← Back
CWE-79

46,037 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (46,037)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Nagios
1Fusion
Nov 21, 2024
Jun 16, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Nagios Fusion before 4.1.4 has XSS, aka TPS#13332-13335.
1Open Xchange
1Open Xchange Appsuite
Jun 17, 2026
Jun 16, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-site scripting (XSS) vulnerability in the office-web component in Open-Xchange OX App Suite before 7.8.3-rev12 and 7.8.4 before 7.8.4-rev9 allows remote attackers to inject arbitrary web script or HTML via a crafte...Show more
Cross-site scripting (XSS) vulnerability in the office-web component in Open-Xchange OX App Suite before 7.8.3-rev12 and 7.8.4 before 7.8.4-rev9 allows remote attackers to inject arbitrary web script or HTML via a crafted presentation file, related to copying content to the clipboard.Show less
1Pandorafms
1Artica Pandora Fms
Nov 21, 2024
Jun 16, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
XSS in Artica Pandora FMS before 7.0 NG 723 allows an attacker to execute arbitrary code via a crafted "refr" parameter in a "/pandora_console/index.php?sec=estado&sec2=operation/agentes/estado_agente&refr=" call.
1Open Xchange
1Open Xchange Appsuite
Nov 21, 2024
Jun 16, 2018
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
The backend component in Open-Xchange OX App Suite before 7.6.3-rev35, 7.8.x before 7.8.2-rev38, 7.8.3 before 7.8.3-rev41, and 7.8.4 before 7.8.4-rev19 allows remote authenticated users to save arbitrary user attributes...Show more
The backend component in Open-Xchange OX App Suite before 7.6.3-rev35, 7.8.x before 7.8.2-rev38, 7.8.3 before 7.8.3-rev41, and 7.8.4 before 7.8.4-rev19 allows remote authenticated users to save arbitrary user attributes by leveraging improper privilege management.Show less
1Chevereto
1Chevereto
Nov 21, 2024
Jun 15, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Chevereto Free before 1.0.13 has XSS.
1Javamelody Project
1Javamelody
Nov 21, 2024
Jun 14, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
JavaMelody through 1.60.0 has XSS via the counter parameter in a clear_counter action to the /monitoring URI.
1Seacms
1Seacms
Nov 21, 2024
Jun 14, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
SeaCMS V6.61 has XSS via the site name parameter on an adm1n/admin_config.php page (aka a system management page).
1Balbooa
1Gridbox
Nov 21, 2024
Jun 14, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Balbooa Gridbox extension version 2.4.0 and previous versions for Joomla! is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerabilit...Show more
The Balbooa Gridbox extension version 2.4.0 and previous versions for Joomla! is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability via a crafted URL to execute script in a victim's Web browser within the security context of the hosting Web site, once the URL is clicked. An attacker could use this vulnerability to steal the victim's cookie-based authentication credentials.Show less
2Hanwha Security
Samsung
10Hrd 1641 Firmware
Hrd 1642 FirmwareHrd 440 Firmware+7 more
Nov 21, 2024
Jun 14, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Web Viewer for Hanwha DVR 2.17 and Smart Viewer in Samsung Web Viewer for Samsung DVR are vulnerable to XSS via the /cgi-bin/webviewer_login_page data3 parameter. (The same Web Viewer codebase was transitioned from Samsu...Show more
Web Viewer for Hanwha DVR 2.17 and Smart Viewer in Samsung Web Viewer for Samsung DVR are vulnerable to XSS via the /cgi-bin/webviewer_login_page data3 parameter. (The same Web Viewer codebase was transitioned from Samsung to Hanwha.)Show less
1Siemens
3Scalance X 200 Firmware
Scalance X 200 Irt FirmwareScalance X300 Firmware
Nov 21, 2024
Jun 14, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A vulnerability has been identified in SCALANCE X-200 switch family (incl. SIPLUS NET variants) (All versions < V5.2.3), SCALANCE X-200IRT switch family (incl. SIPLUS NET variants) (All versions < V5.4.1), SCALANCE X-200...Show more
A vulnerability has been identified in SCALANCE X-200 switch family (incl. SIPLUS NET variants) (All versions < V5.2.3), SCALANCE X-200IRT switch family (incl. SIPLUS NET variants) (All versions < V5.4.1), SCALANCE X-200RNA switch family (All versions < V3.2.7), SCALANCE X-300 switch family (incl. X408 and SIPLUS NET variants) (All versions < V4.1.3). The integrated configuration web server of the affected devices could allow Cross-Site Scripting (XSS) attacks if unsuspecting users are tricked into accessing a malicious link. User interaction is required for a successful exploitation. The user must be logged into the web interface in order for the exploitation to succeed. At the stage of publishing this security advisory no public exploitation is known. The vendor has confirmed the vulnerability and provides mitigations to resolve it.Show less
