← Back
CWE-79

46,105 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (46,105)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Infoblox
1Netmri
Jun 17, 2026
Aug 28, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Infoblox NetMRI 7.1.1 has Reflected Cross-Site Scripting via the /api/docs/index.php query parameter.
1Ricoh
1Mp C4504ex Firmware
Nov 21, 2024
Aug 28, 2018
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
RICOH MP C4504ex devices allow HTML Injection via the /web/entry/en/address/adrsSetUserWizard.cgi entryNameIn parameter.
1Zohocorp
1Manageengine Admanager Plus
Nov 21, 2024
Aug 28, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Zoho ManageEngine ADManager Plus 6.5.7 has XSS on the "Workflow Delegation" "Requester Roles" screen.
1Manageengine
1Admanager Plus
Nov 21, 2024
Aug 28, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Zoho ManageEngine ADManager Plus 6.5.7 allows HTML Injection on the "AD Delegation" "Help Desk Technicians" screen.
1Mybb
1Mybb
Nov 21, 2024
Aug 28, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in inc/class_feedgeneration.php in MyBB 1.8.17. On the forum RSS Syndication page, one can generate a URL such as http://localhost/syndication.php?fid=&type=atom1.0&limit=15. The thread titles (wi...Show more
An issue was discovered in inc/class_feedgeneration.php in MyBB 1.8.17. On the forum RSS Syndication page, one can generate a URL such as http://localhost/syndication.php?fid=&type=atom1.0&limit=15. The thread titles (within title elements of the generated XML documents) aren't sanitized, leading to XSS.Show less
3Debian
GoogleRedhat
5Chrome
Debian LinuxEnterprise Linux Desktop+2 more
Nov 21, 2024
Aug 28, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Insufficient policy enforcement in Omnibox in Google Chrome prior to 63.0.3239.84 allowed a socially engineered user to XSS themselves by dragging and dropping a javascript: URL into the URL bar.
1Wordfence
1Wordfence Security
Nov 21, 2024
Aug 28, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in the Wordfence Security plugin before 5.1.5 for WordPress allows remote attackers to inject arbitrary web script or HTML via the val parameter to whois.php.
1Atlassian
2Jira
Jira Server
Nov 21, 2024
Aug 28, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Various resources in Atlassian Jira before version 7.6.8, from version 7.7.0 before version 7.7.5, from version 7.8.0 before version 7.8.5, from version 7.9.0 before version 7.9.3, from version 7.10.0 before version 7.10...Show more
Various resources in Atlassian Jira before version 7.6.8, from version 7.7.0 before version 7.7.5, from version 7.8.0 before version 7.8.5, from version 7.9.0 before version 7.9.3, from version 7.10.0 before version 7.10.3 and before version 7.11.1 allow remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the epic colour field of an issue while an issue is being moved.Show less
1Asustor
1Data Master
Nov 21, 2024
Aug 27, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
ASUSTOR Data Master 3.1.5 and below makes an HTTP request for a configuration file that is vulnerable to XSS. A man in the middle can take advantage of this by inserting Javascript into the configuration files Version fi...Show more
ASUSTOR Data Master 3.1.5 and below makes an HTTP request for a configuration file that is vulnerable to XSS. A man in the middle can take advantage of this by inserting Javascript into the configuration files Version field.Show less
1Qnap
1Photo Station
Nov 21, 2024
Aug 27, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting vulnerability in QNAP Photo Station versions 5.7.0 and earlier could allow remote attackers to inject Javascript code in the compromised application.
11234n
1Minicms
Feb 13, 2026
Aug 27, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in MiniCMS 1.10. There is a post.php?date= XSS vulnerability.
1Zyxel
1Vmg3312 B10b Firmware
Nov 21, 2024
Aug 26, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Zyxel VMG3312 B10B devices are affected by a persistent XSS vulnerability via the pages/connectionStatus/connectionStatus-hostEntry.cmd hostname parameter.
1Puppycms
1Puppycms
Nov 21, 2024
Aug 25, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in puppyCMS 5.1. There is an XSS vulnerability via menu.php in the "Add Page/URL" URL link field.
1Get Simple
1Getsimple Cms
Nov 21, 2024
Aug 25, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
GetSimple CMS 3.3.14 has XSS via the admin/edit.php "Add New Page" field.
1Wolfcms
1Wolf Cms
Nov 21, 2024
Aug 25, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
WolfCMS 0.8.3.1 has XSS via the /?/admin/page/add slug parameter.
1Dlink
1Dir 615 Firmware
Nov 21, 2024
Aug 25, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability on D-Link DIR-615 routers 20.07 allows attackers to inject JavaScript into the router's admin UPnP page via the description field in an AddPortMapping UPnP SOAP request.
1Dlink
1Dir 615 Firmware
Nov 21, 2024
Aug 25, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability on D-Link DIR-615 routers 20.07 allows an attacker to inject JavaScript into the "Status -> Active Client Table" page via the hostname field in a DHCP request.
1Pimcore
1Pimcore
Nov 21, 2024
Aug 24, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Pimcore allows XSS via Users, Assets, Data Objects, Video Thumbnails, Image Thumbnails, Field-Collections, Objectbrick, Classification Store, Document Types, Predefined Properties, Predefined Asset Metadata, Quantity Val...Show more
Pimcore allows XSS via Users, Assets, Data Objects, Video Thumbnails, Image Thumbnails, Field-Collections, Objectbrick, Classification Store, Document Types, Predefined Properties, Predefined Asset Metadata, Quantity Value, and Static Routes functions.Show less
1Phpmyadmin
1Phpmyadmin
Nov 21, 2024
Aug 24, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in phpMyAdmin before 4.8.3. A Cross-Site Scripting vulnerability has been found where an attacker can use a crafted file to manipulate an authenticated user who loads that file through the import...Show more
An issue was discovered in phpMyAdmin before 4.8.3. A Cross-Site Scripting vulnerability has been found where an attacker can use a crafted file to manipulate an authenticated user who loads that file through the import feature.Show less
1Cobbler Project
1Cobbler
Nov 21, 2024
Aug 22, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A flaw was found in cobbler software component version 2.6.11-1. It suffers from an invalid parameter validation vulnerability, leading the arbitrary file reading. The flaw is triggered by navigating to a vulnerable URL...Show more
A flaw was found in cobbler software component version 2.6.11-1. It suffers from an invalid parameter validation vulnerability, leading the arbitrary file reading. The flaw is triggered by navigating to a vulnerable URL via cobbler-web on a default installation.Show less