← Back
CWE-79

46,160 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (46,160)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Mitel
1Mivoice Office 400
Nov 21, 2024
Oct 23, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A vulnerability in the web admin component of Mitel MiVoice Office 400, versions R5.0 HF3 (v8839a1) and earlier, could allow an unauthenticated attacker to conduct a reflected cross-site scripting (XSS) attack, due to in...Show more
A vulnerability in the web admin component of Mitel MiVoice Office 400, versions R5.0 HF3 (v8839a1) and earlier, could allow an unauthenticated attacker to conduct a reflected cross-site scripting (XSS) attack, due to insufficient validation for the start.asp page. A successful exploit could allow the attacker to execute arbitrary scripts to access sensitive browser-based information.Show less
1Mitel
1St Firmware
Nov 21, 2024
Oct 23, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A vulnerability in the conferencing component of Mitel ST 14.2, versions GA29 (19.49.9400.0) and earlier, could allow an unauthenticated attacker to conduct a reflected cross-site scripting (XSS) attack due to insufficie...Show more
A vulnerability in the conferencing component of Mitel ST 14.2, versions GA29 (19.49.9400.0) and earlier, could allow an unauthenticated attacker to conduct a reflected cross-site scripting (XSS) attack due to insufficient validation for the signin.php page. A successful exploit could allow an attacker to execute arbitrary scripts.Show less
1Bijiadao
1Waimai Super Cms
Nov 21, 2024
Oct 23, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in Waimai Super Cms 20150505. There is XSS via the index.php?m=public&a=doregister username parameter.
1Dedecms
1Dedecms
Nov 21, 2024
Oct 23, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
DedeCMS 5.7 SP2 allows XSS via the function named GetPageList defined in the include/datalistcp.class.php file that is used to display the page numbers list at the bottom of some templates, as demonstrated by the PATH_IN...Show more
DedeCMS 5.7 SP2 allows XSS via the function named GetPageList defined in the include/datalistcp.class.php file that is used to display the page numbers list at the bottom of some templates, as demonstrated by the PATH_INFO to /member/index.php, /member/pm.php, /member/content_list.php, or /plus/feedback.php.Show less
1Dedecms
1Dedecms
Nov 21, 2024
Oct 22, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Reflected XSS exists in DedeCMS 5.7 SP2 via the /member/pm.php folder parameter.
1Dedecms
1Dedecms
Nov 21, 2024
Oct 22, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
DedeCMS 5.7 SP2 allows XSS via the plus/qrcode.php type parameter.
1Advantech
1Webaccess
Nov 21, 2024
Oct 22, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Advantech WebAccess 8.3.2 and below is vulnerable to multiple reflected cross site scripting vulnerabilities. A remote unauthenticated attacker could potentially exploit this vulnerability by tricking a victim to supply...Show more
Advantech WebAccess 8.3.2 and below is vulnerable to multiple reflected cross site scripting vulnerabilities. A remote unauthenticated attacker could potentially exploit this vulnerability by tricking a victim to supply malicious HTML or JavaScript code to WebAccess, which is then reflected back to the victim and executed by the web browser.Show less
1Symantec
1Web Isolation
Nov 21, 2024
Oct 22, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Symantec Web Isolation (WI) 1.11 prior to 1.11.21 is susceptible to a reflected cross-site scripting (XSS) vulnerability. A remote attacker can target end users protected by WI with social engineering attacks using craft...Show more
Symantec Web Isolation (WI) 1.11 prior to 1.11.21 is susceptible to a reflected cross-site scripting (XSS) vulnerability. A remote attacker can target end users protected by WI with social engineering attacks using crafted URLs for legitimate web sites. A successful attack allows injecting malicious JavaScript code into the website's rendered copy running inside the end user's web browser. It does not allow injecting code into the real (isolated) copy of the website running on the WI Threat Isolation Engine.Show less
1Leanote
1Leanote
Nov 21, 2024
Oct 22, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Leanote 2.6.1 has XSS via the Blog Basic Setting title field, which is mishandled during rendering of the "likes" page.
1Fiyo
1Fiyo Cms
Nov 21, 2024
Oct 21, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Fiyo CMS 2.0.7 has XSS via the dapur\apps\app_user\edit_user.php name parameter.
