← Back
CWE-79

46,038 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (46,038)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Open Xchange
1Open Xchange Appsuite
Jun 17, 2026
Jul 5, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in mail compose in Open-Xchange OX App Suite before 7.6.3-rev31, 7.8.x before 7.8.2-rev31, 7.8.3 before 7.8.3-rev41, and 7.8.4 before 7.8.4-rev28 allows remote attackers to inject...Show more
Cross-site scripting (XSS) vulnerability in mail compose in Open-Xchange OX App Suite before 7.6.3-rev31, 7.8.x before 7.8.2-rev31, 7.8.3 before 7.8.3-rev41, and 7.8.4 before 7.8.4-rev28 allows remote attackers to inject arbitrary web script or HTML via the data-target attribute in an HTML page with data-toggle gadgets.Show less
1Airties
25444 Firmware
5444tt Firmware
Jun 17, 2026
Jul 5, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Airties 5444 1.0.0.18 and 5444TT 1.0.0.18 devices allow XSS.
1Sencha
1Ext Js
Jun 17, 2026
Jul 5, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The getTip() method of Action Columns of Sencha Ext JS 4 to 6 before 6.6.0 is vulnerable to XSS attacks, even when passed HTML-escaped data. This framework brings no built-in XSS protection, so the developer has to ensur...Show more
The getTip() method of Action Columns of Sencha Ext JS 4 to 6 before 6.6.0 is vulnerable to XSS attacks, even when passed HTML-escaped data. This framework brings no built-in XSS protection, so the developer has to ensure that data is correctly sanitized. However, the getTip() method of Action Columns takes HTML-escaped data and un-escapes it. If the tooltip contains user-controlled data, an attacker could exploit this to create a cross-site scripting attack, even when developers took precautions and escaped data.Show less
1Siemens
1Fin Stack
Nov 21, 2024
Jul 5, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In J2 Innovations FIN Stack 4.0, the authentication webform is vulnerable to reflected XSS via the query string to /login.
1Entrustdatacard
1Syntera Customization Suite
Nov 21, 2024
Jul 5, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Entrust Datacard Syntera CS 5.x has XSS via the name field of "Domain or Computer Name" in the login page.
1Ruby Grape
1Grape
Nov 21, 2024
Jul 5, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
ruby-grape ruby gem suffers from a cross-site scripting (XSS) vulnerability via "format" parameter.
1Nextcloud
1Contacts
Nov 21, 2024
Jul 5, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
In Nextcloud Contacts before 2.1.2, a missing sanitization of search results for an autocomplete field could lead to a stored XSS requiring user-interaction. The missing sanitization only affected group names, hence mali...Show more
In Nextcloud Contacts before 2.1.2, a missing sanitization of search results for an autocomplete field could lead to a stored XSS requiring user-interaction. The missing sanitization only affected group names, hence malicious search results could only be crafted by privileged users like admins or group admins.Show less
1Nextcloud
1Calendar
Nov 21, 2024
Jul 5, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
In Nextcloud Calendar before 1.5.8 and 1.6.1, a missing sanitization of search results for an autocomplete field could lead to a stored XSS requiring user-interaction. The missing sanitization only affected group names,...Show more
In Nextcloud Calendar before 1.5.8 and 1.6.1, a missing sanitization of search results for an autocomplete field could lead to a stored XSS requiring user-interaction. The missing sanitization only affected group names, hence malicious search results could only be crafted by privileged users like admins or group admins.Show less
1Synology
1Carddav Server
Jun 17, 2026
Jul 5, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-site scripting (XSS) vulnerability in Address Book Editor in Synology CardDAV Server before 6.0.8-0086 allows remote authenticated users to inject arbitrary web script or HTML via the (1) family_name, (2) given_nam...Show more
Cross-site scripting (XSS) vulnerability in Address Book Editor in Synology CardDAV Server before 6.0.8-0086 allows remote authenticated users to inject arbitrary web script or HTML via the (1) family_name, (2) given_name, or (3) additional_name parameter.Show less
1Bedita
1Bedita
Nov 21, 2024
Jul 5, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
An issue was discovered in BEdita before 3.7.0. A cross-site scripting (XSS) attack occurs via a crafted pages/showObjects URI, as demonstrated by appending a payload to a pages/showObjects/2/0/0/leafs URI.
