← Back
CWE-79

46,038 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (46,038)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Atlassian
2Jira
Jira Server
Nov 21, 2024
Jul 18, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The EditIssue.jspa resource in Atlassian Jira before version 7.6.7 and from version 7.7.0 before version 7.10.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerabilit...Show more
The EditIssue.jspa resource in Atlassian Jira before version 7.6.7 and from version 7.7.0 before version 7.10.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the issuetype parameter.Show less
1Mcafee
1Network Security Manager
Jun 17, 2026
Jul 17, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Abuse of Functionality vulnerability in the web interface in McAfee Network Security Management (NSM) 9.1.7.11 and earlier allows authenticated users to allow arbitrary HTML code to be reflected in the response web page...Show more
Abuse of Functionality vulnerability in the web interface in McAfee Network Security Management (NSM) 9.1.7.11 and earlier allows authenticated users to allow arbitrary HTML code to be reflected in the response web page via appliance web interface.Show less
1Techotronic
1All In One Favicon
Nov 21, 2024
Jul 16, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Multiple Persistent cross-site scripting (XSS) issues in the Techotronic all-in-one-favicon (aka All In One Favicon) plugin 4.6 for WordPress allow remote attackers to inject arbitrary web script or HTML via Apple-Text,...Show more
Multiple Persistent cross-site scripting (XSS) issues in the Techotronic all-in-one-favicon (aka All In One Favicon) plugin 4.6 for WordPress allow remote attackers to inject arbitrary web script or HTML via Apple-Text, GIF-Text, ICO-Text, PNG-Text, or JPG-Text.Show less
1Fortinet
2Fortianalyzer Firmware
Fortimanager Firmware
Nov 21, 2024
Jul 16, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A Cross-site Scripting (XSS) vulnerability in Fortinet FortiManager 6.0.0, 5.6.4 and below versions, FortiAnalyzer 6.0.0, 5.6.4 and below versions allows inject Javascript code and HTML tags through the CN value of CA an...Show more
A Cross-site Scripting (XSS) vulnerability in Fortinet FortiManager 6.0.0, 5.6.4 and below versions, FortiAnalyzer 6.0.0, 5.6.4 and below versions allows inject Javascript code and HTML tags through the CN value of CA and CRL certificates via the import CA and CRL certificates feature.Show less
1Cisco
1Web Security Appliance
Nov 21, 2024
Jul 16, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A vulnerability in the web-based management interface of Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the w...Show more
A vulnerability in the web-based management interface of Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. The vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of an affected device. An attacker could exploit this vulnerability by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface or allow the attacker to access sensitive browser-based information. Cisco Bug IDs: CSCvf03514.Show less
1Atlassian
1Universal Plugin Manager
Nov 21, 2024
Jul 16, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The NotificationRepresentationFactoryImpl class in Atlassian Universal Plugin Manager before version 2.22.9 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in...Show more
The NotificationRepresentationFactoryImpl class in Atlassian Universal Plugin Manager before version 2.22.9 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the name of user submitted add-on names.Show less
1Atlassian
2Jira
Jira Server
Nov 21, 2024
Jul 16, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The IncomingMailServers resource in Atlassian JIRA Server before version 7.6.7, from version 7.7.0 before version 7.7.5, from version 7.8.0 before version 7.8.5, from version 7.9.0 before version 7.9.3 and from version 7...Show more
The IncomingMailServers resource in Atlassian JIRA Server before version 7.6.7, from version 7.7.0 before version 7.7.5, from version 7.8.0 before version 7.8.5, from version 7.9.0 before version 7.9.3 and from version 7.10.0 before version 7.10.2 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the messagesThreshold parameter as the fix for CVE-2017-18039 was incomplete.Show less
1Accellion
1Ftp Server
Nov 21, 2024
Jul 13, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Accellion FTP server prior to version FTA_9_12_220 uses the Accusoft Prizm Content flash component, which contains multiple parameters (customTabCategoryName, customButton1Image) that are vulnerable to cross-site scripti...Show more
Accellion FTP server prior to version FTA_9_12_220 uses the Accusoft Prizm Content flash component, which contains multiple parameters (customTabCategoryName, customButton1Image) that are vulnerable to cross-site scripting.Show less
1Jqueryform
1Php Formmail Generator
Nov 21, 2024
Jul 13, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The code generated by PHP FormMail Generator prior to 17 December 2016 is vulnerable to stored cross-site scripting. In the generated form.lib.php file, upload file types are checked against a hard-coded list of dangerou...Show more
The code generated by PHP FormMail Generator prior to 17 December 2016 is vulnerable to stored cross-site scripting. In the generated form.lib.php file, upload file types are checked against a hard-coded list of dangerous extensions. This list does not include all variations of PHP files, which may lead to execution of the contained PHP code if the attacker can guess the uploaded filename. The form by default appends a short random string to the end of the filename.Show less
1Emc
1Rsa Identity Governance And Lifecycle
Nov 21, 2024
Jul 13, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
RSA Identity Lifecycle and Governance versions 7.0.1, 7.0.2 and 7.1.0 contains a reflected cross-site scripting vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability by tricking a...Show more
RSA Identity Lifecycle and Governance versions 7.0.1, 7.0.2 and 7.1.0 contains a reflected cross-site scripting vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability by tricking a victim application user to supply malicious HTML or JavaScript code to a vulnerable web application, which is then reflected back to the victim and executed by the web browser.Show less
1Getbootstrap
1Bootstrap
Nov 21, 2024
Jul 13, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In Bootstrap before 4.1.2, XSS is possible in the data-container property of tooltip.