1Teakki
1Teakki
Nov 21, 2024
Oct 20, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
TeaKKi 2.7 allows XSS via a crafted onerror attribute for a picture's URL.
1Ardawan
1User Management
Nov 21, 2024
Oct 19, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Stored XSS has been discovered in the upload section of ARDAWAN.COM User Management 1.1, as demonstrated by a .jpg filename to the /account URI.
1Creativeitem
1Ekushey Project Manager
Nov 21, 2024
Oct 19, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
In the 3.1 version of Ekushey Project Manager CRM, Stored XSS has been discovered in the input and upload sections, as demonstrated by the name parameter to the index.php/admin/client/create URI.
1Pokkho
1Lango
Nov 21, 2024
Oct 19, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
LANGO Codeigniter Multilingual Script 1.0 has XSS in the input and upload sections, as demonstrated by the site_name parameter to the admin/settings/update URI.
1Sv3c
1H.264 Poe Ip Camera Firmware
Nov 21, 2024
Oct 19, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The SV3C HD Camera (L-SERIES V2.3.4.2103-S50-NTD-B20170508B) does not perform proper validation on user-supplied input and is vulnerable to cross-site scripting attacks. If proper authorization was implemented, this vuln...Show more
The SV3C HD Camera (L-SERIES V2.3.4.2103-S50-NTD-B20170508B) does not perform proper validation on user-supplied input and is vulnerable to cross-site scripting attacks. If proper authorization was implemented, this vulnerability could be leveraged to perform actions on behalf of another user or the administrator.Show less
1F5
13Big Ip Access Policy Manager
Big Ip Advanced Firewall ManagerBig Ip Analytics+10 more
Nov 21, 2024
Oct 19, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
On F5 BIG-IP 13.0.0-13.1.1.1 and 12.1.0-12.1.3.6, there is a reflected Cross Site Scripting (XSS) vulnerability in an undisclosed Configuration Utility page.
1F5
1Big Ip Advanced Firewall Manager
Nov 21, 2024
Oct 19, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
On F5 BIG-IP AFM 13.0.0-13.1.1.1 and 12.1.0-12.1.3.6, there is a Reflected Cross Site Scripting vulnerability in undisclosed TMUI page.
1F5
1Big Ip Advanced Firewall Manager
Nov 21, 2024
Oct 19, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
On F5 BIG-IP AFM 13.0.0-13.1.1.1 and 12.1.0-12.1.3.6, there is a Reflected Cross Site Scripting vulnerability in undisclosed TMUI page.
1F5
13Big Ip Access Policy Manager
Big Ip Advanced Firewall ManagerBig Ip Analytics+10 more
Nov 21, 2024
Oct 19, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
On F5 BIG-IP 13.0.0-13.1.1.1 and 12.1.0-12.1.3.6, a reflected Cross-Site Scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an authenticated user to execute JavaSc...Show more
On F5 BIG-IP 13.0.0-13.1.1.1 and 12.1.0-12.1.3.6, a reflected Cross-Site Scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an authenticated user to execute JavaScript for the currently logged-in user.Show less
1Koha
1Koha
Nov 21, 2024
Oct 18, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Multiple cross-site scripting (XSS) vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before 3.18.08, and 3.20.x before 3.20.1 allow remote attackers to inject arbitrary web script or HTML via...Show more
Multiple cross-site scripting (XSS) vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before 3.18.08, and 3.20.x before 3.20.1 allow remote attackers to inject arbitrary web script or HTML via the (1) tag parameter to opac-search.pl; the (2) value parameter to authorities/authorities-home.pl; the (3) delay parameter to acqui/lateorders.pl; the (4) authtypecode or (5) tagfield to admin/auth_subfields_structure.pl; the (6) tagfield parameter to admin/marc_subfields_structure.pl; the (7) limit parameter to catalogue/search.pl; the (8) bookseller_filter, (9) callnumber_filter, (10) EAN_filter, (11) ISSN_filter, (12) publisher_filter, or (13) title_filter parameter to serials/serials-search.pl; or the (14) author, (15) collectiontitle, (16) copyrightdate, (17) isbn, (18) manageddate_from, (19) manageddate_to, (20) publishercode, (21) suggesteddate_from, or (22) suggesteddate_to parameter to suggestion/suggestion.pl; or the (23) direction, (24) display or (25) addshelf parameter to opac-shelves.pl.Show less