← Back
CWE-79

46,115 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (46,115)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ideacms
1Ideacms
Nov 21, 2024
Sep 3, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The issue was discovered in IdeaCMS through 2016-04-30. There is reflected XSS via the index.php?c=content&a=search kw parameter. NOTE: this product is discontinued.
1Pescms
1Pescms Team
Nov 21, 2024
Sep 3, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
PESCMS Team 2.2.1 has multiple reflected XSS via the keyword parameter: g=Team&m=User&a=index&keyword=, g=Team&m=User_group&a=index&keyword=, g=Team&m=Department&a=index&keyword=, and g=Team&m=Bulletin&a=index&keyword=.
1Mantisbt
1Source Integration
Nov 21, 2024
Sep 2, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in the Source Integration plugin before 1.5.9 and 2.x before 2.1.5 for MantisBT. A cross-site scripting (XSS) vulnerability in the Manage Repository and Changesets List pages allows execution of a...Show more
An issue was discovered in the Source Integration plugin before 1.5.9 and 2.x before 2.1.5 for MantisBT. A cross-site scripting (XSS) vulnerability in the Manage Repository and Changesets List pages allows execution of arbitrary code (if CSP settings permit it) via repo_manage_page.php or list.php.Show less
1Dotclear
1Dotclear
Nov 21, 2024
Sep 2, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A cross-site scripting (XSS) vulnerability in inc/core/class.dc.core.php in the media manager in Dotclear through 2.14.1 allows remote authenticated users to upload HTML content containing an XSS payload with the file ex...Show more
A cross-site scripting (XSS) vulnerability in inc/core/class.dc.core.php in the media manager in Dotclear through 2.14.1 allows remote authenticated users to upload HTML content containing an XSS payload with the file extension .ahtml.Show less
1Wuzhi Cms Project
1Wuzhi Cms
Nov 21, 2024
Sep 2, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
WUZHI CMS 4.1.0 has XSS via the index.php?m=core&f=set&v=basic form[statcode] parameter.
1Wuzhi Cms Project
1Wuzhi Cms
Nov 21, 2024
Sep 2, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
WUZHI CMS 4.1.0 has XSS via the index.php?m=link&f=index&v=add form[remark] parameter.
1Seacms
1Seacms
Nov 21, 2024
Sep 2, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
SeaCMS V6.61 has XSS via the admin_video.php v_content parameter, related to the site name.
1Gleezcms
1Gleez Cms
Nov 21, 2024
Sep 2, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in Gleez CMS v1.2.0. There is XSS via media/imagecache/resize.
1Chemcms Project
1Chemcms
Nov 21, 2024
Sep 2, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
ChemCMS 1.0.6 has XSS via the "setting -> website information" field.
1Showdoc
1Showdoc
Nov 21, 2024
Sep 2, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
ShowDoc v1.8.0 has XSS via a new page.
1Ipandao
1Editor.md
Nov 21, 2024
Sep 2, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Pandao Editor.md 1.5.0 allows XSS via crafted attributes of an invalid IMG element.
1Intelliants
1Subrion
Nov 21, 2024
Sep 1, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
There is Stored XSS in Subrion 4.2.1 via the admin panel URL configuration.
1Get Simple
1Getsimple Cms
Nov 21, 2024
Sep 1, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
There is XSS in GetSimple CMS 3.4.0.9 via the admin/edit.php title field.
1Icewarp
1Mail Server
Nov 21, 2024
Sep 1, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In IceWarp Server 12.0.3.1 and before, there is XSS in the /webmail/ username field.
1Portainer
1Portainer
Nov 21, 2024
Sep 1, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A stored Cross-site scripting (XSS) vulnerability in Portainer through 1.19.1 allows remote authenticated users to inject arbitrary JavaScript and/or HTML via the Team Name field.
1Bludit
1Bludit
Nov 21, 2024
Sep 1, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Bludit 2.3.4 allows XSS via a user name.
11234n
1Minicms
Nov 21, 2024
Aug 31, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in MiniCMS 1.10. There is an mc-admin/post.php?tag= XSS vulnerability for a state=delete, state=draft, or state=publish request.
1Cpanel
1Cpanel
Nov 21, 2024
Aug 30, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
cPanel through 74 allows XSS via a crafted filename in the logs subdirectory of a user account, because the filename is mishandled during frontend/THEME/raw/index.html rendering.
1Morningstarsecurity
1Whatweb
Nov 21, 2024
Aug 30, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
MorningStar WhatWeb 0.4.9 has XSS via JSON report files.
11234n
1Minicms
Nov 21, 2024
Aug 30, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
MiniCMS V1.10 has XSS via the mc-admin/post-edit.php tags parameter.