← Back
CWE-79

46,100 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (46,100)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Open Emr
1Openemr
Nov 21, 2024
Aug 20, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
OpenEMR version v5_0_1_4 contains a Cross Site Scripting (XSS) vulnerability in The 'scan' parameter in line #41 of interface/fax/fax_view.php that can result in The vulnerability could allow remote authenticated attacke...Show more
OpenEMR version v5_0_1_4 contains a Cross Site Scripting (XSS) vulnerability in The 'scan' parameter in line #41 of interface/fax/fax_view.php that can result in The vulnerability could allow remote authenticated attackers to inject arbitrary web script or HTML.. This attack appear to be exploitable via The victim must visit on a specially crafted URL..Show less
1Open Emr
1Openemr
Nov 21, 2024
Aug 20, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
OpenEMR version v5_0_1_4 contains a Cross Site Scripting (XSS) vulnerability in The 'file' parameter in line #43 of interface/fax/fax_view.php that can result in The vulnerability could allow remote authenticated attacke...Show more
OpenEMR version v5_0_1_4 contains a Cross Site Scripting (XSS) vulnerability in The 'file' parameter in line #43 of interface/fax/fax_view.php that can result in The vulnerability could allow remote authenticated attackers to inject arbitrary web script or HTML.. This attack appear to be exploitable via The victim must visit on a specially crafted URL..Show less
1Flightairmap
1Flightairmap
Nov 21, 2024
Aug 20, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
FlightAirMap version <=v1.0-beta.21 contains a Cross Site Scripting (XSS) vulnerability in GET variable used within registration sub menu page that can result in unauthorised actions and access to data, stealing session...Show more
FlightAirMap version <=v1.0-beta.21 contains a Cross Site Scripting (XSS) vulnerability in GET variable used within registration sub menu page that can result in unauthorised actions and access to data, stealing session information. This vulnerability appears to have been fixed in after commit 22b09a3.Show less
1Villagedefrance
1Opencart Overclocked
Nov 21, 2024
Aug 20, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
OpenCart-Overclocked version <=1.11.1 contains a Cross Site Scripting (XSS) vulnerability in User input entered unsanitised within JS function in the template that can result in Unauthorised actions and access to data, s...Show more
OpenCart-Overclocked version <=1.11.1 contains a Cross Site Scripting (XSS) vulnerability in User input entered unsanitised within JS function in the template that can result in Unauthorised actions and access to data, stealing session information, denial of service. This attack appear to be exploitable via Malicious input passed in GET parameter.Show less
11234n
1Minicms
Nov 21, 2024
Aug 20, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
MiniCMS version 1.1 contains a Cross Site Scripting (XSS) vulnerability in http://example.org/mc-admin/page.php?date={payload} that can result in code injection.
1Reprisesoftware
1Reprise License Manager
Apr 30, 2025
Aug 20, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in the license editor in Reprise License Manager (RLM) through 12.2BL2. It is a cross-site scripting vulnerability in the /goform/edit_lf_get_data lf parameter via GET or POST. NOTE: the vendor ha...Show more
An issue was discovered in the license editor in Reprise License Manager (RLM) through 12.2BL2. It is a cross-site scripting vulnerability in the /goform/edit_lf_get_data lf parameter via GET or POST. NOTE: the vendor has stated "We do not consider this a vulnerability."Show less
1Bijiadao
1Waimai Super Cms
Nov 21, 2024
Aug 20, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
In waimai Super Cms 20150505, there is stored XSS via the /admin.php/Foodcat/editsave fcname parameter.
1Cmsuno Project
1Cmsuno
Nov 21, 2024
Aug 20, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
CMSUno before 1.5.3 has XSS via the title field.
1Tp5cms Project
1Tp5cms
Nov 21, 2024
Aug 20, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
tp5cms through 2017-05-25 has XSS via the admin.php/article/index.html q parameter.
1Xiuno
1Xiunobbs
Nov 21, 2024
Aug 20, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The editor in Xiuno BBS 4.0.4 allows stored XSS.
