CWE-79
46,115 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (46,115)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The issue was discovered in IdeaCMS through 2016-04-30. There is reflected XSS via the index.php?c=content&a=search kw parameter. NOTE: this product is discontinued. |
PESCMS Team 2.2.1 has multiple reflected XSS via the keyword parameter: g=Team&m=User&a=index&keyword=, g=Team&m=User_group&a=index&keyword=, g=Team&m=Department&a=index&keyword=, and g=Team&m=Bulletin&a=index&keyword=. |
1Mantisbt 1Source Integration Nov 21, 2024 Sep 2, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in the Source Integration plugin before 1.5.9 and 2.x before 2.1.5 for MantisBT. A cross-site scripting (XSS) vulnerability in the Manage Repository and Changesets List pages allows execution of a...Show more |
A cross-site scripting (XSS) vulnerability in inc/core/class.dc.core.php in the media manager in Dotclear through 2.14.1 allows remote authenticated users to upload HTML content containing an XSS payload with the file ex...Show more |
1Wuzhi Cms Project 1Wuzhi Cms Nov 21, 2024 Sep 2, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 WUZHI CMS 4.1.0 has XSS via the index.php?m=core&f=set&v=basic form[statcode] parameter. |
1Wuzhi Cms Project 1Wuzhi Cms Nov 21, 2024 Sep 2, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 WUZHI CMS 4.1.0 has XSS via the index.php?m=link&f=index&v=add form[remark] parameter. |
SeaCMS V6.61 has XSS via the admin_video.php v_content parameter, related to the site name. |
An issue was discovered in Gleez CMS v1.2.0. There is XSS via media/imagecache/resize. |
ChemCMS 1.0.6 has XSS via the "setting -> website information" field. |
ShowDoc v1.8.0 has XSS via a new page. |
Pandao Editor.md 1.5.0 allows XSS via crafted attributes of an invalid IMG element. |
There is Stored XSS in Subrion 4.2.1 via the admin panel URL configuration. |
There is XSS in GetSimple CMS 3.4.0.9 via the admin/edit.php title field. |
In IceWarp Server 12.0.3.1 and before, there is XSS in the /webmail/ username field. |
A stored Cross-site scripting (XSS) vulnerability in Portainer through 1.19.1 allows remote authenticated users to inject arbitrary JavaScript and/or HTML via the Team Name field. |
Bludit 2.3.4 allows XSS via a user name. |
An issue was discovered in MiniCMS 1.10. There is an mc-admin/post.php?tag= XSS vulnerability for a state=delete, state=draft, or state=publish request. |
cPanel through 74 allows XSS via a crafted filename in the logs subdirectory of a user account, because the filename is mishandled during frontend/THEME/raw/index.html rendering. |
1Morningstarsecurity 1Whatweb Nov 21, 2024 Aug 30, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 MorningStar WhatWeb 0.4.9 has XSS via JSON report files. |
MiniCMS V1.10 has XSS via the mc-admin/post-edit.php tags parameter. |