CWE-79
46,037 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (46,037)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Stored cross-site scripting (XSS) vulnerability in the "Website's name" field found in the "Settings" page under the "General" menu in Creatiwity wityCMS 0.6.1 allows remote attackers to inject arbitrary web script or HT...Show more |
1Website Seller Script Project 1Website Seller Script Nov 21, 2024 May 26, 2018 N/A· v4 8.8 HIGH· v3 6.0 MEDIUM· v2 PHP Scripts Mall Website Seller Script 2.0.3 has CSRF via user_submit.php?upd=2, with resultant XSS. |
PHPMyWind 5.5 has XSS via the cid parameter to newsshow.php, or the query string to news.php or about.php. |
Monstra CMS 3.0.4 has XSS in the registration Form (i.e., the login parameter to users/registration). |
Monstra CMS 3.0.4 has Reflected XSS during Login (i.e., the login parameter to admin/index.php). |
Cockpit 0.5.5 has XSS via a collection, form, or region. |
1Mcafee 1Network Security Manager Nov 21, 2024 May 25, 2018 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 Cross-Site Scripting (XSS) vulnerability in the web interface in McAfee Network Security Management (NSM) before 8.2.7.42.2 allows authenticated users to allow arbitrary HTML code to be reflected in the response web page...Show more |
1Easyservice Billing Project 1Easyservice Billing Nov 21, 2024 May 25, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The parameter q is affected by Cross-site Scripting in jobcard-ongoing.php in EasyService Billing 1.0. |
An issue was discovered in Moodle 3.x. An authenticated user is allowed to add HTML blocks containing scripts to their Dashboard; this is normally not a security issue because a personal dashboard is visible to this user...Show more |
1Sap 1Internet Transaction Server Nov 21, 2024 May 24, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 SAP Internet Transaction Server (ITS) 6200.X.X has Reflected Cross Site Scripting (XSS) via certain wgate URIs. NOTE: the vendor has reportedly indicated that there will not be any further releases of this product. |
Stored cross-site scripting (XSS) vulnerability in the "Site Name" field found in the "site" tab under configurations in ClipperCMS 1.3.3 allows remote attackers to inject arbitrary web script or HTML via a crafted site...Show more |
DomainMod v4.09.03 has XSS via the assets/edit/ssl-provider-account.php sslpaid parameter. |
DomainMod v4.09.03 has XSS via the assets/edit/account-owner.php oid parameter. |
ILIAS before 5.1.26, 5.2.x before 5.2.15, and 5.3.x before 5.3.4, due to inconsistencies in parameter handling, is vulnerable to various instances of reflected cross-site-scripting. |
1Microfocus 3Cms Server Universal CmdbUniversal Cmdb BrowserJun 17, 2026 May 23, 2018 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 Cross-Site Scripting (XSS) in Micro Focus Universal CMDB, version 10.20, 10.21, 10.22, 10.30, 10.31, 10.32, 10.33, 11.0, CMS, version 4.10, 4.11, 4.12, 4.13, 4.14, 4.15.1 and Micro Focus UCMDB Browser, version 4.10, 4.11...Show more |
There is a Cross-Site Scripting Vulnerability in Citrix XenMobile Server 10.7 before RP3. |
Cross-site scripting (XSS) vulnerability in Dolibarr before 7.0.2 allows remote attackers to inject arbitrary web script or HTML via the foruserlogin parameter to adherents/cartes/carte.php. |
1Hp 2Network Automation Network Operations Management UltimateJun 17, 2026 May 22, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Persistent Cross-Site Scripting, and non-persistent HTML Injection in HP Network Operations Management Ultimate, version 2017.07, 2017.11, 2018.02 and in Network Automation, version 10.00, 10.10, 10.11, 10.20, 10.30, 10....Show more |
Cross-site scripting (XSS) vulnerability in the Link package for CKEditor 5 before 10.0.1 allows remote attackers to inject arbitrary web script through a crafted href attribute of a link (A) element. |
In Joomla! Core before 3.8.8, inadequate filtering of file and folder names leads to various XSS attack vectors in the media manager. |