← Back
CWE-79

46,037 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (46,037)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Atlassian
2Crucible
Fisheye
Nov 21, 2024
Apr 24, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The /browse/~raw resource in Atlassian Fisheye and Crucible before version 4.5.3 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the handling of response h...Show more
The /browse/~raw resource in Atlassian Fisheye and Crucible before version 4.5.3 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the handling of response headers.Show less
1Phpipam
1Phpipam
Nov 21, 2024
Apr 24, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
app/tools/mac-lookup/index.php in phpIPAM 1.3.1 has Reflected XSS on /tools/mac-lookup/ via the mac parameter.
1Frogcms Project
1Frogcms
Nov 21, 2024
Apr 24, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Frog CMS 0.9.5 has a stored Cross Site Scripting Vulnerability via "Admin Site title" in Settings.
1Frogcms Project
1Frogcms
Nov 21, 2024
Apr 24, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Frog CMS 0.9.5 has XSS via the admin/?/layout/edit layout[name] parameter, aka Edit Layout.
1Frogcms Project
1Frogcms
Nov 21, 2024
Apr 24, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Frog CMS 0.9.5 has XSS via the admin/?/snippet/edit snippet[name] parameter, aka Edit Snippet.
1Frogcms Project
1Frogcms
Nov 21, 2024
Apr 24, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Frog CMS 0.9.5 has XSS via the admin/?/page/edit page[keywords] parameter, aka Edit Page Metadata.
1Wuzhicms
1Wuzhicms
May 5, 2025
Apr 24, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
WUZHI CMS 4.1.0 allows persistent XSS via the form%5Bqq_10%5D parameter to the /index.php?m=member&f=index&v=profile&set_iframe=1 URI.
1Wuzhicms
1Wuzhicms
May 5, 2025
Apr 24, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A vulnerability was discovered in WUZHI CMS 4.1.0. There is persistent XSS that allows remote attackers to inject arbitrary web script or HTML via the tag[pinyin] parameter to the /index.php?m=tags&f=index&v=add URI.
1Responsive Cookie Consent Project
1Responsive Cookie Consent
Nov 21, 2024
Apr 24, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The Responsive Cookie Consent plugin before 1.8 for WordPress mishandles number fields, leading to XSS.
1Web Dorado
1Wd Instagram Feed
Nov 21, 2024
Apr 23, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in the Web-Dorado Instagram Feed WD plugin before 1.3.1 Premium for WordPress allows remote attackers to inject arbitrary web script or HTML by passing payloads in a comment on an...Show more
Cross-site scripting (XSS) vulnerability in the Web-Dorado Instagram Feed WD plugin before 1.3.1 Premium for WordPress allows remote attackers to inject arbitrary web script or HTML by passing payloads in a comment on an Instagram post.Show less
1Web Dorado
1Wd Instagram Feed
Nov 21, 2024
Apr 23, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in the Web-Dorado Instagram Feed WD plugin before 1.3.1 for WordPress allows remote attackers to inject arbitrary web script or HTML by passing payloads in an Instagram profile's...Show more
Cross-site scripting (XSS) vulnerability in the Web-Dorado Instagram Feed WD plugin before 1.3.1 for WordPress allows remote attackers to inject arbitrary web script or HTML by passing payloads in an Instagram profile's bio.Show less
1Ultimatemember
1User Profile & Membership
Nov 21, 2024
Apr 23, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Authenticated Cross site Scripting exists in the User Profile & Membership plugin before 2.0.11 for WordPress via the "Account Deletion Custom Text" input field on the wp-admin/admin.php?page=um_options&section=account p...Show more
Authenticated Cross site Scripting exists in the User Profile & Membership plugin before 2.0.11 for WordPress via the "Account Deletion Custom Text" input field on the wp-admin/admin.php?page=um_options&section=account page.Show less
1Qnap
1Photo Station
Nov 21, 2024
Apr 23, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in QNAP NAS application Photo Station versions 5.2.7, 5.4.3, and their earlier versions could allow remote attackers to inject arbitrary web script or HTML.
1Ibm
1Cognos Business Intelligence
Nov 21, 2024
Apr 23, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
IBM Cognos Business Intelligence 10.2, 10.2.1, 10.2.1.1, and 10.2.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended funct...Show more
IBM Cognos Business Intelligence 10.2, 10.2.1, 10.2.1.1, and 10.2.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 128624.Show less
1Discuz
1Discuzx
Nov 21, 2024
Apr 22, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Discuz! DiscuzX through X3.4 has reflected XSS via forum.php?mod=post&action=newthread because data/template/1_diy_portal_view.tpl.php does not restrict the content.
1Discuz
1Discuzx
Nov 21, 2024
Apr 22, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Discuz! DiscuzX through X3.4 has stored XSS via the portal.php?mod=portalcp&ac=article URI, related to mishandling of IMG elements associated with remote images.
1Kliqqi
1Kliqqi Cms
Nov 21, 2024
Apr 22, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Kliqqi CMS 3.5.2 has XSS via a crafted group name in pligg/groups.php, a crafted Homepage string in a profile, or a crafted string in Tags or Description within pligg/submit.php.
11234n
1Minicms
Nov 21, 2024
Apr 22, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
MiniCMS V1.10 has XSS via the mc-admin/post-edit.php title parameter.
1Fastadmin
1Fastadmin
Nov 21, 2024
Apr 22, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
An issue was discovered in FastAdmin V1.0.0.20180417_beta. There is XSS via the application\api\controller\User.php avatar parameter.
1Phpipam
1Phpipam
Nov 21, 2024
Apr 21, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
app/sections/user-menu.php in phpIPAM before 1.3.1 has XSS via the ip parameter.