← Back
CWE-79

46,037 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (46,037)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Synology
1Note Station
Jun 17, 2026
May 9, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-site scripting (XSS) vulnerability in Attachment Preview in Synology Note Station before 2.5.1-0844 allows remote authenticated users to inject arbitrary web script or HTML via malicious attachments.
1Severalnines
1Clustercontrol
Nov 21, 2024
May 9, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Severalnines ClusterControl before 1.6.0-4699 allows XSS.
1Puppet
1Puppet Enterprise
Jun 17, 2026
May 8, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A cross-site scripting vulnerability in Puppet Enterprise Console of Puppet Enterprise allows a user to inject scripts into the Puppet Enterprise Console when using the Puppet Enterprise Console. Affected releases are Pu...Show more
A cross-site scripting vulnerability in Puppet Enterprise Console of Puppet Enterprise allows a user to inject scripts into the Puppet Enterprise Console when using the Puppet Enterprise Console. Affected releases are Puppet Puppet Enterprise: 2017.3.x versions prior to 2017.3.6.Show less
1Puppet
1Puppet Enterprise
Jun 17, 2026
May 8, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A cross-site scripting vulnerability in Puppet Enterprise Console of Puppet Enterprise allows a user to inject scripts into the Puppet Enterprise Console when using the Orchestrator. Affected releases are Puppet Puppet E...Show more
A cross-site scripting vulnerability in Puppet Enterprise Console of Puppet Enterprise allows a user to inject scripts into the Puppet Enterprise Console when using the Orchestrator. Affected releases are Puppet Puppet Enterprise: 2017.3.x versions prior to 2017.3.6.Show less
1Jenkins
1S3 Publisher
Nov 21, 2024
May 8, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A cross-site scripting vulnerability exists in Jenkins S3 Plugin 0.10.12 and older in src/main/resources/hudson/plugins/s3/S3ArtifactsProjectAction/jobMain.jelly that allows attackers able to control file names of upload...Show more
A cross-site scripting vulnerability exists in Jenkins S3 Plugin 0.10.12 and older in src/main/resources/hudson/plugins/s3/S3ArtifactsProjectAction/jobMain.jelly that allows attackers able to control file names of uploaded files to define file names containing JavaScript that would be executed in another user's browser when that user performs some UI actions.Show less
1Frogcms Project
1Frogcms
Nov 21, 2024
May 8, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
An issue was discovered in Frog CMS 0.9.5. There is a reflected Cross Site Scripting Vulnerability via the file[current_name] parameter to the admin/?/plugin/file_manager/rename URI. This can be used in conjunction with...Show more
An issue was discovered in Frog CMS 0.9.5. There is a reflected Cross Site Scripting Vulnerability via the file[current_name] parameter to the admin/?/plugin/file_manager/rename URI. This can be used in conjunction with CSRF.Show less
2Ibm
Netapp
2Cognos Analytics
Oncommand Insight
Nov 21, 2024
May 7, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM Cognos Analytics 11.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credential...Show more
IBM Cognos Analytics 11.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 138819.Show less
1Vestacp
1Control Panel
Nov 21, 2024
May 6, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in Vesta Control Panel 0.9.8-20. There is Reflected XSS via $_REQUEST['path'] to the view/file/index.php URI, which can lead to remote PHP code execution via vectors involving a file_put_contents...Show more
An issue was discovered in Vesta Control Panel 0.9.8-20. There is Reflected XSS via $_REQUEST['path'] to the view/file/index.php URI, which can lead to remote PHP code execution via vectors involving a file_put_contents call in web/upload/UploadHandler.php.Show less
1Tagregator Project
1Tagregator
Nov 21, 2024
May 5, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The Tagregator plugin 0.6 for WordPress has stored XSS via the title field in an Add New action.
1Datenstrom
1Yellow
Nov 21, 2024
May 4, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A stored XSS vulnerability was found in Datenstrom Yellow 0.7.3 via an "Edit page" action. NOTE: the vendor disputes the relevance of this report because an installation accessible to untrusted users is supposed to have...Show more
A stored XSS vulnerability was found in Datenstrom Yellow 0.7.3 via an "Edit page" action. NOTE: the vendor disputes the relevance of this report because an installation accessible to untrusted users is supposed to have parserSafeMode=1 in system/config/config.ini to prevent XSSShow less
1Tp Link
1Eap Controller
Nov 21, 2024
May 3, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Stored Cross-site scripting (XSS) vulnerability in the TP-Link EAP Controller and Omada Controller versions 2.5.4_Windows/2.6.0_Windows allows authenticated attackers to inject arbitrary web script or HTML via the userNa...Show more
Stored Cross-site scripting (XSS) vulnerability in the TP-Link EAP Controller and Omada Controller versions 2.5.4_Windows/2.6.0_Windows allows authenticated attackers to inject arbitrary web script or HTML via the userName parameter in the local user creation functionality. This is fixed in version 2.6.1_Windows.Show less
1Tp Link
1Eap Controller
Nov 21, 2024
May 3, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Stored Cross-site scripting (XSS) vulnerability in the TP-Link EAP Controller and Omada Controller versions 2.5.4_Windows/2.6.0_Windows allows authenticated attackers to inject arbitrary web script or HTML via the implem...Show more
Stored Cross-site scripting (XSS) vulnerability in the TP-Link EAP Controller and Omada Controller versions 2.5.4_Windows/2.6.0_Windows allows authenticated attackers to inject arbitrary web script or HTML via the implementation of portalPictureUpload functionality. This is fixed in version 2.6.1_Windows.Show less
1Gemalto
1Sentinel Ldk Rte
Jun 17, 2026
May 2, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The License Manager service of HASP SRM, Sentinel HASP and Sentinel LDK products prior to Sentinel LDK RTE 7.80 allows remote attackers to inject malicious web script in the logs page of Admin Control Center (ACC) for cr...Show more
The License Manager service of HASP SRM, Sentinel HASP and Sentinel LDK products prior to Sentinel LDK RTE 7.80 allows remote attackers to inject malicious web script in the logs page of Admin Control Center (ACC) for cross-site scripting (XSS) vulnerability.Show less
1Flexense
1Disksorter
Nov 21, 2024
May 2, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
XSS exists in Flexense DiskSorter Enterprise from v9.5.12 to v10.7.
1Flexense
1Vx Search
Nov 21, 2024
May 2, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
XSS exists in Flexense VX Search Enterprise from v10.1.12 to v10.7.
1Flexense
1Dupscout
Nov 21, 2024
May 2, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
XSS exists in Flexense DupScout Enterprise from v10.0.18 to v10.7.
1Flexense
1Disksavvy
Nov 21, 2024
May 2, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
XSS exists in Flexense DiskSavvy Enterprise from v10.4 to v10.7.
1Flexense
1Diskpulse
Nov 21, 2024
May 2, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
XSS exists in Flexense DiskPulse Enterprise from v10.4 to v10.7.
1Flexense
1Syncbreeze
Nov 21, 2024
May 2, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An XSS in Flexense SyncBreeze affects all versions (tested from SyncBreeze Enterprise from v10.1 to v10.7).
1Flexense
1Diskboss
Nov 21, 2024
May 2, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Flexense DiskBoss Enterprise v7.4.28 to v9.1.16 has XSS.