← Back
CWE-79

46,160 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (46,160)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Yunucms
1Yunucms
Nov 21, 2024
Oct 29, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
An XSS issue was discovered in admin/content/editcontent?id=29&gopage=1 in YUNUCMS 1.1.5.
1Yunucms
1Yunucms
Nov 21, 2024
Oct 29, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
An XSS issue was discovered in admin/link/editlink?id=5 in YUNUCMS 1.1.5.
1Yunucms
1Yunucms
Nov 21, 2024
Oct 29, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
An XSS issue was discovered in index.php/admin/system/basic in YUNUCMS 1.1.5.
1Eleanor Cms
1Eleanor Cms
Nov 21, 2024
Oct 29, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
An issue was discovered in Eleanor CMS through 2015-03-19. XSS exists via the ajax.php?direct=admin&file=autocomplete&query=[XSS] URI.
1Monstra
1Monstra
Nov 21, 2024
Oct 29, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
admin/index.php?id=filesmanager in Monstra CMS 3.0.4 allows remote authenticated administrators to trigger stored XSS via JavaScript content in a file whose name lacks an extension. Such a file is interpreted as text/htm...Show more
admin/index.php?id=filesmanager in Monstra CMS 3.0.4 allows remote authenticated administrators to trigger stored XSS via JavaScript content in a file whose name lacks an extension. Such a file is interpreted as text/html in certain cases.Show less
1Arcserve
1Udp
Nov 21, 2024
Oct 26, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in Arcserve Unified Data Protection (UDP) through 6.5 Update 4. There is a DDI-VRT-2018-21 Reflected Cross-site Scripting via /authenticationendpoint/domain.jsp issue.
1Geovap
1Reliance 4
Nov 21, 2024
Oct 25, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Reliance 4 SCADA/HMI, Version 4.7.3 Update 3 and prior. This vulnerability could allow an unauthorized attacker to inject arbitrary code.
1Communigate
1Communigate Pro
Nov 21, 2024
Oct 24, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
CommuniGate Pro 6.2 allows stored XSS via a message body in Pronto! Mail Composer, which is mishandled in /MIME/INBOX-MM-1/ if the raw email link (in .txt format) is modified and then renamed with a .html or .wssp extens...Show more
CommuniGate Pro 6.2 allows stored XSS via a message body in Pronto! Mail Composer, which is mishandled in /MIME/INBOX-MM-1/ if the raw email link (in .txt format) is modified and then renamed with a .html or .wssp extension.Show less
1Serverscheck
1Monitoring Software
Nov 21, 2024
Oct 24, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
ServersCheck Monitoring Software through 14.3.3 has Persistent and Reflected XSS via the sensors.html status parameter, sensors.html type parameter, sensors.html device parameter, report.html location parameter, group_de...Show more
ServersCheck Monitoring Software through 14.3.3 has Persistent and Reflected XSS via the sensors.html status parameter, sensors.html type parameter, sensors.html device parameter, report.html location parameter, group_delete.html group parameter, report_save.html query parameter, sensors.html location parameter, or group_delete.html group parameter.Show less
1Eaton
19px Ups Firmware
Jun 17, 2026
Oct 24, 2018
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
An issue was discovered on Eaton UPS 9PX 8000 SP devices. The administration panel is vulnerable to a CSRF attack on the change-password functionality. This vulnerability could be used to force a logged-in administrator...Show more
An issue was discovered on Eaton UPS 9PX 8000 SP devices. The administration panel is vulnerable to a CSRF attack on the change-password functionality. This vulnerability could be used to force a logged-in administrator to perform a silent password update. The affected forms are also vulnerable to Reflected Cross-Site Scripting vulnerabilities. This flaw could be triggered by driving an administrator logged into the Eaton application to a specially crafted web page. This attack could be done silently.Show less
1D Link
1Dsl 2640t Firmware
Nov 21, 2024
Oct 24, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
XSS exists in cgi-bin/webcm on D-link DSL-2640T routers via the var:RelaodHref or var:conid parameter.
1Mailcleaner
1Mailcleaner
Nov 21, 2024
Oct 24, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
www/guis/admin/application/controllers/UserController.php in the administration login interface in MailCleaner CE 2018.08 and 2018.09 allows XSS via the admin/login/user/message/ PATH_INFO.
1Ajenti
1Ajenticp
Nov 21, 2024
Oct 24, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
ajenticp (aka Ajenti Docker control panel) for Ajenti through v1.2.23.13 has XSS via a filename that is mishandled in File Manager.
1Vestacp
1Control Panel
Nov 21, 2024
Oct 24, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Vesta Control Panel through 0.9.8-22 has XSS via the edit/web/ domain parameter, the list/backup/ backup parameter, the list/rrd/ period parameter, the list/directory/ dir_a parameter, or the filename to the list/directo...Show more
Vesta Control Panel through 0.9.8-22 has XSS via the edit/web/ domain parameter, the list/backup/ backup parameter, the list/rrd/ period parameter, the list/directory/ dir_a parameter, or the filename to the list/directory/ URI.Show less
1Citrix
1Netscaler Gateway Firmware
Nov 21, 2024
Oct 24, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Citrix NetScaler Gateway 10.5.x before 10.5.69.003, 11.1.x before 11.1.59.004, 12.0.x before 12.0.58.7, and 12.1.x before 12.1.49.1 has XSS.
1Myadrenalin
1Human Resource Management Software
Mar 2, 2026
Oct 24, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Adrenalin HRMS version 5.4.0 contains a Reflected Cross Site Scripting (XSS) vulnerability in the ApplicationtEmployeeSearch page via 'prntDDLCntrlName' and 'prntFrmName'.
1Ibm
1Websphere Commerce
Nov 21, 2024
Oct 24, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM WebSphere Commerce Enterprise V7, V8, and V9 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentiall...Show more
IBM WebSphere Commerce Enterprise V7, V8, and V9 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 142596.Show less
1Splunk
1Splunk
Jun 17, 2026
Oct 23, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in Splunk Web in Splunk Enterprise 6.0.x before 6.0.14, 6.1.x before 6.1.13, 6.2.x before 6.2.14, 6.3.x before 6.3.10, 6.4.x before 6.4.7, and 6.5.x before 6.5.3; and Splunk Light...Show more
Cross-site scripting (XSS) vulnerability in Splunk Web in Splunk Enterprise 6.0.x before 6.0.14, 6.1.x before 6.1.13, 6.2.x before 6.2.14, 6.3.x before 6.3.10, 6.4.x before 6.4.7, and 6.5.x before 6.5.3; and Splunk Light before 6.6.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.Show less
1Axiositalia
1Registro Elettronico
Nov 21, 2024
Oct 23, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In AXIOS ITALIA Axioscloud Sissiweb Registro Elettronico 1.7.0, secret/relogoff.aspx has XSS via the Error_Desc parameter.
1Telligent
1Community
Nov 21, 2024
Oct 23, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Telligent Community 6.x, 7.x, 8.x, 9.x before 9.2.10.11796, 10.1.x before 10.1.10.11792, and 10.2.x before 10.2.3.4725 has XSS via the Feed RSS widget.