← Back
CWE-79

46,117 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (46,117)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Xwiki
1Xwiki
Nov 21, 2024
Sep 28, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The Image Import function in XWiki through 10.7 has XSS.
1Progress
1Kendo Ui
Nov 21, 2024
Sep 28, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in Progress Kendo UI Editor v2018.1.221 allows remote attackers to inject arbitrary JavaScript into the DOM of the WYSIWYG editor because of the editorNS.Serializer toEditableHtml...Show more
Cross-site scripting (XSS) vulnerability in Progress Kendo UI Editor v2018.1.221 allows remote attackers to inject arbitrary JavaScript into the DOM of the WYSIWYG editor because of the editorNS.Serializer toEditableHtml function in kendo.all.min.js. If the victim accesses the editor, the payload gets executed. Furthermore, if the payload is reflected at any other resource that does rely on the sanitisation of the editor itself, the JavaScript payload will be executed in the context of the application. This allows attackers (in the worst case) to take over user sessions.Show less
1Ibm
1Websphere Portal
Nov 21, 2024
Sep 27, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM WebSphere Portal 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading...Show more
IBM WebSphere Portal 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 150096.Show less
1Ibm
1Websphere Portal
Nov 21, 2024
Sep 27, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially lea...Show more
IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 147164.Show less
1Ibm
1Websphere Portal
Nov 21, 2024
Sep 27, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially lea...Show more
IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-force ID: 144886.Show less
1Ricoh
1Mp C6003 Firmware
Nov 21, 2024
Sep 26, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
On the RICOH MP C6003 printer, HTML Injection and Stored XSS vulnerabilities have been discovered in the area of adding addresses via the entryNameIn parameter to /web/entry/en/address/adrsSetUserWizard.cgi.
1Ricoh
1Mp C2003sp Firmware
Nov 21, 2024
Sep 26, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
On the RICOH MP C2003 printer, HTML Injection and Stored XSS vulnerabilities have been discovered in the area of adding addresses via the entryNameIn parameter to /web/entry/en/address/adrsSetUserWizard.cgi.
1Ricoh
1Mp 305+ Firmware
Nov 21, 2024
Sep 26, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
On the RICOH Aficio MP 305+ printer, HTML Injection and Stored XSS vulnerabilities have been discovered in the area of adding addresses via the entryNameIn parameter to /web/entry/en/address/adrsSetUserWizard.cgi.
1Ricoh
1Mp C307 Firmware
Nov 21, 2024
Sep 26, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
On the RICOH MP C307 printer, HTML Injection and Stored XSS vulnerabilities have been discovered in the area of adding addresses via the entryNameIn parameter to /web/entry/en/address/adrsSetUserWizard.cgi.
1Ricoh
1Aficio Mp 301spf Firmware
Nov 21, 2024
Sep 26, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
On the RICOH Aficio MP 301 printer, HTML Injection and Stored XSS vulnerabilities have been discovered in the area of adding addresses via the entryNameIn parameter to /web/entry/en/address/adrsSetUserWizard.cgi.
1Ricoh
1Mp C6503 Firmware
Nov 21, 2024
Sep 26, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
On the RICOH MP C6503 Plus printer, HTML Injection and Stored XSS vulnerabilities have been discovered in the area of adding addresses via the entryNameIn parameter to /web/entry/en/address/adrsSetUserWizard.cgi.
1Ricoh
1Mp C1803 Jpn Firmware
Nov 21, 2024
Sep 26, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
On the RICOH MP C1803 JPN printer, HTML Injection and Stored XSS vulnerabilities have been discovered in the area of adding addresses via the entryNameIn parameter to /web/entry/en/address/adrsSetUserWizard.cgi.
1Ricoh
1Mp C406zspf Firmware
Nov 21, 2024
Sep 26, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
On the RICOH MP C406Z printer, HTML Injection and Stored XSS vulnerabilities have been discovered in the area of adding addresses via the entryNameIn parameter to /web/entry/en/address/adrsSetUserWizard.cgi.
1Modx
1Modx Revolution
Nov 21, 2024
Sep 26, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
MODX Revolution v2.6.5-pl allows stored XSS via a Create New Media Source action.
1Philips
1E Alert Firmware
Jun 17, 2026
Sep 26, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Philips e-Alert Unit (non-medical device), Version R2.1 and prior. The software does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is then...Show more
Philips e-Alert Unit (non-medical device), Version R2.1 and prior. The software does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is then served to other users.Show less
1Salesagility
1Suitecrm
Nov 21, 2024
Sep 26, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An XSS issue was discovered in SalesAgility SuiteCRM 7.x before 7.8.21 and 7.10.x before 7.10.8, related to phishing an error message.
1Zte
2Mf65 Firmware
Mf65m1 Firmware
Jun 17, 2026
Sep 26, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
All versions up to V1.0.0B05 of ZTE MF65 and all versions up to V1.0.0B02 of ZTE MF65M1 are impacted by cross-site scripting vulnerability. Due to improper neutralization of input during web page generation, an attacker...Show more
All versions up to V1.0.0B05 of ZTE MF65 and all versions up to V1.0.0B02 of ZTE MF65M1 are impacted by cross-site scripting vulnerability. Due to improper neutralization of input during web page generation, an attacker could exploit this vulnerability to conduct reflected XSS or HTML injection attacks on the devices.Show less
1Ibm
1Rational Doors Next Generation
Nov 21, 2024
Sep 26, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM Rational DOORS Next Generation 5.0 through 5.0.2 and 6.0 through 6.0.6 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intend...Show more
IBM Rational DOORS Next Generation 5.0 through 5.0.2 and 6.0 through 6.0.6 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 143931.Show less
1Ibm
1Rational Engineering Lifecycle Manager
Nov 21, 2024
Sep 25, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM Rational Engineering Lifecycle Manager 5.0 through 5.02 and 6.0 through 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the...Show more
IBM Rational Engineering Lifecycle Manager 5.0 through 5.02 and 6.0 through 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 144885.Show less
1Ibm
1Rational Engineering Lifecycle Manager
Nov 21, 2024
Sep 25, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM Rational Engineering Lifecycle Manager 5.0 through 5.02 and 6.0 through 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the...Show more
IBM Rational Engineering Lifecycle Manager 5.0 through 5.02 and 6.0 through 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 142958.Show less