← Back
CWE-79

46,037 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (46,037)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Jenkins
1Groovy Postbuild
Nov 21, 2024
Jun 5, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A persisted cross-site scripting vulnerability exists in Jenkins Groovy Postbuild Plugin 2.3.1 and older in various Jelly files that allows attackers able to control build badge content to define JavaScript that would be...Show more
A persisted cross-site scripting vulnerability exists in Jenkins Groovy Postbuild Plugin 2.3.1 and older in various Jelly files that allows attackers able to control build badge content to define JavaScript that would be executed in another user's browser when that other user performs some UI actions.Show less
1Qnap
1Nas Proxy Server
Nov 21, 2024
Jun 5, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in QNAP NAS application Proxy Server through version 1.2.0 allows remote attackers to inject arbitrary web script or HTML.
1Synology
1Office
Jun 17, 2026
Jun 5, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-site scripting (XSS) vulnerability in Title Tootip in Synology Office before 3.0.3-2143 allows remote authenticated users to inject arbitrary web script or HTML via the malicious file name.
1Synology
1File Station
Jun 17, 2026
Jun 5, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-site scripting (XSS) vulnerability in Attachment Preview in Synology File Station before 1.1.4-0122 allows remote authenticated users to inject arbitrary web script or HTML via malicious attachments.
1Manageengine
1Applications Manager
Nov 21, 2024
Jun 5, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
ManageEngine Applications Manager versions 12 and 13 before build 13200 suffer from a Reflected Cross-Site Scripting vulnerability. Applications Manager is prone to a Cross-Site Scripting vulnerability in parameter LIMIT...Show more
ManageEngine Applications Manager versions 12 and 13 before build 13200 suffer from a Reflected Cross-Site Scripting vulnerability. Applications Manager is prone to a Cross-Site Scripting vulnerability in parameter LIMIT, in URL path /DiagAlertAction.do?REQTYPE=AJAX&LIMIT=1233. The URL is also available without authentication.Show less
1Ximdex
1Ximdex
Nov 21, 2024
Jun 5, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
index.php?action=createaccount in Ximdex 4.0 has XSS via the sname or fname parameter.
1Nzedb
1Nzedb
Nov 21, 2024
Jun 5, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
nZEDb v0.7.3.3 has XSS in the 404 error page.
1Morris.js Project
1Morris.js
Nov 21, 2024
Jun 4, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Morris.js creates an svg graph, with labels that appear when hovering over a point. The hovering label names are not escaped in versions 0.5.0 and earlier. If control over the labels is obtained, script can be injected....Show more
Morris.js creates an svg graph, with labels that appear when hovering over a point. The hovering label names are not escaped in versions 0.5.0 and earlier. If control over the labels is obtained, script can be injected. The script will run on the client side whenever that specific graph is loaded.Show less
1Gitbook
1Gitbook
Nov 21, 2024
Jun 4, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
GitBook is a command line tool (and Node.js library) for building beautiful books using GitHub/Git and Markdown (or AsciiDoc). Stored Cross-Site-Scripting (XSS) is possible in GitBook before 3.2.2 by including code outsi...Show more
GitBook is a command line tool (and Node.js library) for building beautiful books using GitHub/Git and Markdown (or AsciiDoc). Stored Cross-Site-Scripting (XSS) is possible in GitBook before 3.2.2 by including code outside of backticks in any ebook. This code will be executed on the online reader.Show less
1Restify
1Restify
Nov 21, 2024
Jun 4, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Restify is a framework for building REST APIs. Restify >=2.0.0 <=4.0.4 using URL encoded script tags in a non-existent URL, an attacker can get script to run in some browsers.
1Punkave
1Sanitize Html
Nov 21, 2024
Jun 4, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
sanitize-html is a library for scrubbing html input for malicious values Versions 1.2.2 and below have a cross site scripting vulnerability.
1Punkave
1Sanitize Html
Nov 21, 2024
Jun 4, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Sanitize-html is a library for scrubbing html input of malicious values. Versions 1.11.1 and below are vulnerable to cross site scripting (XSS) in certain scenarios: If allowed at least one nonTextTags, the result is a p...Show more
Sanitize-html is a library for scrubbing html input of malicious values. Versions 1.11.1 and below are vulnerable to cross site scripting (XSS) in certain scenarios: If allowed at least one nonTextTags, the result is a potential XSS vulnerability.Show less
1Forms Project
1Forms
Nov 21, 2024
Jun 4, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Forms is a library for easily creating HTML forms. Versions before 1.3.0 did not have proper html escaping. This means that if the application did not sanitize html on behalf of forms, use of forms may be vulnerable to c...Show more
Forms is a library for easily creating HTML forms. Versions before 1.3.0 did not have proper html escaping. This means that if the application did not sanitize html on behalf of forms, use of forms may be vulnerable to cross site scriptingShow less
1Ag Grid
1Ag Grid
Nov 21, 2024
Jun 4, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
ag-grid is an advanced data grid that is library agnostic. ag-grid is vulnerable to Cross-site Scripting (XSS) via Angular Expressions, if AngularJS is used in combination with ag-grid.
1I18next
1I18next
Nov 21, 2024
Jun 4, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
i18next is a language translation framework. Because of how the interpolation is implemented, making replacements from the dictionary one at a time, untrusted user input can use the name of one of the dictionary keys to...Show more
i18next is a language translation framework. Because of how the interpolation is implemented, making replacements from the dictionary one at a time, untrusted user input can use the name of one of the dictionary keys to inject script into the browser. This affects i18next <=1.10.2.Show less
1Remarkable Project
1Remarkable
Nov 21, 2024
Jun 4, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Remarkable is a markdown parser. In versions 1.6.2 and lower, remarkable allows the use of `data:` URIs in links and can therefore execute javascript.
1Html Janitor Project
1Html Janitor
Nov 21, 2024
Jun 4, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
html-janitor node module suffers from a Cross-Site Scripting (XSS) vulnerability via clean() accepting user-controlled values.
1Recent Threads Project
1Recent Threads
Nov 21, 2024
Jun 4, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The Recent Threads plugin before 1.1 for MyBB allows XSS via a thread subject.
1Gvectors
1Wpforo Forum
Nov 21, 2024
Jun 4, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
wpforo_get_request_uri in wpf-includes/functions.php in the wpForo Forum plugin before 1.4.12 for WordPress allows Unauthenticated Reflected Cross-Site Scripting (XSS) via the URI.
1Pagekit
1Pagekit
Nov 21, 2024
Jun 2, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Stored XSS in YOOtheme Pagekit 1.0.13 and earlier allows a user to upload malicious code via the picture upload feature. A user with elevated privileges could upload a photo to the system in an SVG format. This file will...Show more
Stored XSS in YOOtheme Pagekit 1.0.13 and earlier allows a user to upload malicious code via the picture upload feature. A user with elevated privileges could upload a photo to the system in an SVG format. This file will be uploaded to the system and it will not be stripped or filtered. The user can create a link on the website pointing to "/storage/poc.svg" that will point to http://localhost/pagekit/storage/poc.svg. When a user comes along to click that link, it will trigger a XSS attack.Show less