CWE-79
46,037 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (46,037)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Nagios Fusion before 4.1.4 has XSS, aka TPS#13332-13335. |
1Open Xchange 1Open Xchange Appsuite Jun 17, 2026 Jun 16, 2018 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 Cross-site scripting (XSS) vulnerability in the office-web component in Open-Xchange OX App Suite before 7.8.3-rev12 and 7.8.4 before 7.8.4-rev9 allows remote attackers to inject arbitrary web script or HTML via a crafte...Show more |
1Pandorafms 1Artica Pandora Fms Nov 21, 2024 Jun 16, 2018 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 XSS in Artica Pandora FMS before 7.0 NG 723 allows an attacker to execute arbitrary code via a crafted "refr" parameter in a "/pandora_console/index.php?sec=estado&sec2=operation/agentes/estado_agente&refr=" call. |
1Open Xchange 1Open Xchange Appsuite Nov 21, 2024 Jun 16, 2018 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 The backend component in Open-Xchange OX App Suite before 7.6.3-rev35, 7.8.x before 7.8.2-rev38, 7.8.3 before 7.8.3-rev41, and 7.8.4 before 7.8.4-rev19 allows remote authenticated users to save arbitrary user attributes...Show more |
Chevereto Free before 1.0.13 has XSS. |
1Javamelody Project 1Javamelody Nov 21, 2024 Jun 14, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 JavaMelody through 1.60.0 has XSS via the counter parameter in a clear_counter action to the /monitoring URI. |
SeaCMS V6.61 has XSS via the site name parameter on an adm1n/admin_config.php page (aka a system management page). |
The Balbooa Gridbox extension version 2.4.0 and previous versions for Joomla! is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerabilit...Show more |
2Hanwha Security Samsung10Hrd 1641 Firmware Hrd 1642 FirmwareHrd 440 Firmware+7 moreNov 21, 2024 Jun 14, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Web Viewer for Hanwha DVR 2.17 and Smart Viewer in Samsung Web Viewer for Samsung DVR are vulnerable to XSS via the /cgi-bin/webviewer_login_page data3 parameter. (The same Web Viewer codebase was transitioned from Samsu...Show more |
1Siemens 3Scalance X 200 Firmware Scalance X 200 Irt FirmwareScalance X300 FirmwareNov 21, 2024 Jun 14, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 A vulnerability has been identified in SCALANCE X-200 switch family (incl. SIPLUS NET variants) (All versions < V5.2.3), SCALANCE X-200IRT switch family (incl. SIPLUS NET variants) (All versions < V5.4.1), SCALANCE X-200...Show more |
1Siemens 3Scalance X200 Firmware Scalance X200irt FirmwareScalance X300 FirmwareNov 21, 2024 Jun 14, 2018 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 A vulnerability has been identified in SCALANCE X-200IRT switch family (incl. SIPLUS NET variants) (All versions < V5.4.1), SCALANCE X-200RNA switch family (All versions < V3.2.7), SCALANCE X-300 switch family (incl. X40...Show more |
Cross-site scripting (XSS) vulnerability in backend/pages/modify.php in BlackCatCMS 1.3 allows remote authenticated users with the Admin role to inject arbitrary web script or HTML via the search panel. |
1Microsoft 3Project Server Sharepoint FoundationSharepoint ServerJun 17, 2026 Jun 14, 2018 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint Elevation of Privileg...Show more |
1Microsoft 2Sharepoint Foundation Sharepoint ServerJun 17, 2026 Jun 14, 2018 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint Elevation of Privileg...Show more |
1Microsoft 2Office Online Server Office Web AppsJun 17, 2026 Jun 14, 2018 N/A· v4 5.4 MEDIUM· v3 5.8 MEDIUM· v2 An elevation of privilege vulnerability exists when Office Web Apps Server 2013 and Office Online Server fail to properly handle web requests, aka "Microsoft Office Elevation of Privilege Vulnerability." This affects Mic...Show more |
Knowage (formerly SpagoBI) 6.1.1 allows XSS via the name or description field to the "Olap Schemas' Catalogue" catalogue. |
Knowage (formerly SpagoBI) 6.1.1 allows XSS via the name field to the "Business Model's Catalogue" catalogue. |
Reflected Cross-site scripting (XSS) vulnerability in the web profiler in SensioLabs Symfony 3.3.6 allows remote attackers to inject arbitrary web script or HTML via the "file" parameter, aka an _profiler/open?file= URI....Show more |
1Articlecms Project 1Articlecms Nov 21, 2024 Jun 13, 2018 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 ArticleCMS through 2017-02-19 has XSS via an "add an article" action. |
Ignite Realtime Openfire before 3.9.2 is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability via a crafted URL to execute script in...Show more |