CWE-79
46,064 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (46,064)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
An issue was discovered in QCMS 3.0.1. upload/System/Controller/backend/slideshow.php has XSS. |
An issue was discovered in QCMS 3.0.1. upload/System/Controller/backend/system.php has XSS. |
An issue was discovered in EMLsoft 5.4.5. XSS exists via the eml/upload/eml/?action=address&do=edit page. |
zzcms 8.3 has stored XSS related to the content variable in user/manage.php and zt/show.php. |
1Ibm 1Rational Doors Next Generation Nov 21, 2024 Aug 6, 2018 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 IBM Jazz Foundation products (IBM Rational DOORS Next Generation 5.0 through 5.0.2 and 6.0 through 6.0.5) are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the...Show more |
It was noticed an XSS in certain 404 pages that could be exploited to perform an XSS attack. Chrome will detect this as a reflected XSS attempt and prevent the page from loading. Firefox and other browsers don't, and are...Show more |
The mail message display page in SquirrelMail through 1.4.22 has XSS via SVG animations (animate to attribute). |
The mail message display page in SquirrelMail through 1.4.22 has XSS via the formaction attribute. |
The mail message display page in SquirrelMail through 1.4.22 has XSS via a "<math xlink:href=" attack. |
The mail message display page in SquirrelMail through 1.4.22 has XSS via a "<math><maction xlink:href=" attack. |
The mail message display page in SquirrelMail through 1.4.22 has XSS via a "<form action='data:text" attack. |
The mail message display page in SquirrelMail through 1.4.22 has XSS via a "<svg><a xlink:href=" attack. |
The Add page option in my little forum 2.4.12 allows XSS via the Menu Link field. |
The Add page option in my little forum 2.4.12 allows XSS via the Title field. |
PHP Scripts Mall Basic B2B Script 2.0.0 has Reflected and Stored XSS via the First name, Last name, Address 1, City, State, and Company name fields. |
Tenda D152 ADSL routers allow XSS via a crafted SSID. |
Matera Banco 1.0.0 is vulnerable to multiple reflected XSS, as demonstrated by the /contingency/web/index.jsp (aka home page) url parameter. |
Matera Banco 1.0.0 is vulnerable to multiple stored XSS, as demonstrated by the sca/privilegio/consultarUsuario.jsf "Nome Completo" (aka user fullname) field. |
The Web server in 3CX version 15.5.8801.3 is vulnerable to Reflected XSS on all stack traces' propertyPath parameters. |
The Web server in 3CX version 15.5.8801.3 is vulnerable to Reflected XSS on the api/CallLog TimeZoneName parameter. |