← Back
CWE-79

46,038 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (46,038)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Sanscms
1Sanscms
Nov 21, 2024
Jul 20, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
blog/index.php in SansCMS 0.7 has XSS via the q parameter.
1Metinfo
1Metinfo
Nov 21, 2024
Jul 20, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
MetInfo 6.0.0 allows XSS via a modified name of the navigation bar on the home page.
1Icmsdev
1Icms
Nov 21, 2024
Jul 20, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in idreamsoft iCMS before 7.0.10. XSS exists via the fourth and fifth input elements on the admincp.php?app=prop&do=add screen.
1Sensiolabs
1Symfony
Nov 21, 2024
Jul 20, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The debug handler in Symfony before v2.7.33, 2.8.x before v2.8.26, 3.x before v3.2.13, and 3.3.x before v3.3.6 has XSS via an array key during exception pretty printing in ExceptionHandler.php, as demonstrated by a /_deb...Show more
The debug handler in Symfony before v2.7.33, 2.8.x before v2.8.26, 3.x before v3.2.13, and 3.3.x before v3.3.6 has XSS via an array key during exception pretty printing in ExceptionHandler.php, as demonstrated by a /_debugbar/open?op=get URI. NOTE: the vendor's position is that this is not a vulnerability because the debug tools are not intended for production use. NOTE: the Symfony Debug component is used by Laravel DebugbarShow less
1Ibm
2Rational Rhapsody Design Manager
Rational Software Architect Design Manager
Nov 21, 2024
Jul 19, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM Rational Rhapsody Design Manager 5.0 through 5.0.2 and 6.0 through 6.0.5 and IBM Rational Software Architect Design Manager 5.0 through 5.0.2 and 6.0 through 6.0.1 are vulnerable to cross-site scripting. This vulnera...Show more
IBM Rational Rhapsody Design Manager 5.0 through 5.0.2 and 6.0 through 6.0.5 and IBM Rational Software Architect Design Manager 5.0 through 5.0.2 and 6.0 through 6.0.1 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 143498.Show less
1Ibm
2Rational Rhapsody Design Manager
Rational Software Architect Design Manager
Nov 21, 2024
Jul 19, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM Rational Rhapsody Design Manager 5.0 through 5.0.2 and 6.0 through 6.0.5 and IBM Rational Software Architect Design Manager 5.0 through 5.0.2 and 6.0 through 6.0.1 are vulnerable to cross-site scripting. This vulnera...Show more
IBM Rational Rhapsody Design Manager 5.0 through 5.0.2 and 6.0 through 6.0.5 and IBM Rational Software Architect Design Manager 5.0 through 5.0.2 and 6.0 through 6.0.1 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 142558.Show less
1Ibm
2Rational Rhapsody Design Manager
Rational Software Architect Design Manager
Nov 21, 2024
Jul 19, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM Rational Rhapsody Design Manager 5.0 through 5.0.2 and 6.0 through 6.0.5 and IBM Rational Software Architect Design Manager 5.0 through 5.0.2 and 6.0 through 6.0.1 are vulnerable to cross-site scripting. This vulnera...Show more
IBM Rational Rhapsody Design Manager 5.0 through 5.0.2 and 6.0 through 6.0.5 and IBM Rational Software Architect Design Manager 5.0 through 5.0.2 and 6.0 through 6.0.1 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 124557.Show less
1Ibm
2Rational Doors Next Generation
Rational Requirements Composer
Nov 21, 2024
Jul 19, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM Rational DOORS Next Generation 5.0 through 5.0.2, 6.0 through 6.0.5 and IBM Rational Requirements Composer 5.0 through 5.0.2 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary...Show more
IBM Rational DOORS Next Generation 5.0 through 5.0.2, 6.0 through 6.0.5 and IBM Rational Requirements Composer 5.0 through 5.0.2 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 142291.Show less
1Mybb
1New Threads
Nov 21, 2024
Jul 19, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The New Threads plugin before 1.2 for MyBB has XSS.