1Siemens
3Scalance X200 Firmware
Scalance X200irt FirmwareScalance X300 Firmware
Nov 21, 2024
Jun 14, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
A vulnerability has been identified in SCALANCE X-200IRT switch family (incl. SIPLUS NET variants) (All versions < V5.4.1), SCALANCE X-200RNA switch family (All versions < V3.2.7), SCALANCE X-300 switch family (incl. X40...Show more
A vulnerability has been identified in SCALANCE X-200IRT switch family (incl. SIPLUS NET variants) (All versions < V5.4.1), SCALANCE X-200RNA switch family (All versions < V3.2.7), SCALANCE X-300 switch family (incl. X408 and SIPLUS NET variants) (All versions < V4.1.3). A remote, authenticated attacker with access to the configuration web server could be able to store script code on the web site, if the HRP redundancy option is set. This code could be executed in the web browser of victims visiting this web site (XSS), affecting its confidentiality, integrity and availability. User interaction is required for successful exploitation, as the user needs to visit the manipulated web site. At the stage of publishing this security advisory no public exploitation is known. The vendor has confirmed the vulnerability and provides mitigations to resolve it.Show less
1Blackcat Cms
1Blackcat Cms
Nov 21, 2024
Jun 14, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Cross-site scripting (XSS) vulnerability in backend/pages/modify.php in BlackCatCMS 1.3 allows remote authenticated users with the Admin role to inject arbitrary web script or HTML via the search panel.
1Microsoft
3Project Server
Sharepoint FoundationSharepoint Server
Jun 17, 2026
Jun 14, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint Elevation of Privileg...Show more
An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint Elevation of Privilege Vulnerability." This affects Microsoft Project Server, Microsoft SharePoint. This CVE ID is unique from CVE-2018-8252.Show less
1Microsoft
2Sharepoint Foundation
Sharepoint Server
Jun 17, 2026
Jun 14, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint Elevation of Privileg...Show more
An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint Elevation of Privilege Vulnerability." This affects Microsoft SharePoint. This CVE ID is unique from CVE-2018-8254.Show less
1Microsoft
2Office Online Server
Office Web Apps
Jun 17, 2026
Jun 14, 2018
N/A· v4
5.4 MEDIUM· v3
5.8 MEDIUM· v2
An elevation of privilege vulnerability exists when Office Web Apps Server 2013 and Office Online Server fail to properly handle web requests, aka "Microsoft Office Elevation of Privilege Vulnerability." This affects Mic...Show more
An elevation of privilege vulnerability exists when Office Web Apps Server 2013 and Office Online Server fail to properly handle web requests, aka "Microsoft Office Elevation of Privilege Vulnerability." This affects Microsoft Office, Microsoft Office Online Server. This CVE ID is unique from CVE-2018-8245.Show less
1Eng
1Knowage
Nov 21, 2024
Jun 13, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Knowage (formerly SpagoBI) 6.1.1 allows XSS via the name or description field to the "Olap Schemas' Catalogue" catalogue.
1Knowage Suite
1Knowage
Nov 21, 2024
Jun 13, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Knowage (formerly SpagoBI) 6.1.1 allows XSS via the name field to the "Business Model's Catalogue" catalogue.
1Sensiolabs
1Symfony
Nov 21, 2024
Jun 13, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Reflected Cross-site scripting (XSS) vulnerability in the web profiler in SensioLabs Symfony 3.3.6 allows remote attackers to inject arbitrary web script or HTML via the "file" parameter, aka an _profiler/open?file= URI....Show more
Reflected Cross-site scripting (XSS) vulnerability in the web profiler in SensioLabs Symfony 3.3.6 allows remote attackers to inject arbitrary web script or HTML via the "file" parameter, aka an _profiler/open?file= URI. NOTE: The vendor states "The XSS ... is in the web profiler, a tool that should never be deployed in production (so, we don't handle those issues as security issues).Show less
1Articlecms Project
1Articlecms
Nov 21, 2024
Jun 13, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
ArticleCMS through 2017-02-19 has XSS via an "add an article" action.
1Igniterealtime
1Openfire
Nov 21, 2024
Jun 13, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Ignite Realtime Openfire before 3.9.2 is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability via a crafted URL to execute script in...Show more
Ignite Realtime Openfire before 3.9.2 is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability via a crafted URL to execute script in a victim's Web browser within the security context of the hosting Web site, once the URL is clicked. An attacker could use this vulnerability to steal the victim's cookie-based authentication credentials.Show less