← Back
CWE-79

46,064 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (46,064)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Q Cms
1Qcms
Nov 21, 2024
Aug 6, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
An issue was discovered in QCMS 3.0.1. upload/System/Controller/backend/slideshow.php has XSS.
1Q Cms
1Qcms
Nov 21, 2024
Aug 6, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
An issue was discovered in QCMS 3.0.1. upload/System/Controller/backend/system.php has XSS.
1Emlsoft Project
1Emlsoft
Nov 21, 2024
Aug 6, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
An issue was discovered in EMLsoft 5.4.5. XSS exists via the eml/upload/eml/?action=address&do=edit page.
1Zzcms
1Zzcms
Nov 21, 2024
Aug 6, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
zzcms 8.3 has stored XSS related to the content variable in user/manage.php and zt/show.php.
1Ibm
1Rational Doors Next Generation
Nov 21, 2024
Aug 6, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM Jazz Foundation products (IBM Rational DOORS Next Generation 5.0 through 5.0.2 and 6.0 through 6.0.5) are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the...Show more
IBM Jazz Foundation products (IBM Rational DOORS Next Generation 5.0 through 5.0.2 and 6.0 through 6.0.5) are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 139025.Show less
1Apache
1Airflow
Nov 21, 2024
Aug 6, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
It was noticed an XSS in certain 404 pages that could be exploited to perform an XSS attack. Chrome will detect this as a reflected XSS attempt and prevent the page from loading. Firefox and other browsers don't, and are...Show more
It was noticed an XSS in certain 404 pages that could be exploited to perform an XSS attack. Chrome will detect this as a reflected XSS attempt and prevent the page from loading. Firefox and other browsers don't, and are vulnerable to this attack. Mitigation: The fix for this is to upgrade to Apache Airflow 1.9.0 or above.Show less
1Squirrelmail
1Squirrelmail
Nov 21, 2024
Aug 5, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The mail message display page in SquirrelMail through 1.4.22 has XSS via SVG animations (animate to attribute).
1Squirrelmail
1Squirrelmail
Nov 21, 2024
Aug 5, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The mail message display page in SquirrelMail through 1.4.22 has XSS via the formaction attribute.
1Squirrelmail
1Squirrelmail
Nov 21, 2024
Aug 5, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The mail message display page in SquirrelMail through 1.4.22 has XSS via a "<math xlink:href=" attack.
1Squirrelmail
1Squirrelmail
Nov 21, 2024
Aug 5, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The mail message display page in SquirrelMail through 1.4.22 has XSS via a "<math><maction xlink:href=" attack.
1Squirrelmail
1Squirrelmail
Nov 21, 2024
Aug 5, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The mail message display page in SquirrelMail through 1.4.22 has XSS via a "<form action='data:text" attack.
1Squirrelmail
1Squirrelmail
Nov 21, 2024
Aug 5, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The mail message display page in SquirrelMail through 1.4.22 has XSS via a "<svg><a xlink:href=" attack.
1Mylittleforum
1My Little Forum
Nov 21, 2024
Aug 5, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The Add page option in my little forum 2.4.12 allows XSS via the Menu Link field.
1Mylittleforum
1My Little Forum
Nov 21, 2024
Aug 5, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The Add page option in my little forum 2.4.12 allows XSS via the Title field.
1Readymadeb2bscript
1Basic B2b
Nov 21, 2024
Aug 4, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
PHP Scripts Mall Basic B2B Script 2.0.0 has Reflected and Stored XSS via the First name, Last name, Address 1, City, State, and Company name fields.
1Tendacn
1D152 Firmware
Nov 21, 2024
Aug 4, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Tenda D152 ADSL routers allow XSS via a crafted SSID.
1Matera
1Banco
Nov 21, 2024
Aug 3, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Matera Banco 1.0.0 is vulnerable to multiple reflected XSS, as demonstrated by the /contingency/web/index.jsp (aka home page) url parameter.
1Matera
1Banco
Nov 21, 2024
Aug 3, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Matera Banco 1.0.0 is vulnerable to multiple stored XSS, as demonstrated by the sca/privilegio/consultarUsuario.jsf "Nome Completo" (aka user fullname) field.
13cx
13cx Web Server
Nov 21, 2024
Aug 3, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Web server in 3CX version 15.5.8801.3 is vulnerable to Reflected XSS on all stack traces' propertyPath parameters.
13cx
13cx Web Server
Nov 21, 2024
Aug 3, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Web server in 3CX version 15.5.8801.3 is vulnerable to Reflected XSS on the api/CallLog TimeZoneName parameter.