← Back
CWE-79

46,037 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (46,037)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Creatiwity
1Witycms
Nov 21, 2024
May 28, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Stored cross-site scripting (XSS) vulnerability in the "Website's name" field found in the "Settings" page under the "General" menu in Creatiwity wityCMS 0.6.1 allows remote attackers to inject arbitrary web script or HT...Show more
Stored cross-site scripting (XSS) vulnerability in the "Website's name" field found in the "Settings" page under the "General" menu in Creatiwity wityCMS 0.6.1 allows remote attackers to inject arbitrary web script or HTML via a crafted website name by doing an authenticated POST HTTP request to admin/settings/general.Show less
1Website Seller Script Project
1Website Seller Script
Nov 21, 2024
May 26, 2018
N/A· v4
8.8 HIGH· v3
6.0 MEDIUM· v2
PHP Scripts Mall Website Seller Script 2.0.3 has CSRF via user_submit.php?upd=2, with resultant XSS.
1Phpmywind
1Phpmywind
Nov 21, 2024
May 26, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
PHPMyWind 5.5 has XSS via the cid parameter to newsshow.php, or the query string to news.php or about.php.
1Monstra
1Monstra
Nov 21, 2024
May 25, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Monstra CMS 3.0.4 has XSS in the registration Form (i.e., the login parameter to users/registration).
1Monstra
1Monstra
Nov 21, 2024
May 25, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Monstra CMS 3.0.4 has Reflected XSS during Login (i.e., the login parameter to admin/index.php).
1Getcockpit
1Cockpit
Nov 21, 2024
May 25, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cockpit 0.5.5 has XSS via a collection, form, or region.
1Mcafee
1Network Security Manager
Nov 21, 2024
May 25, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-Site Scripting (XSS) vulnerability in the web interface in McAfee Network Security Management (NSM) before 8.2.7.42.2 allows authenticated users to allow arbitrary HTML code to be reflected in the response web page...Show more
Cross-Site Scripting (XSS) vulnerability in the web interface in McAfee Network Security Management (NSM) before 8.2.7.42.2 allows authenticated users to allow arbitrary HTML code to be reflected in the response web page via crafted user input of attributes.Show less
1Easyservice Billing Project
1Easyservice Billing
Nov 21, 2024
May 25, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The parameter q is affected by Cross-site Scripting in jobcard-ongoing.php in EasyService Billing 1.0.
1Moodle
1Moodle
Nov 21, 2024
May 25, 2018
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
An issue was discovered in Moodle 3.x. An authenticated user is allowed to add HTML blocks containing scripts to their Dashboard; this is normally not a security issue because a personal dashboard is visible to this user...Show more
An issue was discovered in Moodle 3.x. An authenticated user is allowed to add HTML blocks containing scripts to their Dashboard; this is normally not a security issue because a personal dashboard is visible to this user only. Through this security vulnerability, users can move such a block to other pages where they can be viewed by other users.Show less
1Sap
1Internet Transaction Server
Nov 21, 2024
May 24, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
SAP Internet Transaction Server (ITS) 6200.X.X has Reflected Cross Site Scripting (XSS) via certain wgate URIs. NOTE: the vendor has reportedly indicated that there will not be any further releases of this product.
1Clippercms
1Clippercms
Nov 21, 2024
May 24, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Stored cross-site scripting (XSS) vulnerability in the "Site Name" field found in the "site" tab under configurations in ClipperCMS 1.3.3 allows remote attackers to inject arbitrary web script or HTML via a crafted site...Show more
Stored cross-site scripting (XSS) vulnerability in the "Site Name" field found in the "site" tab under configurations in ClipperCMS 1.3.3 allows remote attackers to inject arbitrary web script or HTML via a crafted site name to the manager/processors/save_settings.processor.php file.Show less
1Domainmod
1Domainmod
Nov 21, 2024
May 24, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
DomainMod v4.09.03 has XSS via the assets/edit/ssl-provider-account.php sslpaid parameter.
1Domainmod
1Domainmod
Nov 21, 2024
May 24, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
DomainMod v4.09.03 has XSS via the assets/edit/account-owner.php oid parameter.
1Ilias
1Ilias
Nov 21, 2024
May 23, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
ILIAS before 5.1.26, 5.2.x before 5.2.15, and 5.3.x before 5.3.4, due to inconsistencies in parameter handling, is vulnerable to various instances of reflected cross-site-scripting.
1Microfocus
3Cms Server
Universal CmdbUniversal Cmdb Browser
Jun 17, 2026
May 23, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-Site Scripting (XSS) in Micro Focus Universal CMDB, version 10.20, 10.21, 10.22, 10.30, 10.31, 10.32, 10.33, 11.0, CMS, version 4.10, 4.11, 4.12, 4.13, 4.14, 4.15.1 and Micro Focus UCMDB Browser, version 4.10, 4.11...Show more
Cross-Site Scripting (XSS) in Micro Focus Universal CMDB, version 10.20, 10.21, 10.22, 10.30, 10.31, 10.32, 10.33, 11.0, CMS, version 4.10, 4.11, 4.12, 4.13, 4.14, 4.15.1 and Micro Focus UCMDB Browser, version 4.10, 4.11, 4.12, 4.13, 4.14, 4.15.1. This vulnerability could be remotely exploited to allow Cross-Site Scripting (XSS).Show less
1Citrix
1Xenmobile Server
Nov 21, 2024
May 23, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
There is a Cross-Site Scripting Vulnerability in Citrix XenMobile Server 10.7 before RP3.
1Dolibarr
1Dolibarr
Nov 21, 2024
May 22, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in Dolibarr before 7.0.2 allows remote attackers to inject arbitrary web script or HTML via the foruserlogin parameter to adherents/cartes/carte.php.
1Hp
2Network Automation
Network Operations Management Ultimate
Jun 17, 2026
May 22, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Persistent Cross-Site Scripting, and non-persistent HTML Injection in HP Network Operations Management Ultimate, version 2017.07, 2017.11, 2018.02 and in Network Automation, version 10.00, 10.10, 10.11, 10.20, 10.30, 10....Show more
Persistent Cross-Site Scripting, and non-persistent HTML Injection in HP Network Operations Management Ultimate, version 2017.07, 2017.11, 2018.02 and in Network Automation, version 10.00, 10.10, 10.11, 10.20, 10.30, 10.40, 10.50. This vulnerability could be remotely exploited to allow persistent cross-site scripting, and non-persistent HTML Injection.Show less
1Ckeditor
1Ckeditor 5 Link
Nov 21, 2024
May 22, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in the Link package for CKEditor 5 before 10.0.1 allows remote attackers to inject arbitrary web script through a crafted href attribute of a link (A) element.
1Joomla
1Joomla
Jun 17, 2026
May 22, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In Joomla! Core before 3.8.8, inadequate filtering of file and folder names leads to various XSS attack vectors in the media manager.