← Back
CWE-79

46,115 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (46,115)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Dojotoolkit
1Dojo
Nov 21, 2024
Sep 6, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Dojo Dojo Objective Harness (DOH) version prior to version 1.14 contains a Cross Site Scripting (XSS) vulnerability in unit.html and testsDOH/_base/loader/i18n-exhaustive/i18n-test/unit.html and testsDOH/_base/i18nExhaus...Show more
Dojo Dojo Objective Harness (DOH) version prior to version 1.14 contains a Cross Site Scripting (XSS) vulnerability in unit.html and testsDOH/_base/loader/i18n-exhaustive/i18n-test/unit.html and testsDOH/_base/i18nExhaustive.js in the DOH that can result in Victim attacked through their browser - deliver malware, steal HTTP cookies, bypass CORS trust. This attack appear to be exploitable via Victims are typically lured to a web site under the attacker's control; the XSS vulnerability on the target domain is silently exploited without the victim's knowledge. This vulnerability appears to have been fixed in 1.14.Show less
1Exceljs Project
1Exceljs
Nov 21, 2024
Sep 6, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An unescaped payload in exceljs <v1.6 allows a possible XSS via cell value when worksheet is displayed in browser.
1Lavalite
1Lavalite
Nov 21, 2024
Sep 5, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
LavaLite 5.5 has XSS via a /edit URI, as demonstrated by client/job/job/Zy8PWBekrJ/edit.
1E107
1E107
Nov 21, 2024
Sep 5, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
e107 2.1.8 has XSS via the e107_admin/users.php?mode=main&action=list user_loginname parameter.
1Btiteam
1Xbtit
Nov 21, 2024
Sep 5, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in BTITeam XBTIT 2.5.4. news.php allows XSS via the id parameter.
1Opsview
1Opsview
Nov 21, 2024
Sep 5, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The diagnosticsb2ksy parameter of the /rest endpoint in Opsview Monitor before 5.3.1 and 5.4.x before 5.4.2 is vulnerable to Cross-Site Scripting.
1Opsview
1Opsview
Nov 21, 2024
Sep 5, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The data parameter of the /settings/api/router endpoint in Opsview Monitor before 5.3.1 and 5.4.x before 5.4.2 is vulnerable to Cross-Site Scripting.
1Jorani Project
1Jorani
Nov 21, 2024
Sep 5, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Persistent cross-site scripting (XSS) issues in Jorani 0.6.5 allow remote attackers to inject arbitrary web script or HTML via the language parameter to session/language.
1Btiteam
1Xbtit
Nov 21, 2024
Sep 5, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in BTITeam XBTIT 2.5.4. The "keywords" parameter in the search function available at /index.php?page=forums&action=search is vulnerable to reflected cross-site scripting.
1Btiteam
1Xbtit
Nov 21, 2024
Sep 5, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in BTITeam XBTIT 2.5.4. The "act" parameter in the sign-up page available at /index.php?page=signup is vulnerable to reflected cross-site scripting.
1Btiteam
1Xbtit
Nov 21, 2024
Sep 5, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The newsfeed (aka /index.php?page=viewnews) in BTITeam XBTIT 2.5.4 has stored XSS via the title of a news item. This is also exploitable via CSRF.
1Btiteam
1Xbtit
Nov 21, 2024
Sep 5, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
An issue was discovered in BTITeam XBTIT. By using String.replace and eval, it is possible to bypass the includes/crk_protection.php anti-XSS mechanism that looks for a number of dangerous fingerprints.
1Flask Admin Project
1Flask Admin
Nov 21, 2024
Sep 5, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
helpers.py in Flask-Admin 1.5.2 has Reflected XSS via a crafted URL.
1Sixapart
1Movable Type
Nov 21, 2024
Sep 4, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting vulnerability in Movable Type versions prior to Ver. 6.3.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
1Craftedweb Project
1Craftedweb
Nov 21, 2024
Sep 4, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
CraftedWeb through 2013-09-24 has reflected XSS via the p parameter.
1Mayan Edms
1Mayan Edms
Nov 21, 2024
Sep 3, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in Mayan EDMS before 3.0.3. The Tags app has XSS because tag label values are mishandled.
1Mayan Edms
1Mayan Edms
Nov 21, 2024
Sep 3, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in Mayan EDMS before 3.0.2. The Cabinets app has XSS via a crafted cabinet label.
1Mayan Edms
1Mayan Edms
Nov 21, 2024
Sep 3, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in Mayan EDMS before 3.0.2. The Appearance app sets window.location directly, leading to XSS.
1Digimute
1Ogma Cms
Nov 21, 2024
Sep 3, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Ogma CMS 0.4 Beta has XSS via the "Footer Text footer" field on the "Theme/Theme Options" screen.
1Frog Cms Project
1Frog Cms
Nov 21, 2024
Sep 3, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Frog CMS 0.9.5 has stored XSS via /admin/?/plugin/comment/settings.