CWE-79
46,168 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (46,168)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Denial-of-service in the login page of ASUSTOR ADM 3.1.1 allows attackers to prevent users from signing in by placing malformed text in the title. |
Cross-site scripting vulnerability in File Explorer in ASUSTOR ADM version 3.1.1 allows attackers to execute arbitrary JavaScript when a file is moved via a malicious filename. |
Cross-site scripting in the Login page in ASUSTOR ADM version 3.1.1 allows attackers to execute JavaScript via the System Announcement feature. |
Cross-site scripting in File Explorer in ASUSTOR ADM version 3.1.1 allows attackers to execute JavaScript by uploading SVG images with embedded JavaScript. |
Two XSS vulnerabilities are located in the profile edition page of the user panel of the YunoHost 2.7.2 through 2.7.14 web application. By injecting a JavaScript payload, these flaws could be used to manipulate a user's...Show more |
Pluck v4.7.7 allows XSS via the admin.php?action=editpage&page= page title. |
Subrion CMS v4.2.1 allows XSS via the panel/configuration/general/ SITE TITLE parameter. |
panel/uploads/#elf_l1_XA in Subrion CMS v4.2.1 allows XSS via an SVG file with JavaScript in a SCRIPT element. |
panel/login in Kirby v2.5.12 allows XSS via a blog name. |
An issue was discovered in YzmCMS 5.2. XSS exists via the admin/content/search.html searinfo parameter. |
Cross-site scripting in the MySQL API error page in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows attackers to execute JavaScript via a malformed URL path. |
Cross-site scripting in the /DroboAccess/delete_user endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows attackers to execute JavaScript via the "username" URL parameter. |
Cross-site scripting in the /DroboAccess/enable_user endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows attackers to execute JavaScript via the username URL parameter. |
In Metinfo 6.1.3, include/interface/applogin.php allows setting arbitrary HTTP headers (including the Cookie header), and common.inc.php allows registering variables from the $_COOKIE value. This issue can, for example,...Show more |
Metinfo 6.1.3 has reflected XSS via the admin/column/move.php lang_columnerr4 parameter. |
1Kibokolabs 1Arigato Autoresponder And Newsletter Nov 21, 2024 Dec 3, 2018 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 There is a reflected XSS vulnerability in WordPress Arigato Autoresponder and News letter v2.5.1.8 This vulnerability requires administrative privileges to exploit. There is an XSS vulnerability in unsubscribe.html.php:3...Show more |
1Kibokolabs 1Arigato Autoresponder And Newsletter Nov 21, 2024 Dec 3, 2018 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 There is a reflected XSS vulnerability in WordPress Arigato Autoresponder and News letter v2.5.1.8 This vulnerability requires administrative privileges to exploit. There is an XSS vulnerability in list-user.html.php:4:...Show more |
1Kibokolabs 1Arigato Autoresponder And Newsletter Nov 21, 2024 Dec 3, 2018 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 There is a reflected XSS vulnerability in WordPress Arigato Autoresponder and News letter v2.5.1.8 This vulnerability requires administrative privileges to exploit. There is an XSS vulnerability in integration-contact-fo...Show more |
1Kibokolabs 1Arigato Autoresponder And Newsletter Nov 21, 2024 Dec 3, 2018 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 These vulnerabilities require administrative privileges to exploit. There is an XSS vulnerability in integration-contact-form.html.php:14: via POST request variable classes |
1Kibokolabs 1Arigato Autoresponder And Newsletter Nov 21, 2024 Dec 3, 2018 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 These vulnerabilities require administrative privileges to exploit. There is an XSS vulnerability in bft_list.html.php:43: via the filter_signup_date parameter. |