← Back
CWE-79

46,168 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (46,168)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Asustor
1Data Master
Nov 21, 2024
Dec 4, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Denial-of-service in the login page of ASUSTOR ADM 3.1.1 allows attackers to prevent users from signing in by placing malformed text in the title.
1Asustor
1Data Master
Nov 21, 2024
Dec 4, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-site scripting vulnerability in File Explorer in ASUSTOR ADM version 3.1.1 allows attackers to execute arbitrary JavaScript when a file is moved via a malicious filename.
1Asustor
1Data Master
Nov 21, 2024
Dec 4, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-site scripting in the Login page in ASUSTOR ADM version 3.1.1 allows attackers to execute JavaScript via the System Announcement feature.
1Asustor
1Data Master
Nov 21, 2024
Dec 4, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting in File Explorer in ASUSTOR ADM version 3.1.1 allows attackers to execute JavaScript by uploading SVG images with embedded JavaScript.
1Yunohost
1Yunohost
Nov 21, 2024
Dec 4, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Two XSS vulnerabilities are located in the profile edition page of the user panel of the YunoHost 2.7.2 through 2.7.14 web application. By injecting a JavaScript payload, these flaws could be used to manipulate a user's...Show more
Two XSS vulnerabilities are located in the profile edition page of the user panel of the YunoHost 2.7.2 through 2.7.14 web application. By injecting a JavaScript payload, these flaws could be used to manipulate a user's session.Show less
1Pluck Cms
1Pluck
Nov 21, 2024
Dec 4, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Pluck v4.7.7 allows XSS via the admin.php?action=editpage&page= page title.
1Intelliants
1Subrion Cms
Nov 21, 2024
Dec 4, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Subrion CMS v4.2.1 allows XSS via the panel/configuration/general/ SITE TITLE parameter.
1Intelliants
1Subrion Cms
Nov 21, 2024
Dec 4, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
panel/uploads/#elf_l1_XA in Subrion CMS v4.2.1 allows XSS via an SVG file with JavaScript in a SCRIPT element.
1Getkirby
1Kirby
Nov 21, 2024
Dec 4, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
panel/login in Kirby v2.5.12 allows XSS via a blog name.
1Yzmcms
1Yzmcms
Nov 21, 2024
Dec 4, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
An issue was discovered in YzmCMS 5.2. XSS exists via the admin/content/search.html searinfo parameter.
1Drobo
15n2 Firmware
Nov 21, 2024
Dec 3, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting in the MySQL API error page in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows attackers to execute JavaScript via a malformed URL path.
1Drobo
15n2 Firmware
Nov 21, 2024
Dec 3, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting in the /DroboAccess/delete_user endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows attackers to execute JavaScript via the "username" URL parameter.
1Drobo
15n2 Firmware
Nov 21, 2024
Dec 3, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting in the /DroboAccess/enable_user endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows attackers to execute JavaScript via the username URL parameter.
1Metinfo
1Metinfo
Nov 21, 2024
Dec 3, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In Metinfo 6.1.3, include/interface/applogin.php allows setting arbitrary HTTP headers (including the Cookie header), and common.inc.php allows registering variables from the $_COOKIE value. This issue can, for example,...Show more
In Metinfo 6.1.3, include/interface/applogin.php allows setting arbitrary HTTP headers (including the Cookie header), and common.inc.php allows registering variables from the $_COOKIE value. This issue can, for example, be exploited in conjunction with CVE-2018-19835 to bypass many XSS filters such as the Chrome XSS filter.Show less
1Metinfo
1Metinfo
Nov 21, 2024
Dec 3, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Metinfo 6.1.3 has reflected XSS via the admin/column/move.php lang_columnerr4 parameter.
1Kibokolabs
1Arigato Autoresponder And Newsletter
Nov 21, 2024
Dec 3, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
There is a reflected XSS vulnerability in WordPress Arigato Autoresponder and News letter v2.5.1.8 This vulnerability requires administrative privileges to exploit. There is an XSS vulnerability in unsubscribe.html.php:3...Show more
There is a reflected XSS vulnerability in WordPress Arigato Autoresponder and News letter v2.5.1.8 This vulnerability requires administrative privileges to exploit. There is an XSS vulnerability in unsubscribe.html.php:3: via GET reuqest to the email variable.Show less
1Kibokolabs
1Arigato Autoresponder And Newsletter
Nov 21, 2024
Dec 3, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
There is a reflected XSS vulnerability in WordPress Arigato Autoresponder and News letter v2.5.1.8 This vulnerability requires administrative privileges to exploit. There is an XSS vulnerability in list-user.html.php:4:...Show more
There is a reflected XSS vulnerability in WordPress Arigato Autoresponder and News letter v2.5.1.8 This vulnerability requires administrative privileges to exploit. There is an XSS vulnerability in list-user.html.php:4: via GET request offset variable.Show less
1Kibokolabs
1Arigato Autoresponder And Newsletter
Nov 21, 2024
Dec 3, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
There is a reflected XSS vulnerability in WordPress Arigato Autoresponder and News letter v2.5.1.8 This vulnerability requires administrative privileges to exploit. There is an XSS vulnerability in integration-contact-fo...Show more
There is a reflected XSS vulnerability in WordPress Arigato Autoresponder and News letter v2.5.1.8 This vulnerability requires administrative privileges to exploit. There is an XSS vulnerability in integration-contact-form.html.php:15: via POST request variable html_id.Show less
1Kibokolabs
1Arigato Autoresponder And Newsletter
Nov 21, 2024
Dec 3, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
These vulnerabilities require administrative privileges to exploit. There is an XSS vulnerability in integration-contact-form.html.php:14: via POST request variable classes
1Kibokolabs
1Arigato Autoresponder And Newsletter
Nov 21, 2024
Dec 3, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
These vulnerabilities require administrative privileges to exploit. There is an XSS vulnerability in bft_list.html.php:43: via the filter_signup_date parameter.