1Cisco
2Unified Contact Center Express
Unified Ip Interactive Voice Response
Nov 21, 2024
Jul 18, 2018
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
Multiple vulnerabilities in the web-based management interface of Cisco Unified Contact Center Express (Unified CCX) could allow an unauthenticated, remote attacker to retrieve a cleartext password. Cisco Bug IDs: CSCvg7...Show more
Multiple vulnerabilities in the web-based management interface of Cisco Unified Contact Center Express (Unified CCX) could allow an unauthenticated, remote attacker to retrieve a cleartext password. Cisco Bug IDs: CSCvg71040.Show less
1Cisco
2Unified Contact Center Express
Unified Ip Interactive Voice Response
Nov 21, 2024
Jul 18, 2018
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Multiple vulnerabilities in the web-based management interface of Cisco Unified Contact Center Express (Unified CCX) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack....Show more
Multiple vulnerabilities in the web-based management interface of Cisco Unified Contact Center Express (Unified CCX) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack. Cisco Bug IDs: CSCvg70921.Show less
1Cisco
2Unified Contact Center Express
Unified Ip Interactive Voice Response
Nov 21, 2024
Jul 18, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Multiple vulnerabilities in the web-based management interface of Cisco Unified Contact Center Express (Unified CCX) could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a...Show more
Multiple vulnerabilities in the web-based management interface of Cisco Unified Contact Center Express (Unified CCX) could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. Cisco Bug IDs: CSCvg70967.Show less
1Cisco
2Unified Contact Center Express
Unified Ip Interactive Voice Response
Nov 21, 2024
Jul 18, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Multiple vulnerabilities in the web-based management interface of Cisco Unified Contact Center Express (Unified CCX) could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a...Show more
Multiple vulnerabilities in the web-based management interface of Cisco Unified Contact Center Express (Unified CCX) could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. Cisco Bug IDs: CSCvg70904.Show less
1Cisco
1Unified Communications Manager Im And Presence Service
Nov 21, 2024
Jul 18, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A vulnerability in the web framework of the Cisco Unified Communications Manager IM and Presence Service software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against the u...Show more
A vulnerability in the web framework of the Cisco Unified Communications Manager IM and Presence Service software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against the user of the web interface of an affected system. The vulnerability is due to insufficient input validation of certain parameters passed to the web server. An attacker could exploit this vulnerability by convincing the user to access a malicious link or by intercepting the user request and injecting certain malicious code. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected site or allow the attacker to access sensitive browser-based information. Cisco Bug IDs: CSCve25985.Show less
1Cisco
1Webex Meetings
Nov 21, 2024
Jul 18, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A vulnerability in the web framework of Cisco Webex could allow an unauthenticated, remote attacker to conduct a Document Object Model-based (DOM-based) cross-site scripting (XSS) attack against the user of the web inter...Show more
A vulnerability in the web framework of Cisco Webex could allow an unauthenticated, remote attacker to conduct a Document Object Model-based (DOM-based) cross-site scripting (XSS) attack against the user of the web interface of an affected system. The vulnerability is due to insufficient input validation of certain parameters that are passed to the affected software by using the HTTP POST method. An attacker who can submit malicious scripts to the affected user interface element could execute arbitrary script or HTML code in the user's browser in the context of the affected site. Cisco Bug IDs: CSCvj33287.Show less
1Joyplus Cms Project
1Joyplus Cms
Nov 21, 2024
Jul 18, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
joyplus-cms 1.6.0 has XSS via the manager/admin_ajax.php can_search_device array parameter.
1Freelancewebdesignerchennai
1Job Portal
Nov 21, 2024
Jul 18, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
PHP Scripts Mall JOB SITE (aka Job Portal) 3.0.1 has Cross-site Scripting (XSS) via the search bar.
1Jeesns
1Jeesns
Nov 21, 2024
Jul 18, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
JEESNS through 1.2.1 allows XSS attacks by ordinary users who publish articles containing a crafted payload in order to capture an administrator cookie.
1Instantcms
1Instantcms
Nov 21, 2024
Jul 18, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
InstantCMS 2.10.1 has /redirect?url= XSS.
1Graylog
1Graylog
Nov 21, 2024
Jul 18, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In Graylog before 2.4.6, XSS was possible in typeahead components, related to components/common/TypeAheadInput.jsx and components/search/QueryInput.ts.