← Back
CWE-79

46,160 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (46,160)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Metinfo
1Metinfo
Nov 21, 2024
Oct 16, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
XSS exists in the MetInfo 6.1.2 admin/index.php page via the anyid parameter.
1Tuzitio
1Camaleon Cms
Nov 21, 2024
Oct 15, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In the 2.4 version of Camaleon CMS, Stored XSS has been discovered. The profile image in the User settings section can be run in the update / upload area via /admin/media/upload?actions=false. NOTE: the vendor reports th...Show more
In the 2.4 version of Camaleon CMS, Stored XSS has been discovered. The profile image in the User settings section can be run in the update / upload area via /admin/media/upload?actions=false. NOTE: the vendor reports that they are "unable to reproduce the reported issue on any version."Show less
1Luya
1Luya Cms
Nov 21, 2024
Oct 15, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Stored XSS has been discovered in version 1.0.12 of the LUYA CMS software via /admin/api-cms-nav/create-page.
1Teltonika
3Rut900 Firmware
Rut950 FirmwareRut955 Firmware
Nov 21, 2024
Oct 15, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Teltonika RUT9XX routers with firmware before 00.05.01.1 are prone to cross-site scripting vulnerabilities in hotspotlogin.cgi due to insufficient user input sanitization.
1Agentejo
1Cockpit
Nov 21, 2024
Oct 15, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Agentejo Cockpit has multiple Cross-Site Scripting vulnerabilities.
4Canonical
DebianMoinmo+1 more
4Debian Linux
LeapMoinmoin+1 more
Nov 21, 2024
Oct 15, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in the link dialogue in GUI editor in MoinMoin before 1.9.10 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
1Nconsulting
1Nc Cms
Nov 21, 2024
Oct 15, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in nc-cms through 2017-03-10. index.php?action=edit_html allows XSS via the name parameter, as demonstrated by a value beginning with home_content and containing a crafted SRC attribute of an IMG...Show more
An issue was discovered in nc-cms through 2017-03-10. index.php?action=edit_html allows XSS via the name parameter, as demonstrated by a value beginning with home_content and containing a crafted SRC attribute of an IMG element.Show less
1Control Webpanel
1Webpanel
Nov 21, 2024
Oct 15, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.480 has XSS via the admin/fileManager2.php fm_current_dir parameter, or the admin/index.php module, service_start, service_fullstatus, service_restart, service_stop, o...Show more
CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.480 has XSS via the admin/fileManager2.php fm_current_dir parameter, or the admin/index.php module, service_start, service_fullstatus, service_restart, service_stop, or file (within the file_editor) parameter.Show less
1Metinfo
1Metinfo
Nov 21, 2024
Oct 15, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
MetInfo 6.1.2 has XSS via the /admin/index.php bigclass parameter in an n=column&a=doadd action.
1Asus
1Rt Ac58u Firmware
Nov 21, 2024
Oct 14, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A cross site scripting (XSS) vulnerability on ASUS RT-AC58U 3.0.0.4.380_6516 devices allows remote attackers to inject arbitrary web script or HTML via Advanced_ASUSDDNS_Content.asp, Advanced_WSecurity_Content.asp, Advan...Show more
A cross site scripting (XSS) vulnerability on ASUS RT-AC58U 3.0.0.4.380_6516 devices allows remote attackers to inject arbitrary web script or HTML via Advanced_ASUSDDNS_Content.asp, Advanced_WSecurity_Content.asp, Advanced_Wireless_Content.asp, Logout.asp, Main_Login.asp, MobileQIS_Login.asp, QIS_wizard.htma, YandexDNS.asp, ajax_status.xml, apply.cgi, clients.asp, disk.asp, disk_utility.asp, or internet.asp.Show less
1Nconsulting
1Nc Cms
Nov 21, 2024
Oct 14, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
An issue was discovered in nc-cms through 2017-03-10. index.php?action=edit_html&name=home_content allows XSS via the HTML Source Editor. NOTE: the vendor disputes this because the form requires administrator privileges,...Show more
An issue was discovered in nc-cms through 2017-03-10. index.php?action=edit_html&name=home_content allows XSS via the HTML Source Editor. NOTE: the vendor disputes this because the form requires administrator privileges, and entering JavaScript is supported functionalityShow less
1Zeit
1Next.js
Nov 21, 2024
Oct 12, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Next.js 7.0.0 and 7.0.1 has XSS via the 404 or 500 /_error page.
1Paloaltonetworks
1Pan Os
Nov 21, 2024
Oct 12, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
GlobalProtect Portal Login page in Palo Alto Networks PAN-OS before 8.1.4 allows an unauthenticated attacker to inject arbitrary JavaScript or HTML.
1Wago
14750 352 Firmware
750 362 Firmware750 363 Firmware+11 more
Jun 13, 2025
Oct 12, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
WAGO 750-88X and WAGO 750-89X Ethernet Controller devices, versions 01.09.18(13) and before, have XSS in the SNMP configuration via the webserv/cplcfg/snmp.ssi SNMP_DESC or SNMP_LOC_SNMP_CONT field.
1Theforeman
1Foreman
Nov 21, 2024
Oct 12, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A flaw was found in foreman from versions 1.18. A stored cross-site scripting vulnerability exists due to an improperly escaped HTML code in the breadcrumbs bar. This allows a user with permissions to edit which attribut...Show more
A flaw was found in foreman from versions 1.18. A stored cross-site scripting vulnerability exists due to an improperly escaped HTML code in the breadcrumbs bar. This allows a user with permissions to edit which attribute is used in the breadcrumbs bar to store code that will be executed on the client side.Show less
1Cmsmadesimple
1Cms Made Simple
Nov 21, 2024
Oct 12, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
XSS exists in CMS Made Simple version 2.2.7 via the m1_extra parameter in an admin/moduleinterface.php "Content-->News-->Add Article" action.
1Cmsmadesimple
1Cms Made Simple
Nov 21, 2024
Oct 12, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
XSS exists in CMS Made Simple version 2.2.7 via the m1_news_url parameter in an admin/moduleinterface.php "Content-->News-->Add Article" action.
1Ibm
1Engineering Lifecycle Optimization Publishing
Mar 25, 2025
Oct 12, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM Rational Publishing Engine 6.0.5 and 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially...Show more
IBM Rational Publishing Engine 6.0.5 and 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 142432.Show less
1Ibm
1Engineering Lifecycle Optimization Publishing
Mar 25, 2025
Oct 12, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM Rational Publishing Engine 6.0.5 and 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially...Show more
IBM Rational Publishing Engine 6.0.5 and 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 142431.Show less
1Ibm
1Websphere Portal
Nov 21, 2024
Oct 12, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially lea...Show more
IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 145108.Show less