1Ultimatemember
1Ultimate Member
Nov 21, 2024
Jul 4, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Ultimate Member (aka ultimatemember) plugin before 2.0.18 for WordPress has XSS via the wp-admin settings screen.
1Tp Link
1Archer C1200 Firmware
Nov 21, 2024
Jul 4, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
TP-Link Archer C1200 1.13 Build 2018/01/24 rel.52299 EU devices have XSS via the PATH_INFO to the /webpages/data URI.
1Paloaltonetworks
1Pan Os
Jun 17, 2026
Jul 3, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The PAN-OS web interface administration page in PAN-OS 6.1.20 and earlier, PAN-OS 7.1.17 and earlier, PAN-OS 8.0.10 and earlier, and PAN-OS 8.1.1 and earlier may allow an attacker to inject arbitrary JavaScript or HTML.
1Paloaltonetworks
1Pan Os
Jun 17, 2026
Jul 3, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The PAN-OS session browser in PAN-OS 6.1.20 and earlier, PAN-OS 7.1.16 and earlier, PAN-OS 8.0.9 and earlier, and PAN-OS 8.1.1 and earlier may allow an attacker to inject arbitrary JavaScript or HTML.
1Paloaltonetworks
1Pan Os
Jun 17, 2026
Jul 3, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The URL filtering "continue page" hosted by PAN-OS 8.0.10 and earlier may allow an attacker to inject arbitrary JavaScript or HTML via specially crafted URLs.
1Glance Project
1Glance
Nov 21, 2024
Jul 3, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
There is a Stored XSS vulnerability in the glance node module versions <= 3.0.5. File name, which contains malicious HTML (eg. embedded iframe element or javascript: pseudo-protocol handler in <a> element) allows to exec...Show more
There is a Stored XSS vulnerability in the glance node module versions <= 3.0.5. File name, which contains malicious HTML (eg. embedded iframe element or javascript: pseudo-protocol handler in <a> element) allows to execute JavaScript code against any user who opens a directory listing containing such crafted file name.Show less
1Public.js Project
1Public.js
Nov 21, 2024
Jul 3, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The public node module versions <= 1.0.3 allows to embed HTML in file names, which (in certain conditions) might lead to execute malicious JavaScript.
1Ui
1Ucrm
Nov 21, 2024
Jul 3, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Ubiquiti UCRM versions 2.5.0 to 2.7.7 are vulnerable to Stored Cross-site Scripting. Due to the lack sanitization, it is possible to inject arbitrary HTML code by manipulating the uploaded filename. Successful exploitati...Show more
Ubiquiti UCRM versions 2.5.0 to 2.7.7 are vulnerable to Stored Cross-site Scripting. Due to the lack sanitization, it is possible to inject arbitrary HTML code by manipulating the uploaded filename. Successful exploitation requires valid credentials to an account with "Edit" access to "Scheduling".Show less
1Ibm
2Rational Collaborative Lifecycle Management
Rational Quality Manager
Nov 21, 2024
Jul 3, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM Rational Quality Manager and IBM Rational Collaborative Lifecycle Management 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScri...Show more
IBM Rational Quality Manager and IBM Rational Collaborative Lifecycle Management 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 134796.Show less
1Ibm
2Rational Collaborative Lifecycle Management
Rational Quality Manager
Nov 21, 2024
Jul 3, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM Rational Quality Manager and IBM Rational Collaborative Lifecycle Management 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScri...Show more
IBM Rational Quality Manager and IBM Rational Collaborative Lifecycle Management 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 134637.Show less