CWE-79
46,037 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (46,037)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Multiple cross-site scripting (XSS) vulnerabilities in the Caldera Forms plugin before 1.6.0-rc.1 for WordPress allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) a greeting message,...Show more |
Cross-site scripting (XSS) vulnerability in Geist WatchDog Console 3.2.2 allows remote authenticated administrators to inject arbitrary web script or HTML via a server description. |
1Ibm 1Power Hardware Management Console Nov 21, 2024 Apr 20, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 IBM Power HMC 7.1.0 through 7.8.0 and 7.3.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially lea...Show more |
iCMS V7.0.8 has XSS via the admincp.php keywords parameter in a weixin_category action, aka a WeChat Classified Management keyword search. |
A vulnerability in Cisco WebEx Connect IM could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of an affected system. The vulnerability is due to insufficient inpu...Show more |
1Cisco 1Adaptive Security Appliance Software Nov 21, 2024 Apr 19, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 A vulnerability in the Web Server Authentication Required screen of the Clientless Secure Sockets Layer (SSL) VPN portal of Cisco Adaptive Security Appliance (ASA) Software could allow an unauthenticated, remote attacker...Show more |
1Cisco 1Adaptive Security Appliance Software Nov 21, 2024 Apr 19, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 A vulnerability in the WebVPN web-based management interface of Cisco Adaptive Security Appliance could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-b...Show more |
2Ckeditor Drupal2Drupal Enhanced ImageJun 17, 2026 Apr 19, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Cross-site scripting (XSS) vulnerability in the Enhanced Image (aka image2) plugin for CKEditor (in versions 4.5.10 through 4.9.1; fixed in 4.9.2), as used in Drupal 8 before 8.4.7 and 8.5.x before 8.5.2 and other produc...Show more |
Zend Debugger in Zend Server before 9.1.3 has XSS, aka ZSR-2455. |
MiniCMS v1.10 has XSS via the mc-admin/conf.php site_link parameter. |
An issue was discovered in WUZHI CMS V4.1.0. There is a persistent XSS vulnerability that can steal the administrator cookies via the tag[tag] parameter to the index.php?m=tags&f=index&v=add&&_su=wuzhicms URI. After a we...Show more |
D-Link DIR-615 T1 devices allow XSS via the Add User feature. |
1Wicket Jquery Ui Project 1Wicket Jquery Ui Nov 21, 2024 Apr 18, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 In Apache wicket-jquery-ui <= 6.29.0, <= 7.10.1, <= 8.0.0-M9.1, JS code created in WYSIWYG editor will be executed on display. |
1Projectfloodlight 1Floodlight Nov 21, 2024 Apr 18, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Floodlight version 1.2 and earlier contains a Cross Site Scripting (XSS) vulnerability in the web console that can result in javascript injections into the web page. This attack appears to be exploitable via the victim b...Show more |
Parsedown version prior to 1.7.0 contains a Cross Site Scripting (XSS) vulnerability in `setMarkupEscaped` for escaping HTML that can result in JavaScript code execution. This attack appears to be exploitable via special...Show more |
RisingStack protect version 1.2.0 and earlier contains a Cross Site Scripting (XSS) vulnerability in isXss() function in lib/rules/xss.js that can result in dangerous XSS strings being validated as safe. This attack appe...Show more |
A Persistent XSS vulnerability exists in Kodi (formerly XBMC) through 17.6 that allows the execution of arbitrary HTML/script code in the context of the victim user's browser via a playlist. |
In Zulip Server versions before 1.7.2, there was an XSS issue with user uploads and the (default) LOCAL_UPLOADS_DIR storage backend. |
In Zulip Server versions before 1.7.2, there was an XSS issue with stream names in topic typeahead. |
In Zulip Server versions 1.5.x, 1.6.x, and 1.7.x before 1.7.2, there was an XSS issue with muting notifications. |