CWE-79
46,037 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (46,037)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Ibm 2Rational Collaborative Lifecycle Management Rational Quality ManagerNov 21, 2024 Jul 3, 2018 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 IBM Rational Quality Manager and IBM Rational Collaborative Lifecycle Management 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScri...Show more |
1Ibm 2Rational Collaborative Lifecycle Management Rational Quality ManagerNov 21, 2024 Jul 3, 2018 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 IBM Rational Quality Manager and IBM Rational Collaborative Lifecycle Management 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScri...Show more |
1Ibm 2Rational Collaborative Lifecycle Management Rational Quality ManagerNov 21, 2024 Jul 3, 2018 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 IBM Rational Quality Manager and IBM Rational Collaborative Lifecycle Management 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScri...Show more |
1Ibm 2Rational Collaborative Lifecycle Management Rational Quality ManagerNov 21, 2024 Jul 3, 2018 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 IBM Rational Quality Manager and IBM Rational Collaborative Lifecycle Management 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScri...Show more |
1Ibm 2Rational Collaborative Lifecycle Management Rational Quality ManagerNov 21, 2024 Jul 3, 2018 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 IBM Rational Quality Manager and IBM Rational Collaborative Lifecycle Management 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScri...Show more |
1Ibm 2Rational Collaborative Lifecycle Management Rational Quality ManagerNov 21, 2024 Jul 3, 2018 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 IBM Rational Quality Manager and IBM Rational Collaborative Lifecycle Management 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScri...Show more |
ClipperCMS 1.3.3 has stored XSS via the "Tools -> Configuration" screen of the manager/ URI. |
1Schneider Electric 1U.motion Builder Jun 17, 2026 Jul 3, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 In Schneider Electric U.motion Builder software versions prior to v1.3.4, a cross site scripting (XSS) vulnerability exists which could allow injection of malicious scripts. |
ModSecurity 3.0.0 has XSS via an onerror attribute of an IMG element. NOTE: a third party has disputed this issue because it may only apply to environments without a Core Rule Set configured |
An XSS issue was discovered in InvoicePlane 1.5.10 via the "Quote PDF Password(Optional)" field. |
1Zohocorp 1Manageengine Eventlog Analyzer Nov 21, 2024 Jul 2, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in Zoho ManageEngine EventLog Analyzer 11.12. A Cross-Site Scripting vulnerability allows a remote attacker to inject arbitrary web script or HTML via the search functionality (the search box of t...Show more |
1Zohocorp 1Manageengine Eventlog Analyzer Nov 21, 2024 Jul 2, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Cross-site scripting (XSS) vulnerability in Zoho ManageEngine EventLog Analyzer 11.12 allows remote attackers to inject arbitrary web script or HTML via the import logs feature. |
2Canonical Xapian2Ubuntu Linux Xapian CoreNov 21, 2024 Jul 2, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 A cross-site scripting vulnerability in queryparser/termgenerator_internal.cc in Xapian xapian-core before 1.4.6 exists due to incomplete HTML escaping by Xapian::MSet::snippet(). |
OpenSID 18.06-pasca has reflected Cross Site Scripting (XSS) via the cari parameter, aka an index.php/first?cari= URI. |
Cross-site scripting (XSS) vulnerability for webdav/ticket/ URIs in IceWarp Mail Server 12.0.3 allows remote attackers to inject arbitrary web script or HTML. |
An issue was discovered in OpenTSDB 2.3.0. There is XSS in parameter 'type' to the /suggest URI. |
An XSS issue was discovered in Inhaltsprojekte in Weblication CMS Core & Grid v12.6.24. The vulnerability is located in the `wFilemanager.php` and `index.php` files of the `/grid5/scripts/` modules. The injection point i...Show more |
An XSS issue was discovered in Sandoba CP:Shop v2016.1. The vulnerability is located in the `admin.php` file of the `./cpshop/` module. Remote attackers are able to inject their own script codes to the client-side reques...Show more |
1Anelectron 1Advanced Electron Forum Nov 21, 2024 Jun 29, 2018 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 An XSS issue was discovered in Advanced Electron Forum (AEF) v1.0.9. A persistent XSS vulnerability is located in the `FTP Link` element of the `Private Message` module. The editor of the private message module allows in...Show more |
1Zohocorp 5Firewall Analyzer Manageengine Netflow AnalyzerManageengine Network Configuration Manager+2 moreNov 21, 2024 Jun 29, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 A reflected Cross-site scripting (XSS) vulnerability in Zoho ManageEngine Netflow Analyzer before build 123137, Network Configuration Manager before build 123128, OpManager before build 123148, OpUtils before build 12316...Show more |