CWE-79
46,161 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (46,161)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
ShowDoc 2.4.1 has XSS via the lang parameter because install/database.php mishandles the $cur_lang value. |
1Loadbalancer 1Enterprise Va Max Nov 21, 2024 Nov 20, 2018 N/A· v4 9.6 CRITICAL· v3 9.3 HIGH· v2 Loadbalancer.org Enterprise VA MAX before 8.3.3 has XSS because Apache HTTP Server logs are displayed. |
CentOS-WebPanel.com (aka CWP) CentOS Web Panel through 0.9.8.740 allows XSS via the admin/index.php module parameter. |
1Zohocorp 1Manageengine Opmanager Nov 21, 2024 Nov 20, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Zoho ManageEngine OpManager 12.3 before 123219 has a Self XSS Vulnerability. |
1Zohocorp 1Manageengine Opmanager Nov 21, 2024 Nov 20, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Zoho ManageEngine OpManager 12.3 before 123219 has stored XSS. |
Jupyter Notebook before 5.7.2 allows XSS via a crafted directory name because notebook/static/tree/js/notebooklist.js handles certain URLs unsafely. |
Jupyter Notebook before 5.7.1 allows XSS via an untrusted notebook because nbconvert responses are considered to have the same origin as the notebook server. In other words, nbconvert endpoints can execute JavaScript wit...Show more |
In SeaCMS v6.6.4, there is stored XSS via the member.php?action=chgpwdsubmit email parameter during a password change, as demonstrated by a data: URL in an OBJECT element. |
Guriddo Form PHP 5.3 has XSS via the demos/jqform/defaultnodb/default.php OrderID, ShipName, ShipAddress, ShipCity, ShipPostalCode, ShipCountry, Freight, or details parameter. |
kimsQ Rb 2.3.0 allows XSS via the second input field to the /?r=home&mod=mypage&page=info URI. |
Centreon 3.4.x (fixed in Centreon 18.10.0) allows XSS via the Service field to the main.php?p=20201 URI, as demonstrated by the "Monitoring > Status Details > Services" screen. |
tp4a TELEPORT 3.1.0 allows XSS via the login page because a crafted username is mishandled when an administrator later views the system log. |
1Sonatype 1Nexus Repository Manager Nov 21, 2024 Nov 15, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Sonatype Nexus Repository Manager before 3.14 allows XSS. |
1Polycom 1Trio 8500 Firmware Nov 21, 2024 Nov 15, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The Web administration console on Polycom Trio devices with software before 5.5.4 has XSS. |
1Ibm 1Websphere Application Server Nov 21, 2024 Nov 15, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The Installation Verification Tool of IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus a...Show more |
Cross-site scripting vulnerability in YukiWiki 2.1.3 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. |
Cross-site scripting vulnerability in Metabase version 0.29.3 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. |
Cross-site scripting vulnerability in User-friendly SVN (USVN) Version 1.0.7 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. |
Cross-site scripting vulnerability in Denbun by NEOJAPAN Inc. (Denbun POP version V3.3P R4.0 and earlier, Denbun IMAP version V3.3I R4.0 and earlier) allows remote attackers to inject arbitrary web script or HTML via uns...Show more |
1Fxc 10Ae1021 Firmware Ae1021pe FirmwareFxc5210 Firmware+7 moreNov 21, 2024 Nov 15, 2018 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 Cross-site scripting vulnerability in multiple FXC Inc. network devices (Managed Ethernet switch FXC5210/5218/5224 firmware prior to version Ver1.00.22, Managed Ethernet switch FXC5426F firmware prior to version Ver1.00....Show more |