CWE-79
46,037 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (46,037)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Sonatype 1Nexus Repository Manager Nov 21, 2024 Jun 11, 2018 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 Sonatype Nexus Repository Manager versions 3.x before 3.12.0 has XSS in multiple areas in the Administration UI. |
2Grafana Netapp3Active Iq Performance Analytics Services GrafanaStoragegrid Webscale Nas BridgeNov 21, 2024 Jun 11, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Grafana before 5.2.0-beta1 has XSS vulnerabilities in dashboard links. |
A Reflected Cross-Site Scripting web vulnerability has been discovered in the OEcms v3.1 web-application. The vulnerability is located in the mod parameter of info.php. |
Cross-site scripting (XSS) vulnerability in news.php in Dimofinf CMS Version 3.0.0 allows remote attackers to inject arbitrary web script or HTML via the id parameter. |
There is unauthenticated reflected cross-site scripting (XSS) in LAMS before 3.1 that allows a remote attacker to introduce arbitrary JavaScript via manipulation of an unsanitized GET parameter during a forgotPasswordCha...Show more |
1Lynxtechnology 1Twonky Server Jun 17, 2026 Jun 8, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Twonky Server before 8.5.1 has XSS via a modified "language" parameter in the Language section. |
1Lynxtechnology 1Twonky Server Jun 17, 2026 Jun 8, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Twonky Server before 8.5.1 has XSS via a folder name on the Shared Folders screen. |
xfind/search in Ximdex 4.0 has XSS via the filter[n][value] parameters for non-negative values of n, as demonstrated by n equal to 0 through 12. |
A vulnerability in the web framework of Cisco WebEx could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against the user of the web interface of an affected system. The vulnerab...Show more |
A vulnerability in the web framework of Cisco WebEx could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against the user of the web interface of an affected system. The vulnerab...Show more |
A vulnerability in the web framework of Cisco Unity Connection could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against the user of the web interface of an affected system. T...Show more |
1Cisco 1Unified Communications Manager Nov 21, 2024 Jun 7, 2018 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 A vulnerability in the web framework of the Cisco Unified Communications Manager (Unified CM) software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against the user of the...Show more |
1Cisco 1Identity Services Engine Software Nov 21, 2024 Jun 7, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based...Show more |
1Cisco 1Integrated Management Controller Supervisor Nov 21, 2024 Jun 7, 2018 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 A vulnerability in the web-based management interface of Cisco Integrated Management Controller Supervisor Software and Cisco UCS Director Software could allow an authenticated, remote attacker to conduct a Document Obje...Show more |
content/content.blueprintspages.php in Symphony 2.7.6 has XSS via the pages content page. |
1Bracket Template Project 1Bracket Template Nov 21, 2024 Jun 7, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 bracket-template suffers from reflected XSS possible when variable passed via GET parameter is used in template |
1Crud File Server Project 1Crud File Server Nov 21, 2024 Jun 7, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 crud-file-server node module before 0.8.0 suffers from a Cross-Site Scripting vulnerability to a lack of validation of file names. |
connect node module before 2.14.0 suffers from a Cross-Site Scripting (XSS) vulnerability due to a lack of validation of file in directory.js middleware. |
1Simplehttpserver Project 1Simplehttpserver Nov 21, 2024 Jun 7, 2018 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 simplehttpserver node module suffers from a Cross-Site Scripting vulnerability to a lack of validation of file names. |
SGIN.CN xiangyun platform V9.4.10 has XSS via the login_url parameter to /login.php. |