← Back
CWE-79

46,117 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (46,117)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Dedecms
1Dedecms
Nov 21, 2024
Sep 21, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
DedeCMS 5.7 SP2 allows XSS via an onhashchange attribute in the msg parameter to /plus/feedback_ajax.php.
1Espocrm
1Espocrm
Nov 21, 2024
Sep 21, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Stored XSS exists in views/fields/wysiwyg.js in EspoCRM 5.3.6 via a /#Email/view saved draft message.
1Espocrm
1Espocrm
Nov 21, 2024
Sep 21, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Reflected XSS exists in client/res/templates/global-search/name-field.tpl in EspoCRM 5.3.6 via /#Account in the search panel.
1Cuppacms
1Cuppacms
Nov 21, 2024
Sep 21, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Stored XSS exists in CuppaCMS through 2018-09-03 via an administrator/#/component/table_manager/view/cu_menus section name.
1Hp
1Arcsight Management Center
Jun 17, 2026
Sep 20, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A potential Reflected Cross-Site Scripting (XSS) Security vulnerability has been identified in ArcSight Management Center (ArcMC) in all versions prior to 2.81. This vulnerability could be exploited to allow for Reflecte...Show more
A potential Reflected Cross-Site Scripting (XSS) Security vulnerability has been identified in ArcSight Management Center (ArcMC) in all versions prior to 2.81. This vulnerability could be exploited to allow for Reflected Cross-site Scripting (XSS).Show less
2Elastic
Redhat
2Kibana
Openshift Container Platform
Nov 21, 2024
Sep 19, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Kibana versions 5.3.0 to 6.4.1 had a cross-site scripting (XSS) vulnerability via the source field formatter that could allow an attacker to obtain sensitive information from or perform destructive actions on behalf of o...Show more
Kibana versions 5.3.0 to 6.4.1 had a cross-site scripting (XSS) vulnerability via the source field formatter that could allow an attacker to obtain sensitive information from or perform destructive actions on behalf of other Kibana users.Show less
1Elastic
3Elasticsearch X Pack
Kibana X PackLogstash X Pack
Nov 21, 2024
Sep 19, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
X-Pack Machine Learning versions before 6.2.4 and 5.6.9 had a cross-site scripting (XSS) vulnerability. If an attacker is able to inject data into an index that has a ML job running against it, then when another user vie...Show more
X-Pack Machine Learning versions before 6.2.4 and 5.6.9 had a cross-site scripting (XSS) vulnerability. If an attacker is able to inject data into an index that has a ML job running against it, then when another user views the results of the ML job it could allow the attacker to obtain sensitive information from or perform destructive actions on behalf of that other ML user.Show less
1Elastic
3Elasticsearch X Pack
Kibana X PackLogstash X Pack
Nov 21, 2024
Sep 19, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
X-Pack Machine Learning versions before 6.2.4 and 5.6.9 had a cross-site scripting (XSS) vulnerability. Users with manage_ml permissions could create jobs containing malicious data as part of their configuration that cou...Show more
X-Pack Machine Learning versions before 6.2.4 and 5.6.9 had a cross-site scripting (XSS) vulnerability. Users with manage_ml permissions could create jobs containing malicious data as part of their configuration that could allow the attacker to obtain sensitive information from or perform destructive actions on behalf of other ML users viewing the results of the jobs.Show less
1Opmantek
1Open Audit
Nov 21, 2024
Sep 19, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-site scripting (XSS) vulnerability in the Orgs Page in Open-AudIT Professional edition in 2.2.7 allows remote attackers to inject arbitrary web script via the Orgs name field.
1Accusoft
1Prizmdoc
Nov 21, 2024
Sep 18, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Accusoft PrizmDoc version 13.3 and earlier contains a Stored Cross-Site Scripting issue through a crafted PDF file.
1Open Xchange
1Open Xchange Appsuite
Nov 21, 2024
Sep 18, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in the Open-Xchange webmail before 7.6.3-rev28 allows remote attackers to inject arbitrary web script or HTML via the event attribute in a time tag.
1Oracle
1Webcenter Interaction
Nov 21, 2024
Sep 18, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The login function of Oracle WebCenter Interaction Portal 10.3.3 is vulnerable to reflected cross-site scripting (XSS). The content of the in_hi_redirect parameter, when prefixed with the https:// scheme, is unsafely ref...Show more
The login function of Oracle WebCenter Interaction Portal 10.3.3 is vulnerable to reflected cross-site scripting (XSS). The content of the in_hi_redirect parameter, when prefixed with the https:// scheme, is unsafely reflected in a HTML META tag in the HTTP response. NOTE: this CVE is assigned by MITRE and isn't validated by Oracle because Oracle WebCenter Interaction Portal is out of support.Show less
1Oracle
1Webcenter Interaction
Nov 21, 2024
Sep 18, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The AjaxView::DisplayResponse() function of the portalpages.dll assembly in Oracle WebCenter Interaction Portal 10.3.3 is vulnerable to reflected cross-site scripting (XSS). User input from the name parameter is unsafely...Show more
The AjaxView::DisplayResponse() function of the portalpages.dll assembly in Oracle WebCenter Interaction Portal 10.3.3 is vulnerable to reflected cross-site scripting (XSS). User input from the name parameter is unsafely reflected in the server response. NOTE: this CVE is assigned by MITRE and isn't validated by Oracle because Oracle WebCenter Interaction Portal is out of support.Show less
1Moodle
1Moodle
Nov 21, 2024
Sep 17, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
moodle before versions 3.5.2, 3.4.5, 3.3.8 is vulnerable to a boost theme - blog search GET parameter insufficiently filtered. The breadcrumb navigation provided by Boost theme when displaying search results of a blog we...Show more
moodle before versions 3.5.2, 3.4.5, 3.3.8 is vulnerable to a boost theme - blog search GET parameter insufficiently filtered. The breadcrumb navigation provided by Boost theme when displaying search results of a blog were insufficiently filtered, which could result in reflected XSS if a user followed a malicious link containing JavaScript in the search parameter.Show less
1Vms Studio
1Quizlord
Nov 21, 2024
Sep 17, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The Quizlord plugin through 2.0 for WordPress is prone to Stored XSS via the title parameter in a ql_insert action to wp-admin/admin.php.
1Nickelpro
1Jibu Pro
Nov 21, 2024
Sep 17, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The Jibu Pro plugin through 1.7 for WordPress is prone to Stored XSS via the wp-content/plugins/jibu-pro/quiz_action.php name (aka Quiz Name) field.
1Phpmywind
1Phpmywind
Nov 21, 2024
Sep 17, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
PHPMyWind 5.5 has XSS in member.php via an HTTP Referer header,
1Mybb
1Mybb
Nov 21, 2024
Sep 17, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A Persistent XSS issue was discovered in the Visual Editor in MyBB before 1.8.19 via a Video MyCode.
1Easycms
1Easycms
Nov 21, 2024
Sep 17, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
App/Modules/Admin/Tpl/default/Public/dwz/uploadify/scripts/uploadify.swf in EasyCMS 1.5 has XSS via the uploadifyID or movieName parameter, a related issue to CVE-2018-9173.
1I4a
1Donlinkage
Nov 21, 2024
Sep 16, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
An issue was discovered in DonLinkage 6.6.8. The modules /pages/bazy/bazy_adresow.php and /pages/proxy/add.php are vulnerable to stored XSS that can be triggered by closing <textarea> followed by <script></script> tags.