CWE-79
46,037 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (46,037)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Zohocorp 1Manageengine Applications Manager Nov 21, 2024 Jun 29, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 A reflected Cross-site scripting (XSS) vulnerability in Zoho ManageEngine Applications Manager before 13 (Build 13800) allows remote attackers to inject arbitrary web script or HTML via the parameter 'method' to Graphica...Show more |
1Maelostore Project 1Maelostore Nov 21, 2024 Jun 29, 2018 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 An issue was discovered CMS MaeloStore V.1.5.0. There is stored XSS in the Telephone field of the admin interface. |
An issue was discovered in OpenTSDB 2.3.0. There is XSS in parameter 'json' to the /q URI. |
A Cross-site Scripting (XSS) vulnerability in Fortinet FortiManager 6.0.0, 5.6.6 and below versions allows attacker to execute HTML/javascript code via managed remote devices CLI commands by viewing the remote device CLI...Show more |
1Ibm 1Rational Doors Next Generation Nov 21, 2024 Jun 27, 2018 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 IBM DOORS Next Generation (DNG/RRC) 6.0.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leadi...Show more |
1Craftedweb Project 1Craftedweb Nov 21, 2024 Jun 27, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 In CraftedWeb through 2013-09-24, aasp_includes/pages/notice.php allows XSS via the e parameter. |
1Joyplus Cms Project 1Joyplus Cms Nov 21, 2024 Jun 27, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 joyplus-cms 1.6.0 has XSS in admin_player.php, related to manager/index.php "system manage" and "add" actions. |
1Cyberark 1Endpoint Privilege Manager Nov 21, 2024 Jun 26, 2018 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 In CyberArk Endpoint Privilege Manager (formerly Viewfinity) 10.2.1.603, there is persistent XSS via an account name on the create token screen, the VfManager.asmx SelectAccounts->DisplayName screen, a user's groups in C...Show more |
1Easymagazine Project 1Easymagazine Nov 21, 2024 Jun 26, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 In Easy Magazine through 2012-10-26, there is XSS in the search bar of the web site. |
An XSS issue was discovered in the language switcher module in Joomla! 1.6.0 through 3.8.8 before 3.8.9. In some cases, the link of the current language might contain unescaped HTML special characters. This may lead to r...Show more |
A vulnerability has been identified in SCALANCE M875 (All versions). An attacker with access to the local file system might obtain passwords for administrative users. Successful exploitation requires read access to files...Show more |
1Siemens 1Scalance M875 Firmware Nov 21, 2024 Jun 26, 2018 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 A vulnerability has been identified in SCALANCE M875 (All versions). The web interface on port 443/tcp could allow a stored Cross-Site Scripting (XSS) attack if an unsuspecting user is tricked into accessing a malicious...Show more |
A persisted cross-site scripting vulnerability exists in Jenkins Badge Plugin 1.4 and earlier in BadgeSummaryAction.java, HtmlBadgeAction.java that allows attackers able to control build badge content to define JavaScrip...Show more |
qutebrowser version introduced in v0.11.0 (1179ee7a937fb31414d77d9970bac21095358449) contains a Cross Site Scripting (XSS) vulnerability in history command, qute://history page that can result in Via injected JavaScript...Show more |
1Ocsinventory Ng 1Ocsinventory Ng Nov 21, 2024 Jun 26, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 OCS Inventory OCS Inventory NG version ocsreports 2.4 contains a Cross Site Scripting (XSS) vulnerability in login form and search functionality that can result in An attacker is able to execute arbitrary (javascript) co...Show more |
1Veronalabs 1Wp Statistics Nov 21, 2024 Jun 26, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 WordPress version 4.8 + contains a Cross Site Scripting (XSS) vulnerability in plugins.php or core wordpress on delete function that can result in An attacker can perform client side attacks which could be from stealing...Show more |
Akiee version 0.0.3 contains a XSS leading to code execution due to the use of node integration vulnerability in "Details" of a task is not validated that can result in XSS leading to abritrary code execution. This attac...Show more |
Medis version 0.6.1 and earlier contains a XSS vulnerability evolving into code execution due to enabled nodeIntegration for the renderer process vulnerability in Key name parameter on new key creation that can result in...Show more |
Joplin version prior to 1.0.90 contains a XSS evolving into code execution due to enabled nodeIntegration for that particular BrowserWindow instance where XSS was identified from vulnerability in Note content field - inf...Show more |
Grails Fields plugin version 2.2.7 contains a Cross Site Scripting (XSS) vulnerability in Using the display tag that can result in XSS . This vulnerability appears to have been fixed in 2.2.8. |