← Back
CWE-79

46,037 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (46,037)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Sonatype
1Nexus Repository Manager
Nov 21, 2024
Jun 11, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Sonatype Nexus Repository Manager versions 3.x before 3.12.0 has XSS in multiple areas in the Administration UI.
2Grafana
Netapp
3Active Iq Performance Analytics Services
GrafanaStoragegrid Webscale Nas Bridge
Nov 21, 2024
Jun 11, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Grafana before 5.2.0-beta1 has XSS vulnerabilities in dashboard links.
1Oecms Project
1Oecms
Nov 21, 2024
Jun 11, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A Reflected Cross-Site Scripting web vulnerability has been discovered in the OEcms v3.1 web-application. The vulnerability is located in the mod parameter of info.php.
1Dimofinf
1Dimofinf Cms
Nov 21, 2024
Jun 11, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-site scripting (XSS) vulnerability in news.php in Dimofinf CMS Version 3.0.0 allows remote attackers to inject arbitrary web script or HTML via the id parameter.
1Lamsfoundation
1Lams
Nov 21, 2024
Jun 11, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
There is unauthenticated reflected cross-site scripting (XSS) in LAMS before 3.1 that allows a remote attacker to introduce arbitrary JavaScript via manipulation of an unsanitized GET parameter during a forgotPasswordCha...Show more
There is unauthenticated reflected cross-site scripting (XSS) in LAMS before 3.1 that allows a remote attacker to introduce arbitrary JavaScript via manipulation of an unsanitized GET parameter during a forgotPasswordChange.jsp?key= password change.Show less
1Lynxtechnology
1Twonky Server
Jun 17, 2026
Jun 8, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Twonky Server before 8.5.1 has XSS via a modified "language" parameter in the Language section.
1Lynxtechnology
1Twonky Server
Jun 17, 2026
Jun 8, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Twonky Server before 8.5.1 has XSS via a folder name on the Shared Folders screen.
1Ximdex
1Ximdex
Nov 21, 2024
Jun 8, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
xfind/search in Ximdex 4.0 has XSS via the filter[n][value] parameters for non-negative values of n, as demonstrated by n equal to 0 through 12.
1Cisco
1Webex Meetings
Nov 21, 2024
Jun 7, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A vulnerability in the web framework of Cisco WebEx could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against the user of the web interface of an affected system. The vulnerab...Show more
A vulnerability in the web framework of Cisco WebEx could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against the user of the web interface of an affected system. The vulnerability is due to insufficient input validation of certain parameters that are passed to the affected software via the HTTP GET and HTTP POST methods. An attacker who can convince a user to follow an attacker-supplied link could execute arbitrary script or HTML code in the user's browser in the context of an affected site. Cisco Bug IDs: CSCvi71274.Show less
1Cisco
1Webex Meetings
Nov 21, 2024
Jun 7, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A vulnerability in the web framework of Cisco WebEx could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against the user of the web interface of an affected system. The vulnerab...Show more
A vulnerability in the web framework of Cisco WebEx could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against the user of the web interface of an affected system. The vulnerability is due to insufficient input validation of certain parameters that are passed to the affected software via the HTTP GET and HTTP POST methods. An attacker who can convince a user to follow an attacker-supplied link could execute arbitrary script or HTML code in the user's browser in the context of an affected site. Cisco Bug IDs: CSCvi63757.Show less
1Cisco
1Unity Connection
Nov 21, 2024
Jun 7, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A vulnerability in the web framework of Cisco Unity Connection could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against the user of the web interface of an affected system. T...Show more
A vulnerability in the web framework of Cisco Unity Connection could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against the user of the web interface of an affected system. The vulnerability is due to insufficient input validation of certain parameters that are passed to the affected software via the HTTP GET and HTTP POST methods. An attacker who can convince a user to follow an attacker-supplied link could execute arbitrary script or HTML code in the user's browser in the context of an affected site. Cisco Bug IDs: CSCvf76417.Show less
1Cisco
1Unified Communications Manager
Nov 21, 2024
Jun 7, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A vulnerability in the web framework of the Cisco Unified Communications Manager (Unified CM) software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against the user of the...Show more
A vulnerability in the web framework of the Cisco Unified Communications Manager (Unified CM) software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against the user of the web interface of the affected system. The vulnerability is due to insufficient input validation of certain parameters passed to the web server. An attacker could exploit this vulnerability by convincing the user to access a malicious link or by intercepting the user request and injecting certain malicious code. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected site or allow the attacker to access sensitive browser-based information. Cisco Bug IDs: CSCvj00512.Show less
1Cisco
1Identity Services Engine Software
Nov 21, 2024
Jun 7, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based...Show more
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based interface. The vulnerability is due to insufficient input validation of some parameters passed to the web-based management interface. An attacker could exploit this vulnerability by convincing a user of the interface to click a specific link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface or allow the attacker to access sensitive browser-based information. Cisco Bug IDs: CSCvf72309.Show less
1Cisco
1Integrated Management Controller Supervisor
Nov 21, 2024
Jun 7, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
A vulnerability in the web-based management interface of Cisco Integrated Management Controller Supervisor Software and Cisco UCS Director Software could allow an authenticated, remote attacker to conduct a Document Obje...Show more
A vulnerability in the web-based management interface of Cisco Integrated Management Controller Supervisor Software and Cisco UCS Director Software could allow an authenticated, remote attacker to conduct a Document Object Model-based (DOM-based), stored cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. The vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of the affected software. An attacker could exploit this vulnerability by persuading a user of the affected interface to click a malicious link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or allow the attacker to access sensitive browser-based information on the affected device. Cisco Bug IDs: CSCvh12994.Show less
1Getsymphony
1Symphony
Nov 21, 2024
Jun 7, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
content/content.blueprintspages.php in Symphony 2.7.6 has XSS via the pages content page.
1Bracket Template Project
1Bracket Template
Nov 21, 2024
Jun 7, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
bracket-template suffers from reflected XSS possible when variable passed via GET parameter is used in template
1Crud File Server Project
1Crud File Server
Nov 21, 2024
Jun 7, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
crud-file-server node module before 0.8.0 suffers from a Cross-Site Scripting vulnerability to a lack of validation of file names.
1Sencha
1Connect
Nov 21, 2024
Jun 7, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
connect node module before 2.14.0 suffers from a Cross-Site Scripting (XSS) vulnerability due to a lack of validation of file in directory.js middleware.
1Simplehttpserver Project
1Simplehttpserver
Nov 21, 2024
Jun 7, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
simplehttpserver node module suffers from a Cross-Site Scripting vulnerability to a lack of validation of file names.
1Sgin
1Xiangyun Platform
Nov 21, 2024
Jun 6, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
SGIN.CN xiangyun platform V9.4.10 has XSS via the login_url parameter to /login.php.