CWE-79
46,038 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (46,038)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
blog/index.php in SansCMS 0.7 has XSS via the q parameter. |
MetInfo 6.0.0 allows XSS via a modified name of the navigation bar on the home page. |
An issue was discovered in idreamsoft iCMS before 7.0.10. XSS exists via the fourth and fifth input elements on the admincp.php?app=prop&do=add screen. |
The debug handler in Symfony before v2.7.33, 2.8.x before v2.8.26, 3.x before v3.2.13, and 3.3.x before v3.3.6 has XSS via an array key during exception pretty printing in ExceptionHandler.php, as demonstrated by a /_deb...Show more |
1Ibm 2Rational Rhapsody Design Manager Rational Software Architect Design ManagerNov 21, 2024 Jul 19, 2018 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 IBM Rational Rhapsody Design Manager 5.0 through 5.0.2 and 6.0 through 6.0.5 and IBM Rational Software Architect Design Manager 5.0 through 5.0.2 and 6.0 through 6.0.1 are vulnerable to cross-site scripting. This vulnera...Show more |
1Ibm 2Rational Rhapsody Design Manager Rational Software Architect Design ManagerNov 21, 2024 Jul 19, 2018 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 IBM Rational Rhapsody Design Manager 5.0 through 5.0.2 and 6.0 through 6.0.5 and IBM Rational Software Architect Design Manager 5.0 through 5.0.2 and 6.0 through 6.0.1 are vulnerable to cross-site scripting. This vulnera...Show more |
1Ibm 2Rational Rhapsody Design Manager Rational Software Architect Design ManagerNov 21, 2024 Jul 19, 2018 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 IBM Rational Rhapsody Design Manager 5.0 through 5.0.2 and 6.0 through 6.0.5 and IBM Rational Software Architect Design Manager 5.0 through 5.0.2 and 6.0 through 6.0.1 are vulnerable to cross-site scripting. This vulnera...Show more |
1Ibm 2Rational Doors Next Generation Rational Requirements ComposerNov 21, 2024 Jul 19, 2018 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 IBM Rational DOORS Next Generation 5.0 through 5.0.2, 6.0 through 6.0.5 and IBM Rational Requirements Composer 5.0 through 5.0.2 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary...Show more |
The New Threads plugin before 1.2 for MyBB has XSS. |
1Cisco 2Unified Contact Center Express Unified Ip Interactive Voice ResponseNov 21, 2024 Jul 18, 2018 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 Multiple vulnerabilities in the web-based management interface of Cisco Unified Contact Center Express (Unified CCX) could allow an unauthenticated, remote attacker to retrieve a cleartext password. Cisco Bug IDs: CSCvg7...Show more |
1Cisco 2Unified Contact Center Express Unified Ip Interactive Voice ResponseNov 21, 2024 Jul 18, 2018 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Multiple vulnerabilities in the web-based management interface of Cisco Unified Contact Center Express (Unified CCX) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack....Show more |
1Cisco 2Unified Contact Center Express Unified Ip Interactive Voice ResponseNov 21, 2024 Jul 18, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Multiple vulnerabilities in the web-based management interface of Cisco Unified Contact Center Express (Unified CCX) could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a...Show more |
1Cisco 2Unified Contact Center Express Unified Ip Interactive Voice ResponseNov 21, 2024 Jul 18, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Multiple vulnerabilities in the web-based management interface of Cisco Unified Contact Center Express (Unified CCX) could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a...Show more |
1Cisco 1Unified Communications Manager Im And Presence Service Nov 21, 2024 Jul 18, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 A vulnerability in the web framework of the Cisco Unified Communications Manager IM and Presence Service software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against the u...Show more |
A vulnerability in the web framework of Cisco Webex could allow an unauthenticated, remote attacker to conduct a Document Object Model-based (DOM-based) cross-site scripting (XSS) attack against the user of the web inter...Show more |
1Joyplus Cms Project 1Joyplus Cms Nov 21, 2024 Jul 18, 2018 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 joyplus-cms 1.6.0 has XSS via the manager/admin_ajax.php can_search_device array parameter. |
1Freelancewebdesignerchennai 1Job Portal Nov 21, 2024 Jul 18, 2018 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 PHP Scripts Mall JOB SITE (aka Job Portal) 3.0.1 has Cross-site Scripting (XSS) via the search bar. |
JEESNS through 1.2.1 allows XSS attacks by ordinary users who publish articles containing a crafted payload in order to capture an administrator cookie. |
InstantCMS 2.10.1 has /redirect?url= XSS. |
In Graylog before 2.4.6, XSS was possible in typeahead components, related to components/common/TypeAheadInput.jsx and components/search/QueryInput.ts. |