CWE-79
46,161 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (46,161)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
In JPress v1.0-rc.5, there is stored XSS via each of the first three input fields to the starter-tomcat-1.0/admin/setting URI, as demonstrated by the web_name parameter. |
1Otrs 1Open Ticket Request System Nov 21, 2024 Nov 11, 2018 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 Open Ticket Request System (OTRS) 6.0.x before 6.0.13 allows an admin to conduct an XSS attack via a modified URL. |
2Debian Otrs2Debian Linux Open Ticket Request SystemNov 21, 2024 Nov 11, 2018 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 Open Ticket Request System (OTRS) 4.0.x before 4.0.33 and 5.0.x before 5.0.31 allows an admin to conduct an XSS attack via a modified URL because user and customer preferences are mishandled. |
An issue was discovered in S-CMS v1.5. There is an XSS vulnerability in search.php via the keyword parameter. |
DomainMOD through 4.11.01 has XSS via the assets/edit/ip-address.php ipid parameter. |
DomainMOD through 4.11.01 has XSS via the assets/edit/registrar-account.php raid parameter. |
IBM Maximo Asset Management 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to cred...Show more |
Squid before 4.4 has XSS via a crafted X.509 certificate during HTTP(S) error page generation for certificate errors. |
A vulnerability in the web-based management interface of Cisco Prime Service Catalog could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management...Show more |
1Cisco 1Content Security Management Appliance Nov 21, 2024 Nov 8, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 A vulnerability in the web-based management interface of Cisco Content Security Management Appliance (SMA) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a...Show more |
An issue was discovered in YzmCMS v5.2. It has XSS via a search/index/archives/pubtime/ query string, as demonstrated by the search/index/archives/pubtime/1526387722/page/1.html URI. NOTE: this does not obtain a user's c...Show more |
tianti 2.3 has reflected XSS in the user management module via the tianti-module-admin/user/list userName parameter. |
tianti 2.3 has stored XSS in the article management module via an article title. |
tianti 2.3 has stored XSS in the userlist module via the tianti-module-admin/user/ajax/save_role name parameter, which is mishandled in tianti-module-admin\src\main\webapp\WEB-INF\views\user\user_list.jsp. |
WeCenter 3.2.0 through 3.2.2 has XSS in the views/default/question/index.tpl.html htmlspecialchars_decode function via the /?/publish/ajax/publish_question/ question_content parameter. |
2Foscam Opticam4C2 Application Firmware C2 System FirmwareI5 Application Firmware+1 moreNov 21, 2024 Nov 7, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered on Foscam Opticam i5 devices with System Firmware 1.5.2.11 and Application Firmware 2.21.1.128. The ONVIF devicemgmt SetHostname method allows unauthenticated persistent XSS. |
SimpleMDE 1.11.2 has XSS via an onerror attribute of a crafted IMG element, or via certain input with [ and ( characters, which is mishandled during construction of an A element. |
pandao Editor.md 1.5.0 has DOM XSS via input starting with a "<<" substring, which is mishandled during construction of an A element. |
MetInfo 6.1.3 has XSS via the admin/index.php?a=dogetpassword abt_type parameter. |
MetInfo 6.1.3 has XSS via the admin/index.php?a=dogetpassword langset parameter. |