CWE-79
45,703 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (45,703)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Smoothwall 1Smoothwall Express Jun 17, 2026 Feb 16, 2026 5.1 MEDIUM· v4 6.1 MEDIUM· v3 N/A· v2 Smoothwall Express 3.1-SP4-polar-x86_64-update9 contains multiple reflected cross-site scripting vulnerabilities in the portfw.cgi script that allow attackers to inject malicious scripts through unvalidated parameters. A...Show more |
1Smoothwall 1Smoothwall Express Jun 17, 2026 Feb 16, 2026 5.1 MEDIUM· v4 6.1 MEDIUM· v3 N/A· v2 Smoothwall Express 3.1-SP4-polar-x86_64-update9 contains multiple reflected cross-site scripting vulnerabilities in the apcupsd.cgi script that allow attackers to inject malicious scripts through multiple POST parameters...Show more |
1Smoothwall 1Smoothwall Express Jun 17, 2026 Feb 16, 2026 5.1 MEDIUM· v4 6.1 MEDIUM· v3 N/A· v2 Smoothwall Express 3.1-SP4-polar-x86_64-update9 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating the NTP_SERVER parameter. Attacker...Show more |
1Smoothwall 1Smoothwall Express Jun 17, 2026 Feb 16, 2026 5.1 MEDIUM· v4 6.1 MEDIUM· v3 N/A· v2 Smoothwall Express 3.1-SP4-polar-x86_64-update9 contains multiple reflected cross-site scripting vulnerabilities in the hosts.cgi script that allow attackers to inject malicious scripts through unvalidated parameters. At...Show more |
1Smoothwall 1Smoothwall Express Jun 17, 2026 Feb 16, 2026 5.1 MEDIUM· v4 6.1 MEDIUM· v3 N/A· v2 Smoothwall Express 3.1-SP4-polar-x86_64-update9 contains multiple reflected cross-site scripting vulnerabilities in the dhcp.cgi script that allow attackers to inject malicious scripts through multiple parameters. Attack...Show more |
1Smoothwall 1Smoothwall Express Jun 17, 2026 Feb 16, 2026 5.3 MEDIUM· v4 7.2 HIGH· v3 N/A· v2 Smoothwall Express 3.1-SP4-polar-x86_64-update9 contains stored and reflected cross-site scripting vulnerabilities in the urlfilter.cgi endpoint that allow attackers to inject malicious scripts. Attackers can submit POST...Show more |
1Smoothwall 1Smoothwall Express Jun 17, 2026 Feb 16, 2026 5.1 MEDIUM· v4 6.1 MEDIUM· v3 N/A· v2 Smoothwall Express 3.1-SP4-polar-x86_64-update9 contains multiple cross-site scripting vulnerabilities in the proxy.cgi endpoint that allow attackers to inject malicious scripts through parameters including CACHE_SIZE, M...Show more |
A Reflected Cross-site Scripting (XSS) vulnerability affecting ENOVIAvpm Web Access from ENOVIAvpm Version 1 Release 16 through ENOVIAvpm Version 1 Release 19 allows an attacker to execute arbitrary script code in user's...Show more |
SmarterTools SmarterMail before 9526 allows XSS via MAPI requests. |
An issue in Visual Studio Code Extensions Live Server v5.7.9 allows attackers to exfiltrate files via user interaction with a crafted HTML page. |
A vulnerability was detected in cskefu up to 8.0.1. Impacted is the function Upload of the file com/cskefu/cc/controller/resource/MediaController.java of the component File Upload. The manipulation results in cross site...Show more |
Cross-Site Scripting (XSS) vulnerability reflected in Kubysoft, which occurs through multiple parameters within the endpoint ‘/node/kudaby/nodeFN/procedure’. This flaw allows the injection of arbitrary client-side script...Show more |
Stored Cross-Site Scripting (XSS) vulnerability in Kubysoft, which is triggered through multiple parameters in the '/kForms/app' endpoint. This issue allows malicious scripts to be injected and executed persistently in t...Show more |
Stored Cross-Site Scripting (XSS) vulnerability in Kubysoft, where uploaded SVG images are not properly sanitized. This allows attackers to embed malicious scripts within SVG files as visual content, which are then store...Show more |
1Ligerosmart 1Ligerosmart Jun 17, 2026 Feb 16, 2026 2.0 LOW· v4 6.1 MEDIUM· v3 4.0 MEDIUM· v2 A vulnerability was detected in LigeroSmart up to 6.1.26. The impacted element is the function AgentDashboard of the file /otrs/index.pl. Performing a manipulation of the argument Subaction results in cross site scriptin...Show more |
1Ligerosmart 1Ligerosmart Jun 17, 2026 Feb 16, 2026 2.0 LOW· v4 6.1 MEDIUM· v3 4.0 MEDIUM· v2 A security vulnerability has been detected in LigeroSmart up to 6.1.26. The affected element is an unknown function of the file /otrs/index.pl. Such manipulation of the argument SortBy leads to cross site scripting. The...Show more |
1Ligerosmart 1Ligerosmart Jun 17, 2026 Feb 16, 2026 2.0 LOW· v4 6.1 MEDIUM· v3 4.0 MEDIUM· v2 A weakness has been identified in LigeroSmart up to 6.1.26. Impacted is an unknown function of the file /otrs/index.pl?Action=AgentTicketSearch. This manipulation of the argument Profile causes cross site scripting. The...Show more |
OPNsense 19.1 contains a reflected cross-site scripting vulnerability in the system_advanced_sysctl.php endpoint that allows attackers to inject malicious scripts via the value parameter. Attackers can craft POST request...Show more |
OPNsense 19.1 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by submitting crafted payloads through the ignoreLogACL parameter. Attackers can sen...Show more |
OPNsense 19.1 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by submitting crafted input to the mailserver parameter. Attackers can send POST req...Show more |