CWE-79
46,037 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (46,037)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
mao10cms 6 allows XSS via the m=bbs&a=index page. |
Reflected Cross-Site Scripting (XSS) exists in the Stock Take module in SLiMS 8 Akasia 8.3.1 via an admin/modules/stock_take/index.php?keywords= URI. |
1Slims Akasia Project 1Slims Akasia Nov 21, 2024 Jun 22, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Reflected Cross-Site Scripting (XSS) exists in the Master File module in SLiMS 8 Akasia 8.3.1 via an admin/modules/master_file/rda_cmc.php?keywords= URI. |
1Slims Akasia Project 1Slims Akasia Nov 21, 2024 Jun 22, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Reflected Cross-Site Scripting (XSS) exists in the Membership module in SLiMS 8 Akasia 8.3.1 via an admin/modules/membership/index.php?keywords= URI. |
1Slims Akasia Project 1Slims Akasia Nov 21, 2024 Jun 22, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Reflected Cross-Site Scripting (XSS) exists in the Circulation module in SLiMS 8 Akasia 8.3.1 via an admin/modules/circulation/loan_rules.php?keywords= URI, a related issue to CVE-2017-7242. |
1Slims Akasia Project 1Slims Akasia Nov 21, 2024 Jun 22, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Reflected Cross-Site Scripting (XSS) exists in the Bibliography module in SLiMS 8 Akasia 8.3.1 via an admin/modules/bibliography/index.php?keywords= URI. |
An issue was discovered in js/designer/move.js in phpMyAdmin before 4.8.2. A Cross-Site Scripting vulnerability has been found where an attacker can use a crafted database name to trigger an XSS attack when that database...Show more |
1Microfocus 1Solutions Business Manager Jun 17, 2026 Jun 21, 2018 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 Micro Focus Solutions Business Manager versions prior to 11.4 allows JavaScript to be embedded in URLs placed in "Favorites" folder. If the user has certain administrative privileges then this vulnerability can impact ot...Show more |
1Microfocus 1Solutions Business Manager Jun 17, 2026 Jun 21, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Micro Focus Solutions Business Manager versions prior to 11.4 can reflect back HTTP header values. |
1Emc 1Rsa Authentication Manager Nov 21, 2024 Jun 21, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 RSA Authentication Manager Security Console, versions 8.3 P1 and earlier, contains a reflected cross-site scripting vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability by trickin...Show more |
1Emc 1Rsa Authentication Manager Nov 21, 2024 Jun 21, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 RSA Authentication Manager Operation Console, versions 8.3 P1 and earlier, contains a stored cross-site scripting vulnerability. A malicious Operations Console administrator could potentially exploit this vulnerability t...Show more |
Cross-site scripting (XSS) vulnerability in App Center in QNAP QTS 4.2.6 build 20171208, QTS 4.3.3 build 20171213, QTS 4.3.4 build 20171223, and their earlier versions could allow remote attackers to inject Javascript co...Show more |
On D-Link DIR-620 devices with a certain customized (by ISP) variant of firmware 1.0.3, 1.0.37, 1.3.1, 1.3.3, 1.3.7, 1.4.0, and 2.0.22, a reflected Cross-Site Scripting (XSS) attack is possible as a result of missed filt...Show more |
CheckSec Canopy 3.x before 3.0.7 has stored XSS via the Login Page Disclaimer, allowing attacks by low-privileged users against higher-privileged users. |
1Public Knowledge Project 1Open Monograph Press Nov 21, 2024 Jun 19, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Cross-site scripting (XSS) vulnerability in templates/frontend/pages/searchResults.tpl in Public Knowledge Project (PKP) Open Monograph Press (OMP) v1.2.0 through 3.1.1-2 before 3.1.1-3 allows remote attackers to inject...Show more |
1Dragonbyte Tech 1Vbsecurity Nov 21, 2024 Jun 19, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 library/DBTech/Security/Action/Sessions.php in DragonByte vBSecurity 3.x through 3.3.0 for vBulletin 3 and vBulletin 4 allows self-XSS via $session['user_agent'] in the "Login Sessions" feature. |
1Ca 1Ca Privileged Access Manager Jun 17, 2026 Jun 18, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 A reflected cross-site scripting vulnerability in CA Privileged Access Manager 2.x allows remote attackers to execute malicious script with a specially crafted link. |
Cross-site scripting (XSS) vulnerability in Airbnb Knowledge Repo 0.7.4 allows remote attackers to inject arbitrary web scripts or HTML via the post comments functionality, as demonstrated by the post/posts/new_report.kp...Show more |
An issue was discovered on Eminent EM4544 9.10 devices. The device does not require the user's current password to set a new one within the web interface. Therefore, it is possible to exploit this issue (e.g., in combina...Show more |
1Oauth2orize Fprm Project 1Oauth2orize Fprm Nov 21, 2024 Jun 17, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 index.js in oauth2orize-fprm before 0.2.1 has XSS via a crafted URL. |