← Back
CWE-79

46,161 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (46,161)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Showdoc
1Showdoc
Nov 21, 2024
Nov 22, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
ShowDoc 2.4.1 has XSS via the lang parameter because install/database.php mishandles the $cur_lang value.
1Loadbalancer
1Enterprise Va Max
Nov 21, 2024
Nov 20, 2018
N/A· v4
9.6 CRITICAL· v3
9.3 HIGH· v2
Loadbalancer.org Enterprise VA MAX before 8.3.3 has XSS because Apache HTTP Server logs are displayed.
1Control Webpanel
1Webpanel
Nov 21, 2024
Nov 20, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
CentOS-WebPanel.com (aka CWP) CentOS Web Panel through 0.9.8.740 allows XSS via the admin/index.php module parameter.
1Zohocorp
1Manageengine Opmanager
Nov 21, 2024
Nov 20, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Zoho ManageEngine OpManager 12.3 before 123219 has a Self XSS Vulnerability.
1Zohocorp
1Manageengine Opmanager
Nov 21, 2024
Nov 20, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Zoho ManageEngine OpManager 12.3 before 123219 has stored XSS.
1Jupyter
1Notebook
Nov 21, 2024
Nov 18, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Jupyter Notebook before 5.7.2 allows XSS via a crafted directory name because notebook/static/tree/js/notebooklist.js handles certain URLs unsafely.
1Jupyter
1Notebook
Nov 21, 2024
Nov 18, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Jupyter Notebook before 5.7.1 allows XSS via an untrusted notebook because nbconvert responses are considered to have the same origin as the notebook server. In other words, nbconvert endpoints can execute JavaScript wit...Show more
Jupyter Notebook before 5.7.1 allows XSS via an untrusted notebook because nbconvert responses are considered to have the same origin as the notebook server. In other words, nbconvert endpoints can execute JavaScript with access to the server API. In notebook/nbconvert/handlers.py, NbconvertFileHandler and NbconvertPostHandler do not set a Content Security Policy to prevent this.Show less
1Seacms
1Seacms
Nov 21, 2024
Nov 17, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
In SeaCMS v6.6.4, there is stored XSS via the member.php?action=chgpwdsubmit email parameter during a password change, as demonstrated by a data: URL in an OBJECT element.
1Guriddo
1Form Php
Nov 21, 2024
Nov 17, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Guriddo Form PHP 5.3 has XSS via the demos/jqform/defaultnodb/default.php OrderID, ShipName, ShipAddress, ShipCity, ShipPostalCode, ShipCountry, Freight, or details parameter.
1Kimsq
1Rb
Nov 21, 2024
Nov 17, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
kimsQ Rb 2.3.0 allows XSS via the second input field to the /?r=home&mod=mypage&page=info URI.
1Centreon
1Centreon
Nov 21, 2024
Nov 16, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Centreon 3.4.x (fixed in Centreon 18.10.0) allows XSS via the Service field to the main.php?p=20201 URI, as demonstrated by the "Monitoring > Status Details > Services" screen.
1Tp4a
1Teleport
Nov 21, 2024
Nov 15, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
tp4a TELEPORT 3.1.0 allows XSS via the login page because a crafted username is mishandled when an administrator later views the system log.
1Sonatype
1Nexus Repository Manager
Nov 21, 2024
Nov 15, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Sonatype Nexus Repository Manager before 3.14 allows XSS.
1Polycom
1Trio 8500 Firmware
Nov 21, 2024
Nov 15, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Web administration console on Polycom Trio devices with software before 5.5.4 has XSS.
1Ibm
1Websphere Application Server
Nov 21, 2024
Nov 15, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Installation Verification Tool of IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus a...Show more
The Installation Verification Tool of IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 144588Show less
1Hyuki
1Yukiwiki
Nov 21, 2024
Nov 15, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting vulnerability in YukiWiki 2.1.3 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
1Metabase
1Metabase
Nov 21, 2024
Nov 15, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting vulnerability in Metabase version 0.29.3 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
1Usvn
1Usvn
Nov 21, 2024
Nov 15, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting vulnerability in User-friendly SVN (USVN) Version 1.0.7 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
1Neo
2Debun Imap
Debun Pop
Nov 21, 2024
Nov 15, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting vulnerability in Denbun by NEOJAPAN Inc. (Denbun POP version V3.3P R4.0 and earlier, Denbun IMAP version V3.3I R4.0 and earlier) allows remote attackers to inject arbitrary web script or HTML via uns...Show more
Cross-site scripting vulnerability in Denbun by NEOJAPAN Inc. (Denbun POP version V3.3P R4.0 and earlier, Denbun IMAP version V3.3I R4.0 and earlier) allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.Show less
1Fxc
10Ae1021 Firmware
Ae1021pe FirmwareFxc5210 Firmware+7 more
Nov 21, 2024
Nov 15, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Cross-site scripting vulnerability in multiple FXC Inc. network devices (Managed Ethernet switch FXC5210/5218/5224 firmware prior to version Ver1.00.22, Managed Ethernet switch FXC5426F firmware prior to version Ver1.00....Show more
Cross-site scripting vulnerability in multiple FXC Inc. network devices (Managed Ethernet switch FXC5210/5218/5224 firmware prior to version Ver1.00.22, Managed Ethernet switch FXC5426F firmware prior to version Ver1.00.06, Managed Ethernet switch FXC5428 firmware prior to version Ver1.00.07, Power over Ethernet (PoE) switch FXC5210PE/5218PE/5224PE firmware prior to version Ver1.00.14, and Wireless LAN router AE1021/AE1021PE firmware all versions) allows attacker with administrator rights to inject arbitrary web script or HTML via the administrative page.Show less