1Paloaltonetworks
1Pan Os
Nov 21, 2024
Aug 16, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The PAN-OS response for GlobalProtect Gateway in Palo Alto Networks PAN-OS 6.1.21 and earlier, PAN-OS 7.1.18 and earlier, PAN-OS 8.0.11 and earlier may allow an unauthenticated attacker to inject arbitrary JavaScript or...Show more
The PAN-OS response for GlobalProtect Gateway in Palo Alto Networks PAN-OS 6.1.21 and earlier, PAN-OS 7.1.18 and earlier, PAN-OS 8.0.11 and earlier may allow an unauthenticated attacker to inject arbitrary JavaScript or HTML. PAN-OS 8.1 is NOT affected.Show less
1Ibm
1Maximo Asset Management
Nov 21, 2024
Aug 16, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM Maximo Asset Management 7.6 through 7.6.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially l...Show more
IBM Maximo Asset Management 7.6 through 7.6.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 147003.Show less
1Cisco
2Hosted Collaboration Solution
Unified Communications Domain Manager
Nov 21, 2024
Aug 15, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A vulnerability in Cisco Unified Communications Domain Manager Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack on an affected system. The vulnerability is due to im...Show more
A vulnerability in Cisco Unified Communications Domain Manager Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack on an affected system. The vulnerability is due to improper validation of input that is passed to the affected software. An attacker could exploit this vulnerability by persuading a user of the affected software to access a malicious URL. A successful exploit could allow the attacker to access sensitive, browser-based information on the affected system or perform arbitrary actions in the affected software in the security context of the user. Cisco Bug IDs: CSCvh49694.Show less
1Cisco
1Registered Envelope Service
Nov 21, 2024
Aug 15, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A vulnerability in the web-based management interface of the Cisco Registered Envelope Service could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based...Show more
A vulnerability in the web-based management interface of the Cisco Registered Envelope Service could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of the affected service. The vulnerability is due to insufficient validation of user-supplied input that is processed by the web-based management interface of the affected service. An attacker could exploit this vulnerability by persuading a user of the interface to click a malicious link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface or access sensitive browser-based information. Cisco Bug IDs: CVE-2018-0367.Show less
1Intelbras
1Win 240 Firmware
Nov 21, 2024
Aug 15, 2018
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
A Cross-site scripting (XSS) vulnerability was discovered on Intelbras Win 240 V1.1.0 devices. An attacker can change the Admin Password without a Login.
1Monstra
1Monstra
Nov 21, 2024
Aug 14, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Multiple cross-site scripting (XSS) vulnerabilities in Monstra CMS 3.0.4 allow remote attackers to inject arbitrary web script or HTML via the (1) first name or (2) last name field in the edit profile page.
1Thank You/like Project
1Thank You/like
Nov 21, 2024
Aug 14, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
inc/plugins/thankyoulike.php in the Eldenroot Thank You/Like plugin before 3.1.0 for MyBB allows XSS via a post or thread subject.
1Sap
1Businessobjects Financial Consolidation
Nov 21, 2024
Aug 14, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
SAP BusinessObjects Financial Consolidation, versions 10.0, 10.1, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.
1Nextcloud
1Talk
Nov 21, 2024
Aug 13, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A missing sanitization of search results for an autocomplete field in NextCloud Talk <3.2.5 could lead to a stored XSS requiring user-interaction. The missing sanitization only affected user names, hence malicious search...Show more
A missing sanitization of search results for an autocomplete field in NextCloud Talk <3.2.5 could lead to a stored XSS requiring user-interaction. The missing sanitization only affected user names, hence malicious search results could only be crafted by authenticated users.Show less
1Nextcloud
1Nextcloud Server
Nov 21, 2024
Aug 13, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A missing sanitization of search results for an autocomplete field in NextCloud Server <13.0.5 could lead to a stored XSS requiring user-interaction. The missing sanitization only affected user names, hence malicious sea...Show more
A missing sanitization of search results for an autocomplete field in NextCloud Server <13.0.5 could lead to a stored XSS requiring user-interaction. The missing sanitization only affected user names, hence malicious search results could only be crafted by authenticated users.Show less