1Getbootstrap
1Bootstrap
Nov 21, 2024
Jul 13, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In Bootstrap before 4.1.2, XSS is possible in the data-target property of scrollspy.
2Debian
Getbootstrap
2Bootstrap
Debian Linux
Nov 21, 2024
Jul 13, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In Bootstrap before 4.1.2, XSS is possible in the collapse data-parent attribute.
1Wago
4762 3000 Firmware
762 3001 Firmware762 3002 Firmware+1 more
Nov 21, 2024
Jul 12, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
An issue was discovered on WAGO e!DISPLAY 762-3000 through 762-3003 devices with firmware before FW 02. The vulnerability can be exploited by authenticated and unauthenticated users by sending special crafted requests to...Show more
An issue was discovered on WAGO e!DISPLAY 762-3000 through 762-3003 devices with firmware before FW 02. The vulnerability can be exploited by authenticated and unauthenticated users by sending special crafted requests to the web server allowing injecting code within the WBM. The code will be rendered and/or executed in the browser of the user's browser.Show less
1Catfish Cms
1Catfish Cms
Nov 21, 2024
Jul 12, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Catfish CMS v4.7.9 allows XSS via the admin/Index/write.html editorValue parameter (aka an article posted by an administrator).
1Clippercms
1Clippercms
Nov 21, 2024
Jul 12, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
ClipperCMS 1.3.3 has stored XSS via the Full Name field of (1) Security -> Manager Users or (2) Security -> Web Users.
1Topdesk
1Topdesk
Nov 21, 2024
Jul 11, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in TOPdesk before 8.05.017 (June 2018 version) and before 5.7.SR9 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters.
1Crestron
2Airmedia Am 100 Firmware
Airmedia Am 101 Firmware
Nov 21, 2024
Jul 11, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Cross-site scripting (XSS) vulnerability in Crestron Airmedia AM-100 devices with firmware before 1.6.0 and AM-101 devices with firmware before 2.7.0 allows remote attackers to inject arbitrary web script or HTML via uns...Show more
Cross-site scripting (XSS) vulnerability in Crestron Airmedia AM-100 devices with firmware before 1.6.0 and AM-101 devices with firmware before 2.7.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.Show less
1Ibm
1Inotes
Nov 21, 2024
Jul 11, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-site scripting (XSS) vulnerability in IBM iNotes before 8.5.3 Fix Pack 6 and 9.x before 9.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. IBM X-Force ID: 83815.
1Rocketchat
1Rocket.chat
Nov 21, 2024
Jul 11, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A reflected XSS issue was discovered in the registration form in Rocket.Chat before 0.66. When one creates an account, the next step will ask for a username. This field will not save HTML control characters but an error...Show more
A reflected XSS issue was discovered in the registration form in Rocket.Chat before 0.66. When one creates an account, the next step will ask for a username. This field will not save HTML control characters but an error will be displayed that shows the attempted username unescaped via packages/rocketchat-ui-login/client/username/username.js in packages/rocketchat-ui-login/client/username/username.html.Show less