← Back
CWE-79

46,037 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (46,037)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Zulip
1Zulip Server
Jun 17, 2026
Apr 18, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In Zulip Server versions before 1.7.2, there were XSS issues with the frontend markdown processor.
1Mautic
1Mautic
Jun 17, 2026
Apr 18, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Mautic before v2.13.0 has stored XSS via a theme config file.
1Tibco
3Jasperreports Server
JaspersoftJaspersoft Reporting And Analytics
Jun 17, 2026
Apr 17, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The domain designer component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server for ActiveMatrix BPM, TIBCO Jaspersoft for AWS with Multi-Tenanc...Show more
The domain designer component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server for ActiveMatrix BPM, TIBCO Jaspersoft for AWS with Multi-Tenancy, and TIBCO Jaspersoft Reporting and Analytics for AWS contains a vulnerability which may allow, in the context of a non-default permissions configuration, persisted cross-site scripting (XSS) attacks. Affected releases include TIBCO Software Inc.'s TIBCO JasperReports Server: versions up to and including 6.2.4; 6.3.0; 6.3.2; 6.3.3; 6.4.0; 6.4.2, TIBCO JasperReports Server Community Edition: versions up to and including 6.4.2, TIBCO JasperReports Server for ActiveMatrix BPM: versions up to and including 6.4.2, TIBCO Jaspersoft for AWS with Multi-Tenancy: versions up to and including 6.4.2, TIBCO Jaspersoft Reporting and Analytics for AWS: versions up to and including 6.4.2.Show less
1Ibm
1Websphere Portal
Nov 21, 2024
Apr 17, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM WebSphere Portal 8.0.0 through 8.0.0.1, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality po...Show more
IBM WebSphere Portal 8.0.0 through 8.0.0.1, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 139907.Show less
1Bigtreecms
1Bigtree Cms
Nov 21, 2024
Apr 17, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in BigTree 4.2.22. There is cross-site scripting (XSS) in /core/inc/lib/less.php/test/index.php because of a $_SERVER['REQUEST_URI'] echo, as demonstrated by the dir parameter in a file=charsets a...Show more
An issue was discovered in BigTree 4.2.22. There is cross-site scripting (XSS) in /core/inc/lib/less.php/test/index.php because of a $_SERVER['REQUEST_URI'] echo, as demonstrated by the dir parameter in a file=charsets action.Show less
1Atlassian
1Jira Server
Nov 21, 2024
Apr 17, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The wiki markup component of atlassian-renderer from version 8.0.0 before version 8.0.22 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in nested wiki markup...Show more
The wiki markup component of atlassian-renderer from version 8.0.0 before version 8.0.22 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in nested wiki markup.Show less
1Catalooksupport
1.netstore
Nov 21, 2024
Apr 16, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The CATALooK.netStore module through 7.2.8 for DNN (formerly DotNetNuke) allows XSS via the /ViewEditGoogleMaps.aspx PortalID or CATSkin parameter, or the /ImageViewer.aspx link or desc parameter.
1Iscripts
1Uberforx
Nov 21, 2024
Apr 16, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
iScripts UberforX 2.2 has Stored XSS in the "manage_settings" section of the Admin Panel via a value field to the /cms?section=manage_settings&action=edit URI.
1Iscripts
1Eswap
Nov 21, 2024
Apr 16, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
iScripts eSwap v2.4 has Reflected XSS via the "catwiseproducts.php" catid parameter in the User Panel.
1Ibm
1Security Appscan
Nov 21, 2024
Apr 16, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-site scripting (XSS) vulnerability in IBM AppScan Enterprise Edition 9.0.x before 9.0.2 iFix 001 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. IBM X-Force ID: 103416.
1Xyhcms Project
1Xyhcms
Nov 21, 2024
Apr 16, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in XYHCMS 3.5. It has XSS via the test parameter to index.php.
1Cybozu
1Garoon
Nov 21, 2024
Apr 16, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-site scripting vulnerability in Cybozu Garoon 3.0.0 to 4.6.1 allows remote authenticated attackers to inject arbitrary web script or HTML via unspecified vectors.
1Cybozu
1Garoon
Nov 21, 2024
Apr 16, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-site scripting vulnerability in Cybozu Garoon 3.0.0 to 4.6.0 allows remote authenticated attackers to inject arbitrary web script or HTML via unspecified vectors.
1Cybozu
1Garoon
Nov 21, 2024
Apr 16, 2018
N/A· v4
2.7 LOW· v3
4.0 MEDIUM· v2
Cybozu Garoon 3.0.0 to 4.2.6 allows remote authenticated attackers to bypass access restriction to alter setting data of the Standard database via unspecified vectors.
1Zblogcn
1Z Blogphp
Jun 17, 2026
Apr 16, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Z-BlogPHP 1.5.1 has XSS via the zb_users/plugin/AppCentre/plugin_edit.php app_id parameter. The component must be accessed directly by an administrator, or through CSRF.
1Monstra
1Monstra
Nov 21, 2024
Apr 16, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
plugins/box/pages/pages.admin.php in Monstra CMS 3.0.4 has a stored XSS vulnerability when an attacker has access to the editor role, and enters the payload in the title section of an admin/index.php?id=pages&action=edit...Show more
plugins/box/pages/pages.admin.php in Monstra CMS 3.0.4 has a stored XSS vulnerability when an attacker has access to the editor role, and enters the payload in the title section of an admin/index.php?id=pages&action=edit_page&name=error404 (aka Edit 404 page) action.Show less
1Monstra
1Monstra
Nov 21, 2024
Apr 16, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Monstra CMS 3.0.4 has Stored XSS via the Name field on the Create New Page screen under the admin/index.php?id=pages URI, related to plugins/box/pages/pages.admin.php.
1Monstra
1Monstra
Nov 21, 2024
Apr 16, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Monstra CMS 3.0.4 has a stored XSS vulnerability when an attacker has access to the editor role, and enters the payload in the content section of a new page in the blog catalog.
1Dlink
1Dir 815 Firmware
Nov 21, 2024
Apr 16, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
D-Link DIR-815 REV. B (with firmware through DIR-815_REVB_FIRMWARE_PATCH_2.07.B01) devices have XSS in the Treturn parameter to /htdocs/webinc/js/bsc_sms_inbox.php.
1Dlink
1Dir 815 Firmware
Nov 21, 2024
Apr 16, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
D-Link DIR-815 REV. B (with firmware through DIR-815_REVB_FIRMWARE_PATCH_2.07.B01) devices have XSS in the RESULT parameter to /htdocs/webinc/js/info.php.