← Back
CWE-79

46,037 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (46,037)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Debian
Wordpress
2Debian Linux
Wordpress
Nov 21, 2024
Apr 16, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Before WordPress 4.9.5, the version string was not escaped in the get_the_generator function, and could lead to XSS in a generator tag.
1Smartscriptsolutions
1Domain Trader
Nov 21, 2024
Apr 16, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
XSS exists in Domain Trader 2.5.3 via the recoverlogin.php email_address parameter.
1Jenkins
1Jenkins
Nov 21, 2024
Apr 16, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A cross-site scripting vulnerability exists in Jenkins 2.115 and older, LTS 2.107.1 and older, in confirmationList.jelly and stopButton.jelly that allows attackers with Job/Configure and/or Job/Create permission to creat...Show more
A cross-site scripting vulnerability exists in Jenkins 2.115 and older, LTS 2.107.1 and older, in confirmationList.jelly and stopButton.jelly that allows attackers with Job/Configure and/or Job/Create permission to create an item name containing JavaScript that would be executed in another user's browser when that other user performs some UI actions.Show less
1Joyplus Cms Project
1Joyplus Cms
Nov 21, 2024
Apr 13, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
joyplus-cms 1.6.0 has XSS via the device_name parameter in a manager/admin_ajax.php?action=save flag=add request.
2Debian
Mediawiki
2Debian Linux
Mediawiki
Nov 21, 2024
Apr 13, 2018
N/A· v4
4.7 MEDIUM· v3
2.6 LOW· v2
Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a XSS vulnerability in SearchHighlighter::highlightText() with non-default configurations.
1Vmware
1Vrealize Automation
Jun 17, 2026
Apr 13, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
VMware vRealize Automation (vRA) prior to 7.3.1 contains a vulnerability that may allow for a DOM-based cross-site scripting (XSS) attack. Exploitation of this issue may lead to the compromise of the vRA user's workstati...Show more
VMware vRealize Automation (vRA) prior to 7.3.1 contains a vulnerability that may allow for a DOM-based cross-site scripting (XSS) attack. Exploitation of this issue may lead to the compromise of the vRA user's workstation.Show less
1Student Profile Management System Script Project
1Student Profile Management System Script
Jun 17, 2026
Apr 12, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
PHP Scripts Mall Student Profile Management System Script v2.0.6 has XSS via the Name field to list_student.php.
1Car Rental Script Project
1Car Rental Script
Jun 17, 2026
Apr 12, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
PHP Scripts Mall Car Rental Script 2.0.8 has XSS via the User Name field in an Edit Profile action.
1Image Sharing Script Project
1Image Sharing Script
Jun 17, 2026
Apr 12, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
PHP Scripts Mall Image Sharing Script 1.3.3 has XSS via the Full Name field in an Edit Profile action.
1Website Broker Script Project
1Website Broker Script
Jun 17, 2026
Apr 12, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
PHP Scripts Mall Website Broker Script 3.0.6 has XSS via the Last Name field on the My Profile page.
1Website Seller Script Project
1Website Seller Script
Jun 17, 2026
Apr 12, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Reflected XSS exists in PHP Scripts Mall Website Seller Script 2.0.3 via the Listings Search feature.
1Ibm
1Forms Experience Builder
Nov 21, 2024
Apr 12, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-site scripting (XSS) vulnerability in IBM Forms Experience Builder 8.5.0 and 8.5.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. IBM X-Force ID: 97777.
1Joyplus Cms Project
1Joyplus Cms
Nov 21, 2024
Apr 12, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
joyplus-cms 1.6.0 has XSS in manager/admin_vod.php via the keyword parameter.
1Jdownloads
1Jdownloads
Nov 21, 2024
Apr 12, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The jDownloads extension before 3.2.59 for Joomla! has XSS.
2Cacti
Debian
2Cacti
Debian Linux
Nov 21, 2024
Apr 12, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cacti before 1.1.37 has XSS because it makes certain htmlspecialchars calls without the ENT_QUOTES flag (these calls occur when the html_escape function in lib/html.php is not used).
2Cacti
Debian
2Cacti
Debian Linux
Nov 21, 2024
Apr 12, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cacti before 1.1.37 has XSS because it does not properly reject unintended characters, related to use of the sanitize_uri function in lib/functions.php.
1Cacti
1Cacti
Nov 21, 2024
Apr 12, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cacti before 1.1.37 has XSS because the get_current_page function in lib/functions.php relies on $_SERVER['PHP_SELF'] instead of $_SERVER['SCRIPT_NAME'] to determine a page name.
1Open Audit
1Open Audit
Jun 17, 2026
Apr 12, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-site scripting (XSS) vulnerability in Open-AudIT Professional 2.1.1 allows remote attackers to inject arbitrary web script or HTML via a crafted name of a component, as demonstrated by the Admin->Logs section (with...Show more
Cross-site scripting (XSS) vulnerability in Open-AudIT Professional 2.1.1 allows remote attackers to inject arbitrary web script or HTML via a crafted name of a component, as demonstrated by the Admin->Logs section (with a logs?logs.type= URI) and the Manage->Attributes section (via the "Name (display)" field to the attributes/create URI).Show less
1Ibm
2Rational Doors Next Generation
Rational Requirements Composer
Nov 21, 2024
Apr 12, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM DOORS Next Generation (DNG/RRC) 5.0, 5.0.1, 5.0.2, and 6.0 through 6.0.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the inten...Show more
IBM DOORS Next Generation (DNG/RRC) 5.0, 5.0.1, 5.0.2, and 6.0 through 6.0.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 137035.Show less
1Nextendweb
1Nextend Twitter Connect
Nov 21, 2024
Apr 12, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in the new_Twitter_sign_button function in nextend-Twitter-connect.php in the Nextend Twitter Connect plugin before 1.5.2 for WordPress allows remote attackers to inject arbitrary...Show more
Cross-site scripting (XSS) vulnerability in the new_Twitter_sign_button function in nextend-Twitter-connect.php in the Nextend Twitter Connect plugin before 1.5.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the redirect_to parameter. NOTE: this may overlap CVE-2015-4413.Show less