← Back
CWE-79

46,117 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (46,117)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Microsoft
1Sharepoint Enterprise Server
Jun 17, 2026
Sep 13, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint Elevation of Privileg...Show more
An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint Elevation of Privilege Vulnerability." This affects Microsoft SharePoint. This CVE ID is unique from CVE-2018-8431.Show less
1Microsoft
3Sharepoint Enterprise Server 2013
Sharepoint Enterprise Server 2016Sharepoint Server 2010
Jun 17, 2026
Sep 13, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft Office SharePoint XSS Vulnera...Show more
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft Office SharePoint XSS Vulnerability." This affects Microsoft SharePoint Server, Microsoft SharePoint.Show less
1Dotcms
1Dotcms
Nov 21, 2024
Sep 12, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
dotCMS V5.0.1 has XSS in the /html/portlet/ext/contentlet/image_tools/index.jsp fieldName and inode parameters.
1Monstra
1Monstra
Nov 21, 2024
Sep 12, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Monstra CMS V3.0.4 has XSS when ones tries to register an account with a crafted password parameter to users/registration, a different vulnerability than CVE-2018-11473.
1Pluck Cms
1Pluck
Nov 21, 2024
Sep 12, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Pluck 4.7.7 allows XSS via an SVG file that contains Javascript in a SCRIPT element, and is uploaded via pages->manage under admin.php?action=files.
1Feindura
1Feindura
Nov 21, 2024
Sep 12, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
feindura 2.0.7 allows XSS via the tags field of a new page created at index.php?category=0&page=new.
1Razorcms
1Razorcms
Nov 21, 2024
Sep 12, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
razorCMS 3.4.7 allows Stored XSS via the keywords of the homepage within the settings component.
1Razorcms
1Razorcms
Nov 21, 2024
Sep 12, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
razorCMS 3.4.7 allows HTML injection via the description of the homepage within the settings component.
1Dlink
1Dir 600m Firmware
Nov 21, 2024
Sep 12, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
D-Link DIR-600M devices allow XSS via the Hostname and Username fields in the Dynamic DNS Configuration page.
1Redhat
1Openshift Container Platform
Nov 21, 2024
Sep 11, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A cross site scripting flaw exists in the tetonic-console component of Openshift Container Platform 3.11. An attacker with the ability to create pods can use this flaw to perform actions on the K8s API as the victim.
1Sap
1Netweaver
Nov 21, 2024
Sep 11, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
SAP WebDynpro Java, versions 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user-controlled inputs, resulting in a stored Cross-Site Scripting (XSS) vulnerability.
1Sap
1Netweaver Application Server Java
Nov 21, 2024
Sep 11, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The logon application of SAP NetWeaver AS Java 7.10 to 7.11, 7.20, 7.30, 7.31, 7.40, 7.50 does not sufficiently encode user-controlled inputs, resulting in a cross-site scripting (XSS) vulnerability.
1B3log
1Solo
Nov 21, 2024
Sep 10, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
In b3log Solo 2.9.3, XSS in the Input page under the Publish Articles menu, with an ID of linkAddress stored in the link JSON field, allows remote attackers to inject arbitrary Web scripts or HTML via a crafted site name...Show more
In b3log Solo 2.9.3, XSS in the Input page under the Publish Articles menu, with an ID of linkAddress stored in the link JSON field, allows remote attackers to inject arbitrary Web scripts or HTML via a crafted site name provided by an administrator.Show less
1Complete Responsive Cms Blog Project
1Complete Responsive Cms Blog
Nov 21, 2024
Sep 10, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Complete Responsive CMS Blog through 2018-05-20 has XSS via a comment.
1Blogcms Project
1Blogcms
Nov 21, 2024
Sep 10, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
BlogCMS through 2016-10-25 has XSS via a comment.
1Creatiwity
1Witycms
Nov 21, 2024
Sep 10, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
wityCMS 0.6.2 has XSS via the "Site Name" field found in the "Contact" "Configuration" page.
1Victor Cms Project
1Victor Cms
Nov 21, 2024
Sep 10, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
An issue was discovered in Victor CMS through 2018-05-10. There is XSS via the site name in the "Categories" menu.
1Easycms
1Easycms
Nov 21, 2024
Sep 10, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
EasyCMS 1.5 allows XSS via the index.php?s=/admin/fields/update/navTabId/listfields/callbackType/closeCurrent content field.
1Hoosk
1Hoosk
Nov 21, 2024
Sep 10, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Hoosk v1.7.0 allows XSS via the Navigation Title of a new page entered at admin/pages/new.
1Easycms
1Easycms
Nov 21, 2024
Sep 9, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The removeXSS function in App/Common/common.php (called from App/Modules/Index/Action/SearchAction.class.php) in EasyCMS v1.4 allows XSS via an onhashchange event.