← Back
CWE-79

46,037 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (46,037)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Backbone Project
1Backbone
Nov 21, 2024
May 31, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
backbone is a module that adds in structure to a JavaScript heavy application through key-value pairs and custom events connecting to your RESTful API through JSON There exists a potential Cross Site Scripting vulnerabil...Show more
backbone is a module that adds in structure to a JavaScript heavy application through key-value pairs and custom events connecting to your RESTful API through JSON There exists a potential Cross Site Scripting vulnerability in the `Model#Escape` function of backbone 0.3.3 and earlier, if a user is able to supply input. This is due to the regex that's replacing things to miss the conversion of things such as `<` to `<`.Show less
1Marked Project
1Marked
Nov 21, 2024
May 31, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
marked is an application that is meant to parse and compile markdown. Due to the way that marked 0.3.5 and earlier parses input, specifically HTML entities, it's possible to bypass marked's content injection protection (...Show more
marked is an application that is meant to parse and compile markdown. Due to the way that marked 0.3.5 and earlier parses input, specifically HTML entities, it's possible to bypass marked's content injection protection (`sanitize: true`) to inject a `javascript:` URL. This flaw exists because `&#xNNanything;` gets parsed to what it could and leaves the rest behind, resulting in just `anything;` being left.Show less
1Remarkable Project
1Remarkable
Nov 21, 2024
May 31, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Certain input when passed into remarkable before 1.4.1 will bypass the bad protocol check that disallows the javascript: scheme allowing for javascript: url's to be injected into the rendered content.
2Redhat
Sinatrarb
2Cloudforms
Sinatra
Nov 21, 2024
May 31, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Sinatra before 2.0.2 has XSS via the 400 Bad Request page that occurs upon a params parser exception.
1Quest
1Kace System Management Appliance
Nov 21, 2024
May 31, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The 'fmt' parameter of the '/common/run_cross_report.php' script in the the Quest KACE System Management Appliance 8.0.318 is vulnerable to cross-site scripting.
1Seacms
1Seacms
Nov 21, 2024
May 31, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
SeaCMS 6.61 has stored XSS in admin_collect.php via the siteurl parameter.
1Multidots
1Mass Pages/posts Creator
Nov 21, 2024
May 31, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
An issue was discovered in mass-pages-posts-creator.php in the MULTIDOTS Mass Pages/Posts Creator plugin 1.2.2 for WordPress. Any logged in user can launch Mass Pages/Posts creation with custom content. There is no nonce...Show more
An issue was discovered in mass-pages-posts-creator.php in the MULTIDOTS Mass Pages/Posts Creator plugin 1.2.2 for WordPress. Any logged in user can launch Mass Pages/Posts creation with custom content. There is no nonce or user capability check, so anyone can launch a DoS attack against a site and create hundreds of thousands of posts with custom content.Show less
1Clippercms
1Clippercms
Nov 21, 2024
May 31, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
ClipperCMS 1.3.3 has XSS in the "Module name" field in a "Modules -> Manage modules -> edit" action to the manager/ URI.
1Cactusthemes
1Gameplan Event And Gym Fitness
Nov 21, 2024
May 30, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Reflected XSS is possible in the GamePlan theme through 1.5.13.2 for WordPress because of insufficient input sanitization, as demonstrated by the s parameter. In some (but not all) cases, the '<' and '>' characters have...Show more
Reflected XSS is possible in the GamePlan theme through 1.5.13.2 for WordPress because of insufficient input sanitization, as demonstrated by the s parameter. In some (but not all) cases, the '<' and '>' characters have &lt; and &gt; representations.Show less
2Synacor
Zimbra
2Zimbra Collaboration Suite
Zimbra Collaboration Suite
Nov 21, 2024
May 30, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Zimbra Web Client (ZWC) in Zimbra Collaboration Suite 8.8 before 8.8.8.Patch4 and 8.7 before 8.7.11.Patch4 has Persistent XSS via a contact group.
2Misp
Misp Project
2Misp
Misp
Jun 22, 2026
May 30, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in MISP 2.4.91. A vulnerability in app/View/Elements/eventattribute.ctp allows reflected XSS if a user clicks on a malicious link for an event view and then clicks on the deleted attributes quick...Show more
An issue was discovered in MISP 2.4.91. A vulnerability in app/View/Elements/eventattribute.ctp allows reflected XSS if a user clicks on a malicious link for an event view and then clicks on the deleted attributes quick filter.Show less
1Domainmod
1Domainmod
Nov 21, 2024
May 30, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
DomainMod 4.10.0 has Stored XSS in the "/settings/profile/index.php" new_last_name parameter.
1Domainmod
1Domainmod
Nov 21, 2024
May 30, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
DomainMod 4.10.0 has Stored XSS in the "/settings/profile/index.php" new_first_name parameter.
1Yiban
1Easy Class Education Platform
Nov 21, 2024
May 30, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
YIBAN Easy class education platform 2.0 has XSS via the articlelist.php k parameter.
1Wuzhicms
1Wuzhicms
May 5, 2025
May 29, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
An issue was discovered in WUZHI CMS 4.1.0 There is a Stored XSS Vulnerability in "Account Settings -> Member Centre -> Chinese information -> Ordinary member" via a QQ number, as demonstrated by a form[qq_10]= substring...Show more
An issue was discovered in WUZHI CMS 4.1.0 There is a Stored XSS Vulnerability in "Account Settings -> Member Centre -> Chinese information -> Ordinary member" via a QQ number, as demonstrated by a form[qq_10]= substring.Show less
1Ruckussecurity
1Icx7450 48 Firmware
Nov 21, 2024
May 29, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A reflected XSS vulnerability on Ruckus ICX7450-48 devices allows remote attackers to inject arbitrary web script or HTML.
1I18next
1I18next
Nov 21, 2024
May 29, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
i18next is a language translation framework. When using the .init method, passing interpolation options without passing an escapeValue will default to undefined rather than the assumed true. This can result in a cross-si...Show more
i18next is a language translation framework. When using the .init method, passing interpolation options without passing an escapeValue will default to undefined rather than the assumed true. This can result in a cross-site scripting vulnerability because user input is assumed to be escaped, but is not. This vulnerability affects i18next 2.0.0 and later.Show less
1Ibm
1Security Guardium Big Data Intelligence
Nov 21, 2024
May 29, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
IBM Security Guardium Big Data Intelligence (SonarG) 3.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality po...Show more
IBM Security Guardium Big Data Intelligence (SonarG) 3.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 137777.Show less
1Changuondyu Advanced Statistics Project
1Changuondyu Advanced Statistics
Nov 21, 2024
May 29, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in the ChangUonDyU Advanced Statistics plugin 1.0.2 for MyBB. changstats.php has XSS, as demonstrated by a subject field.
1Moderator Log Notes Project
1Moderator Log Notes
Nov 21, 2024
May 28, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
An issue was discovered in the Moderator Log Notes plugin 1.1 for MyBB. It allows moderators to save notes and display them in a list in the modCP. The XSS is located in the mod notes textarea.