CWE-79
46,117 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (46,117)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Microsoft 1Sharepoint Enterprise Server Jun 17, 2026 Sep 13, 2018 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint Elevation of Privileg...Show more |
1Microsoft 3Sharepoint Enterprise Server 2013 Sharepoint Enterprise Server 2016Sharepoint Server 2010Jun 17, 2026 Sep 13, 2018 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft Office SharePoint XSS Vulnera...Show more |
dotCMS V5.0.1 has XSS in the /html/portlet/ext/contentlet/image_tools/index.jsp fieldName and inode parameters. |
Monstra CMS V3.0.4 has XSS when ones tries to register an account with a crafted password parameter to users/registration, a different vulnerability than CVE-2018-11473. |
Pluck 4.7.7 allows XSS via an SVG file that contains Javascript in a SCRIPT element, and is uploaded via pages->manage under admin.php?action=files. |
feindura 2.0.7 allows XSS via the tags field of a new page created at index.php?category=0&page=new. |
razorCMS 3.4.7 allows Stored XSS via the keywords of the homepage within the settings component. |
razorCMS 3.4.7 allows HTML injection via the description of the homepage within the settings component. |
D-Link DIR-600M devices allow XSS via the Hostname and Username fields in the Dynamic DNS Configuration page. |
1Redhat 1Openshift Container Platform Nov 21, 2024 Sep 11, 2018 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 A cross site scripting flaw exists in the tetonic-console component of Openshift Container Platform 3.11. An attacker with the ability to create pods can use this flaw to perform actions on the K8s API as the victim. |
SAP WebDynpro Java, versions 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user-controlled inputs, resulting in a stored Cross-Site Scripting (XSS) vulnerability. |
1Sap 1Netweaver Application Server Java Nov 21, 2024 Sep 11, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The logon application of SAP NetWeaver AS Java 7.10 to 7.11, 7.20, 7.30, 7.31, 7.40, 7.50 does not sufficiently encode user-controlled inputs, resulting in a cross-site scripting (XSS) vulnerability. |
In b3log Solo 2.9.3, XSS in the Input page under the Publish Articles menu, with an ID of linkAddress stored in the link JSON field, allows remote attackers to inject arbitrary Web scripts or HTML via a crafted site name...Show more |
1Complete Responsive Cms Blog Project 1Complete Responsive Cms Blog Nov 21, 2024 Sep 10, 2018 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 Complete Responsive CMS Blog through 2018-05-20 has XSS via a comment. |
BlogCMS through 2016-10-25 has XSS via a comment. |
wityCMS 0.6.2 has XSS via the "Site Name" field found in the "Contact" "Configuration" page. |
1Victor Cms Project 1Victor Cms Nov 21, 2024 Sep 10, 2018 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 An issue was discovered in Victor CMS through 2018-05-10. There is XSS via the site name in the "Categories" menu. |
EasyCMS 1.5 allows XSS via the index.php?s=/admin/fields/update/navTabId/listfields/callbackType/closeCurrent content field. |
Hoosk v1.7.0 allows XSS via the Navigation Title of a new page entered at admin/pages/new. |
The removeXSS function in App/Common/common.php (called from App/Modules/Index/Action/SearchAction.class.php) in EasyCMS v1.4 allows XSS via an onhashchange event. |