← Back
CWE-79

46,161 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (46,161)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Apache
1Syncope
Nov 21, 2024
Nov 6, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A malicious user with enough administration entitlements can inject html-like elements containing JavaScript statements into Connector names, Report names, AnyTypeClass keys and Policy descriptions. When another user wit...Show more
A malicious user with enough administration entitlements can inject html-like elements containing JavaScript statements into Connector names, Report names, AnyTypeClass keys and Policy descriptions. When another user with enough administration entitlements edits one of the Entities above via Admin Console, the injected JavaScript code is executed.Show less
1Tianma Static Project
1Tianma Static
Nov 21, 2024
Nov 6, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A stored xss in tianma-static module versions <=1.0.4 allows an attacker to execute arbitrary javascript.
1Jeecms
1Jeecms
Nov 21, 2024
Nov 5, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
JEECMS 9.3 has XSS via an index.do#/content/update?type=update URI.
1Basercms
1Basercms
Nov 21, 2024
Nov 5, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
An issue was discovered in baserCMS before 4.1.4. In the Register New Category feature of the Upload menu, the category name can be used for XSS via the data[UploaderCategory][name] parameter to an admin/uploader/uploade...Show more
An issue was discovered in baserCMS before 4.1.4. In the Register New Category feature of the Upload menu, the category name can be used for XSS via the data[UploaderCategory][name] parameter to an admin/uploader/uploader_categories/edit URI.Show less
1Wuzhi Cms Project
1Wuzhi Cms
Nov 21, 2024
Nov 5, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
An issue was discovered in WUZHI CMS 4.1.0. There is stored XSS in index.php?m=core&f=index via a seventh input field.
1Wuzhicms
1Wuzhicms
May 5, 2025
Nov 5, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
An issue was discovered in WUZHI CMS 4.1.0. There is stored XSS in index.php?m=core&f=index via an ontoggle attribute to details/open/ within a second input field.
1Publiccms
1Publiccms
Nov 21, 2024
Nov 4, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
An issue was discovered in PublicCMS V4.0. It allows XSS by modifying the page_list "attached" attribute (which typically has 'class="icon-globe icon-large"' in its value), as demonstrated by an 'UPDATE sys_module SET at...Show more
An issue was discovered in PublicCMS V4.0. It allows XSS by modifying the page_list "attached" attribute (which typically has 'class="icon-globe icon-large"' in its value), as demonstrated by an 'UPDATE sys_module SET attached = "[XSS]" WHERE id="page_list"' statement.Show less
1Iiong
1Wp Editor.md
Nov 21, 2024
Nov 4, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The WP Editor.md plugin 10.0.1 for WordPress allows XSS via the comment area.
1Xheditor
1Xheditor
Nov 21, 2024
Nov 3, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
xhEditor 1.2.2 allows XSS via JavaScript code in the SRC attribute of an IFRAME element within the editor's source-code view.
1Ibm
1Rational Quality Manager
Nov 21, 2024
Nov 2, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM Quality Manager (RQM) 5.0 through 5.0.2 and 6.0 through 6.0.6 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functi...Show more
IBM Quality Manager (RQM) 5.0 through 5.0.2 and 6.0 through 6.0.6 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 132929.Show less
1Rainmachine
1Rainmachine Web Application
Jun 17, 2026
Nov 1, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A persistent Cross Site Scripting (XSS) vulnerability in the Green Electronics RainMachine Mini-8 (2nd Generation) and Touch HD 12 web application allows an attacker to inject arbitrary JavaScript via the REST API.
1Microstrategy
1Microstrategy Web
Nov 21, 2024
Nov 1, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Microstrategy Web, version 7, does not sufficiently encode user-controlled inputs, resulting in a Cross-Site Scripting (XSS) vulnerability via the admin/admin.asp ShowAll parameter. NOTE: this is a deprecated product.
1Microstrategy
1Microstrategy Web
Nov 21, 2024
Nov 1, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Microstrategy Web, version 7, does not sufficiently encode user-controlled inputs, resulting in a Cross-Site Scripting (XSS) vulnerability via the Login.asp Msg parameter. NOTE: this is a deprecated product.
1Netgain Systems
1Enterprise Manager
Nov 21, 2024
Nov 1, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
NetGain Enterprise Manager (EM) is affected by multiple Stored Cross-Site Scripting (XSS) vulnerabilities in versions before 10.1.12.
1Advantech
1Webaccess
Nov 21, 2024
Oct 31, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Advantech WebAccess 8.3.1 and 8.3.2 are vulnerable to cross-site scripting in the Bwmainleft.asp page. An attacker could leverage this vulnerability to disclose credentials amongst other things.
1Redhat
1Jboss Bpm Suite
Nov 21, 2024
Oct 31, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
JBoss BPM Suite 6 is vulnerable to a reflected XSS via dashbuilder. Remote attackers can entice authenticated users that have privileges to access dashbuilder (usually admins) to click on links to /dashbuilder/Controller...Show more
JBoss BPM Suite 6 is vulnerable to a reflected XSS via dashbuilder. Remote attackers can entice authenticated users that have privileges to access dashbuilder (usually admins) to click on links to /dashbuilder/Controller containing malicious scripts. Successful exploitation would allow execution of script code within the context of the affected user.Show less
1No Cms Project
1No Cms
Nov 21, 2024
Oct 31, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
No-CMS 1.1.3 is prone to Persistent XSS via a contact_us name parameter, as demonstrated by the VG48Z5PqVWname parameter.
2Debian
Loofah Project
2Debian Linux
Loofah
Nov 21, 2024
Oct 30, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
In the Loofah gem for Ruby, through v2.2.2, unsanitized JavaScript may occur in sanitized output when a crafted SVG element is republished.
1Mantisbt
1Mantisbt
Nov 21, 2024
Oct 30, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A cross-site scripting (XSS) vulnerability in the Edit Filter page (manage_filter_edit page.php) in MantisBT 2.1.0 through 2.17.1 allows remote attackers (if access rights permit it) to inject arbitrary code (if CSP sett...Show more
A cross-site scripting (XSS) vulnerability in the Edit Filter page (manage_filter_edit page.php) in MantisBT 2.1.0 through 2.17.1 allows remote attackers (if access rights permit it) to inject arbitrary code (if CSP settings permit it) through a crafted project name.Show less
1Mantisbt
1Mantisbt
Nov 21, 2024
Oct 30, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A cross-site scripting (XSS) vulnerability in the Manage Filters page (manage_filter_page.php) in MantisBT 2.1.0 through 2.17.1 allows remote attackers (if access rights permit it) to inject arbitrary code (if CSP settin...Show more
A cross-site scripting (XSS) vulnerability in the Manage Filters page (manage_filter_page.php) in MantisBT 2.1.0 through 2.17.1 allows remote attackers (if access rights permit it) to inject arbitrary code (if CSP settings permit it) through a crafted project name.Show less