← Back
CWE-79

46,168 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (46,168)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Kibokolabs
1Arigato Autoresponder And Newsletter
Nov 21, 2024
Dec 3, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
There is a reflected XSS vulnerability in WordPress Arigato Autoresponder and News letter v2.5.1.8 This vulnerability requires administrative privileges to exploit.
1Kibokolabs
1Arigato Autoresponder And Newsletter
Nov 21, 2024
Dec 3, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
There is a reflected XSS vulnerability in WordPress Arigato Autoresponder and News letter v2.5.1.8 This vulnerability requires administrative privileges to exploit.
1Kibokolabs
1Arigato Autoresponder And Newsletter
Nov 21, 2024
Dec 3, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
There is a reflected XSS vulnerability in WordPress Arigato Autoresponder and News letter v2.5.1.8 This vulnerability requires administrative privileges to exploit.
1Kibokolabs
1Arigato Autoresponder And Newsletter
Nov 21, 2024
Dec 3, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
There is a reflected XSS vulnerability in WordPress Arigato Autoresponder and News letter v2.5.1.8 This vulnerability requires administrative privileges to exploit.
1Internet2
1Grouper
Nov 21, 2024
Dec 3, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in UiV2Public.index in Internet2 Grouper 2.2 and 2.3 allows remote attackers to inject arbitrary web script or HTML via the code parameter.
3Canonical
DebianLxml
3Debian Linux
LxmlUbuntu Linux
Dec 18, 2025
Dec 2, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in lxml before 4.2.5. lxml/html/clean.py in the lxml.html.clean module does not remove javascript: URLs that use escaping, allowing a remote attacker to conduct XSS attacks, as demonstrated by "j...Show more
An issue was discovered in lxml before 4.2.5. lxml/html/clean.py in the lxml.html.clean module does not remove javascript: URLs that use escaping, allowing a remote attacker to conduct XSS attacks, as demonstrated by "j a v a s c r i p t:" in Internet Explorer. This is a similar issue to CVE-2014-3146.Show less
1Php Proxy
1Php Proxy
Nov 21, 2024
Dec 1, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
PHP-Proxy through 5.1.0 has Cross-Site Scripting (XSS) via the URL field in index.php.
1Schneider Electric
4Modicom Bmxnor0200h Firmware
Modicom M340 FirmwareModicom Premium Firmware+1 more
Jun 17, 2026
Nov 30, 2018
N/A· v4
8.8 HIGH· v3
4.3 MEDIUM· v2
An Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability exists in the embedded web servers in all Modicon M340, Premium, Quantum PLCs and BMXNOR0200 allowing an attacker to send a s...Show more
An Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability exists in the embedded web servers in all Modicon M340, Premium, Quantum PLCs and BMXNOR0200 allowing an attacker to send a specially crafted URL to a currently authenticated web server user to execute a password change on the web server.Show less
1Schneider Electric
4Modicom Bmxnor0200h Firmware
Modicom M340 FirmwareModicom Premium Firmware+1 more
Jun 17, 2026
Nov 30, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists in the embedded web servers in all Modicon M340, Premium, Quantum PLCs and BMXNOR0200 allowing an attacker to c...Show more
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists in the embedded web servers in all Modicon M340, Premium, Quantum PLCs and BMXNOR0200 allowing an attacker to craft a URL containing JavaScript that will be executed within the user's browser, potentially impacting the machine the browser is running on.Show less
1Qnap
1Qts
Nov 21, 2024
Nov 30, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting vulnerability in QTS 4.2.6 build 20180711, QTS 4.3.3: Qsync Central 3.0.2, QTS 4.3.4: Qsync Central 3.0.3, QTS 4.3.5: Qsync Central 3.0.4 and earlier versions could allow remote attackers to inject J...Show more
Cross-site scripting vulnerability in QTS 4.2.6 build 20180711, QTS 4.3.3: Qsync Central 3.0.2, QTS 4.3.4: Qsync Central 3.0.3, QTS 4.3.5: Qsync Central 3.0.4 and earlier versions could allow remote attackers to inject Javascript code in the compromised application.Show less
1I4
1Ai Si Assistant
Nov 21, 2024
Nov 29, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
i4 assistant 7.85 allows XSS via a crafted machine name field within iOS settings.
1Domainmod
1Domainmod
Nov 21, 2024
Nov 29, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
DomainMOD through 4.11.01 has XSS via the assets/add/registrar.php notes field for the Registrar.
1Domainmod
1Domainmod
Nov 21, 2024
Nov 29, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
DomainMOD through 4.11.01 has XSS via the admin/ssl-fields/add.php notes field for Custom SSL Fields.
1Domainmod
1Domainmod
Nov 21, 2024
Nov 29, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
DomainMOD through 4.11.01 has XSS via the admin/domain-fields/ notes field in an Add Custom Field action for Custom Domain Fields.
1Domainmod
1Domainmod
Nov 21, 2024
Nov 29, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
DomainMOD through 4.11.01 has XSS via the assets/add/account-owner.php Owner name field.
1Tp5cms Project
1Tp5cms
Nov 21, 2024
Nov 29, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in tp5cms through 2017-05-25. admin.php/system/set.html has XSS via the title parameter.
1Ibm
7Rational Collaborative Lifecycle Management
Rational Doors Next GenerationRational Engineering Lifecycle Manager+4 more
Nov 21, 2024
Nov 29, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM Rational Collaborative Lifecycle Management 5.0 through 5.0.2 and 6.0 through 6.0.6 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus alteri...Show more
IBM Rational Collaborative Lifecycle Management 5.0 through 5.0.2 and 6.0 through 6.0.6 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 148616.Show less
1Ibm
1Maximo Asset Management
Nov 21, 2024
Nov 28, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM Maximo Asset Management 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to cred...Show more
IBM Maximo Asset Management 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 143497.Show less
1Openwrt
2Lede
Openwrt
Nov 21, 2024
Nov 28, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
cgi_handle_request in uhttpd in OpenWrt through 18.06.1 and LEDE through 17.01 has unauthenticated reflected XSS via the URI, as demonstrated by a cgi-bin/?[XSS] URI.
1Terra Master
1Terramaster Operating System
Nov 21, 2024
Nov 27, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting in Text Editor in TerraMaster TOS version 3.1.03 allows attackers to execute JavaScript via the "filename" URL parameter.