← Back
CWE-79

46,117 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (46,117)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Otcms
1Otcms
Nov 21, 2024
Sep 16, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in OTCMS 3.61. XSS exists in admin/share_switch.php via these parameters: fieldName fieldName2 tabName.
1Otcms
1Otcms
Nov 21, 2024
Sep 16, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in OTCMS 3.61. XSS exists in admin/users.php via these parameters: dataTypeCN dataMode dataModeStr.
1Seacms
1Seacms
Nov 21, 2024
Sep 16, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in SeaCMS 6.64. XSS exists in admin_video.php via the action, area, type, yuyan, jqtype, v_isunion, v_recycled, v_ismoney, or v_ispsd parameter.
3Debian
NetappPhp
3Debian Linux
PhpStorage Automation Store
Nov 21, 2024
Sep 16, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Apache2 component in PHP before 5.6.38, 7.0.x before 7.0.32, 7.1.x before 7.1.22, and 7.2.x before 7.2.10 allows XSS via the body of a "Transfer-Encoding: chunked" request, because the bucket brigade is mishandled in...Show more
The Apache2 component in PHP before 5.6.38, 7.0.x before 7.0.32, 7.1.x before 7.1.22, and 7.2.x before 7.2.10 allows XSS via the body of a "Transfer-Encoding: chunked" request, because the bucket brigade is mishandled in the php_handler function in sapi/apache2handler/sapi_apache2.c.Show less
1Yiqicms Project
1Yiqicms
Nov 21, 2024
Sep 16, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in yiqicms through 2016-11-20. There is stored XSS in comment.php because a length limit can be bypassed.
1Bullguard
1Safe Browsing
Nov 21, 2024
Sep 15, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
BullGuard Safe Browsing before 18.1.355.9 allows XSS on Google, Bing, and Yahoo! pages via domains indexed in search results.
1Synametrics
1Synaman
Nov 21, 2024
Sep 14, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Multiple cross-site scripting (XSS) vulnerabilities in Synametrics SynaMan 4.0 build 1488 via the (1) Main heading or (2) Sub heading fields in the Partial Branding configuration page.
1Knet
1Cisco Configuration Manager
Nov 21, 2024
Sep 14, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
K-Net Cisco Configuration Manager through 2014-11-19 has XSS via devices.php.
1Cqu Lankers Project
1Cqu Lankers
Nov 21, 2024
Sep 14, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
CQU-LANKERS through 2017-11-02 has XSS via the public/api.php callback parameter in an uploadpic action.
1Translate Man Project
1Translate Man
Nov 21, 2024
Sep 14, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
translate man before 2018-08-21 has XSS via containers/outputBox/outputBox.vue and store/index.js.
1Yzmcms
1Yzmcms
Nov 21, 2024
Sep 14, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
In YzmCMS 5.1, stored XSS exists via the admin/system_manage/user_config_add.html title parameter.
11234n
1Minicms
Nov 21, 2024
Sep 14, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
MiniCMS 1.10, when Internet Explorer is used, allows XSS via a crafted URI because $_SERVER['REQUEST_URI'] is mishandled.
1Ucms Project
1Ucms
Nov 21, 2024
Sep 14, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
UCMS 1.4.6 has XSS via the install/index.php mysql_dbname parameter.
1Gogs
1Gogs
Nov 21, 2024
Sep 14, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In Gogs 0.11.53, an attacker can use a crafted .eml file to trigger MIME type sniffing, which leads to XSS, as demonstrated by Internet Explorer, because an "X-Content-Type-Options: nosniff" header is not sent.
1Monstra
1Monstra
Nov 21, 2024
Sep 13, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
admin/index.php in Monstra CMS 3.0.4 allows XSS via the page_meta_title parameter in an edit_page&name=error404 action, a different vulnerability than CVE-2018-10121.
1Monstra
1Monstra
Nov 21, 2024
Sep 13, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
admin/index.php in Monstra CMS 3.0.4 allows XSS via the page_meta_title parameter in an edit_page action for a page with no special role.
1Monstra
1Monstra
Nov 21, 2024
Sep 13, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
admin/index.php in Monstra CMS 3.0.4 allows XSS via the page_meta_title parameter in an add_page action.
1Asus
1Gt Ac5300 Firmware
Nov 21, 2024
Sep 13, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability on ASUS GT-AC5300 devices with firmware through 3.0.0.4.384_32738 allows remote attackers to inject arbitrary web script or HTML via the appGet.cgi hook parameter.
1Microsoft
1Internet Explorer
Jun 17, 2026
Sep 13, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A security feature bypass vulnerability exists in Internet Explorer due to how scripts are handled that allows a universal cross-site scripting (UXSS) condition, aka "Internet Explorer Security Feature Bypass Vulnerabili...Show more
A security feature bypass vulnerability exists in Internet Explorer due to how scripts are handled that allows a universal cross-site scripting (UXSS) condition, aka "Internet Explorer Security Feature Bypass Vulnerability." This affects Internet Explorer 11.Show less
1Microsoft
2Sharepoint Enterprise Server
Sharepoint Server
Jun 17, 2026
Sep 13, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint Elevation of Privileg...Show more
An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint Elevation of Privilege Vulnerability." This affects Microsoft SharePoint Server, Microsoft SharePoint. This CVE ID is unique from CVE-2018-8428.Show less