CWE-79
46,037 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (46,037)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
backbone is a module that adds in structure to a JavaScript heavy application through key-value pairs and custom events connecting to your RESTful API through JSON There exists a potential Cross Site Scripting vulnerabil...Show more |
marked is an application that is meant to parse and compile markdown. Due to the way that marked 0.3.5 and earlier parses input, specifically HTML entities, it's possible to bypass marked's content injection protection (...Show more |
1Remarkable Project 1Remarkable Nov 21, 2024 May 31, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Certain input when passed into remarkable before 1.4.1 will bypass the bad protocol check that disallows the javascript: scheme allowing for javascript: url's to be injected into the rendered content. |
2Redhat Sinatrarb2Cloudforms SinatraNov 21, 2024 May 31, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Sinatra before 2.0.2 has XSS via the 400 Bad Request page that occurs upon a params parser exception. |
1Quest 1Kace System Management Appliance Nov 21, 2024 May 31, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The 'fmt' parameter of the '/common/run_cross_report.php' script in the the Quest KACE System Management Appliance 8.0.318 is vulnerable to cross-site scripting. |
SeaCMS 6.61 has stored XSS in admin_collect.php via the siteurl parameter. |
1Multidots 1Mass Pages/posts Creator Nov 21, 2024 May 31, 2018 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 An issue was discovered in mass-pages-posts-creator.php in the MULTIDOTS Mass Pages/Posts Creator plugin 1.2.2 for WordPress. Any logged in user can launch Mass Pages/Posts creation with custom content. There is no nonce...Show more |
ClipperCMS 1.3.3 has XSS in the "Module name" field in a "Modules -> Manage modules -> edit" action to the manager/ URI. |
1Cactusthemes 1Gameplan Event And Gym Fitness Nov 21, 2024 May 30, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Reflected XSS is possible in the GamePlan theme through 1.5.13.2 for WordPress because of insufficient input sanitization, as demonstrated by the s parameter. In some (but not all) cases, the '<' and '>' characters have...Show more |
2Synacor Zimbra2Zimbra Collaboration Suite Zimbra Collaboration SuiteNov 21, 2024 May 30, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Zimbra Web Client (ZWC) in Zimbra Collaboration Suite 8.8 before 8.8.8.Patch4 and 8.7 before 8.7.11.Patch4 has Persistent XSS via a contact group. |
An issue was discovered in MISP 2.4.91. A vulnerability in app/View/Elements/eventattribute.ctp allows reflected XSS if a user clicks on a malicious link for an event view and then clicks on the deleted attributes quick...Show more |
DomainMod 4.10.0 has Stored XSS in the "/settings/profile/index.php" new_last_name parameter. |
DomainMod 4.10.0 has Stored XSS in the "/settings/profile/index.php" new_first_name parameter. |
1Yiban 1Easy Class Education Platform Nov 21, 2024 May 30, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 YIBAN Easy class education platform 2.0 has XSS via the articlelist.php k parameter. |
An issue was discovered in WUZHI CMS 4.1.0 There is a Stored XSS Vulnerability in "Account Settings -> Member Centre -> Chinese information -> Ordinary member" via a QQ number, as demonstrated by a form[qq_10]= substring...Show more |
1Ruckussecurity 1Icx7450 48 Firmware Nov 21, 2024 May 29, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 A reflected XSS vulnerability on Ruckus ICX7450-48 devices allows remote attackers to inject arbitrary web script or HTML. |
i18next is a language translation framework. When using the .init method, passing interpolation options without passing an escapeValue will default to undefined rather than the assumed true. This can result in a cross-si...Show more |
1Ibm 1Security Guardium Big Data Intelligence Nov 21, 2024 May 29, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 IBM Security Guardium Big Data Intelligence (SonarG) 3.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality po...Show more |
1Changuondyu Advanced Statistics Project 1Changuondyu Advanced Statistics Nov 21, 2024 May 29, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in the ChangUonDyU Advanced Statistics plugin 1.0.2 for MyBB. changstats.php has XSS, as demonstrated by a subject field. |
1Moderator Log Notes Project 1Moderator Log Notes Nov 21, 2024 May 28, 2018 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 An issue was discovered in the Moderator Log Notes plugin 1.1 for MyBB. It allows moderators to save notes and display them in a list in the modCP. The XSS is located in the mod notes textarea. |