← Back
CWE-79

46,161 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (46,161)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Sem Cms
1Semcms
Nov 21, 2024
Oct 30, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
XSS was discovered in SEMCMS PHP V3.4 via the SEMCMS_SeoAndTag.php?Class=edit&CF=SeoAndTag tag_indexkey parameter.
1Sem Cms
1Semcms
Nov 21, 2024
Oct 30, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
XSS was discovered in SEMCMS PHP V3.4 via the SEMCMS_SeoAndTag.php?Class=edit&CF=SeoAndTag tag_indexmetatit parameter.
1Pagoda Linux Project
1Pagoda Linux
Nov 21, 2024
Oct 30, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Pagoda Linux panel V6.0 has XSS via the verification code associated with an invalid account login. A crafted code is mishandled during rendering of the login log.
1Ibm
1Websphere Application Server
Nov 21, 2024
Oct 29, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 Cachemonitor is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended func...Show more
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 Cachemonitor is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 148621.Show less
1Ibm
1Rational Team Concert
Nov 21, 2024
Oct 29, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM Team Concert (RTC) 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functiona...Show more
IBM Team Concert (RTC) 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 148620.Show less
1Sem Cms
1Semcms
Nov 21, 2024
Oct 29, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
XSS was discovered in SEMCMS V3.4 via the semcms_remail.php?type=ok umail parameter.
1Dedecms
1Dedecms
Nov 21, 2024
Oct 29, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Reflected XSS exists in DedeCMS 5.7 SP2 via the /member/myfriend.php ftype parameter.
1Dedecms
1Dedecms
Nov 21, 2024
Oct 29, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
DedeCMS 5.7 SP2 allows XSS via the /member/uploads_select.php f or keyword parameter.
1Sem Cms
1Semcms
Nov 21, 2024
Oct 29, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
An XSS issue was discovered in SEMCMS 3.4 via admin/SEMCMS_Menu.php?lgid=1 during editing.
1Sem Cms
1Semcms
Nov 21, 2024
Oct 29, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
An XSS issue was discovered in SEMCMS 3.4 via the fifth text box to the admin/SEMCMS_Main.php URI.
1Sem Cms
1Semcms
Nov 21, 2024
Oct 29, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
An XSS issue was discovered in SEMCMS 3.4 via the second text field to the admin/SEMCMS_Categories.php?pid=1&lgid=1 URI.
1Sem Cms
1Semcms
Nov 21, 2024
Oct 29, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
An XSS issue was discovered in SEMCMS 3.4 via admin/SEMCMS_Download.php?lgid=1 during editing.
1Sem Cms
1Semcms
Nov 21, 2024
Oct 29, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
An XSS issue was discovered in SEMCMS 3.4 via the first input field to the admin/SEMCMS_Link.php?lgid=1 URI.
1Sem Cms
1Semcms
Nov 21, 2024
Oct 29, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
An XSS issue was discovered in SEMCMS 3.4 via the admin/SEMCMS_Products.php?lgid=1 Keywords field.
1Sem Cms
1Semcms
Nov 21, 2024
Oct 29, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
An XSS issue was discovered in SEMCMS 3.4 via the admin/SEMCMS_Categories.php?pid=1&lgid=1 category_key parameter.
1Catfish Cms
1Catfish Blog
Nov 21, 2024
Oct 29, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
An XSS issue was discovered in catfish blog 2.0.33, related to "write source code."
1Catfish Cms
1Catfish Cms
Nov 21, 2024
Oct 29, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
An XSS issue was discovered in Catfish CMS 4.8.30, related to "write source code," a similar issue to CVE-2018-13999.
1Yunucms
1Yunucms
Nov 21, 2024
Oct 29, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
An XSS issue was discovered in admin/sitelink/editsitelink?id=16 in YUNUCMS 1.1.5.
1Yunucms
1Yunucms
Nov 21, 2024
Oct 29, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
An XSS issue was discovered in admin/banner/editbanner?id=20 in YUNUCMS 1.1.5.
1Yunucms
1Yunucms
Nov 21, 2024
Oct 29, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
An XSS issue was discovered in index.php/admin/category/editcategory?id=73 in YUNUCMS 1.1.5.