could allow an attacker to send a crafted URL that contains JavaScript, which can be reflected off the web application to the victim's browser.Show less