← Back
CWE-79

46,161 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (46,161)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Jpress
1Jpress
Nov 21, 2024
Nov 11, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
In JPress v1.0-rc.5, there is stored XSS via each of the first three input fields to the starter-tomcat-1.0/admin/setting URI, as demonstrated by the web_name parameter.
1Otrs
1Open Ticket Request System
Nov 21, 2024
Nov 11, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Open Ticket Request System (OTRS) 6.0.x before 6.0.13 allows an admin to conduct an XSS attack via a modified URL.
2Debian
Otrs
2Debian Linux
Open Ticket Request System
Nov 21, 2024
Nov 11, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Open Ticket Request System (OTRS) 4.0.x before 4.0.33 and 5.0.x before 5.0.31 allows an admin to conduct an XSS attack via a modified URL because user and customer preferences are mishandled.
1S Cms
1S Cms
Nov 21, 2024
Nov 9, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in S-CMS v1.5. There is an XSS vulnerability in search.php via the keyword parameter.
1Domainmod
1Domainmod
Nov 21, 2024
Nov 9, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
DomainMOD through 4.11.01 has XSS via the assets/edit/ip-address.php ipid parameter.
1Domainmod
1Domainmod
Nov 21, 2024
Nov 9, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
DomainMOD through 4.11.01 has XSS via the assets/edit/registrar-account.php raid parameter.
1Ibm
1Maximo Asset Management
Nov 21, 2024
Nov 9, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM Maximo Asset Management 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to cred...Show more
IBM Maximo Asset Management 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 151330.Show less
1Squid Cache
1Squid
Nov 21, 2024
Nov 9, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Squid before 4.4 has XSS via a crafted X.509 certificate during HTTP(S) error page generation for certificate errors.
1Cisco
1Prime Service Catalog
Nov 21, 2024
Nov 8, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A vulnerability in the web-based management interface of Cisco Prime Service Catalog could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management...Show more
A vulnerability in the web-based management interface of Cisco Prime Service Catalog could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface. The vulnerability is due to insufficient validation of user-supplied input that is processed by the web-based management interface. An attacker could exploit this vulnerability by persuading a user of the interface to click a maliciously crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface or access sensitive browser-based information.Show less
1Cisco
1Content Security Management Appliance
Nov 21, 2024
Nov 8, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A vulnerability in the web-based management interface of Cisco Content Security Management Appliance (SMA) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a...Show more
A vulnerability in the web-based management interface of Cisco Content Security Management Appliance (SMA) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface. The vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of an affected device. An attacker could exploit this vulnerability by persuading a user of the interface to click a maliciously crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.Show less
1Yzmcms
1Yzmcms
Nov 21, 2024
Nov 7, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in YzmCMS v5.2. It has XSS via a search/index/archives/pubtime/ query string, as demonstrated by the search/index/archives/pubtime/1526387722/page/1.html URI. NOTE: this does not obtain a user's c...Show more
An issue was discovered in YzmCMS v5.2. It has XSS via a search/index/archives/pubtime/ query string, as demonstrated by the search/index/archives/pubtime/1526387722/page/1.html URI. NOTE: this does not obtain a user's cookie.Show less
1Tianti Project
1Tianti
Nov 21, 2024
Nov 7, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
tianti 2.3 has reflected XSS in the user management module via the tianti-module-admin/user/list userName parameter.
1Tianti Project
1Tianti
Nov 21, 2024
Nov 7, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
tianti 2.3 has stored XSS in the article management module via an article title.
1Tianti Project
1Tianti
Nov 21, 2024
Nov 7, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
tianti 2.3 has stored XSS in the userlist module via the tianti-module-admin/user/ajax/save_role name parameter, which is mishandled in tianti-module-admin\src\main\webapp\WEB-INF\views\user\user_list.jsp.
1Wecenter
1Wecenter
Nov 21, 2024
Nov 7, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
WeCenter 3.2.0 through 3.2.2 has XSS in the views/default/question/index.tpl.html htmlspecialchars_decode function via the /?/publish/ajax/publish_question/ question_content parameter.
2Foscam
Opticam
4C2 Application Firmware
C2 System FirmwareI5 Application Firmware+1 more
Nov 21, 2024
Nov 7, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered on Foscam Opticam i5 devices with System Firmware 1.5.2.11 and Application Firmware 2.21.1.128. The ONVIF devicemgmt SetHostname method allows unauthenticated persistent XSS.
1Sparksuite
1Simplemde
Nov 21, 2024
Nov 7, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
SimpleMDE 1.11.2 has XSS via an onerror attribute of a crafted IMG element, or via certain input with [ and ( characters, which is mishandled during construction of an A element.
1Ipandao
1Editor.md
Nov 21, 2024
Nov 7, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
pandao Editor.md 1.5.0 has DOM XSS via input starting with a "<<" substring, which is mishandled during construction of an A element.
1Metinfo
1Metinfo
Nov 21, 2024
Nov 7, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
MetInfo 6.1.3 has XSS via the admin/index.php?a=dogetpassword abt_type parameter.
1Metinfo
1Metinfo
Nov 21, 2024
Nov 7, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
MetInfo 6.1.3 has XSS via the admin/index.php?a=dogetpassword langset parameter.