← Back
CWE-79

46,037 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (46,037)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Microsoft
1Sharepoint Enterprise Server
Nov 21, 2024
Apr 12, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint Elevation of Privileg...Show more
An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint Elevation of Privilege Vulnerability." This affects Microsoft SharePoint. This CVE ID is unique from CVE-2018-1005, CVE-2018-1014, CVE-2018-1032.Show less
1Microsoft
1Sharepoint Enterprise Server
Nov 21, 2024
Apr 12, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint Elevation of Privileg...Show more
An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint Elevation of Privilege Vulnerability." This affects Microsoft SharePoint Server, Microsoft SharePoint. This CVE ID is unique from CVE-2018-1005, CVE-2018-1014, CVE-2018-1034.Show less
1Microsoft
1Sharepoint Enterprise Server
Nov 21, 2024
Apr 12, 2018
N/A· v4
5.4 MEDIUM· v3
4.9 MEDIUM· v2
An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint Elevation of Privileg...Show more
An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint Elevation of Privilege Vulnerability." This affects Microsoft SharePoint. This CVE ID is unique from CVE-2018-1005, CVE-2018-1032, CVE-2018-1034.Show less
1Microsoft
1Sharepoint Enterprise Server
Nov 21, 2024
Apr 12, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint Elevation of Privileg...Show more
An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint Elevation of Privilege Vulnerability." This affects Microsoft SharePoint. This CVE ID is unique from CVE-2018-1014, CVE-2018-1032, CVE-2018-1034.Show less
1Iscripts
1Supportdesk
Nov 21, 2024
Apr 11, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
iScripts SupportDesk v4.3 has XSS via the admin/inteligentsearchresult.php txtinteligentsearch parameter.
1Iscripts
1Supportdesk
Nov 21, 2024
Apr 11, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
iScripts SupportDesk v4.3 has XSS via the staff/inteligentsearchresult.php txtinteligentsearch parameter.
1Iscripts
1Eswap
Nov 21, 2024
Apr 11, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
iScripts eSwap v2.4 has XSS via the "registration_settings.php" txtDate parameter in the Admin Panel.
1Cmsmadesimple
1Cms Made Simple
Nov 21, 2024
Apr 11, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
CMS Made Simple (aka CMSMS) 2.2.7 has Stored XSS in admin/siteprefs.php via the metadata parameter.
1Cmsmadesimple
1Cms Made Simple
Nov 21, 2024
Apr 11, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
CMS Made Simple (aka CMSMS) 2.2.7 has Reflected XSS in admin/moduleinterface.php via the m1_version parameter.
1Cmsmadesimple
1Cms Made Simple
Nov 21, 2024
Apr 11, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
CMS Made Simple (aka CMSMS) 2.2.7 has Reflected XSS in admin/moduleinterface.php via the m1_name parameter, related to moduledepends, a different vulnerability than CVE-2017-16799.
1Redhat
1Openshift
Nov 21, 2024
Apr 11, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
OpenShift Enterprise version 3.x is vulnerable to a stored XSS via the log viewer for pods. The flaw is due to lack of sanitation of user input, specifically terminal escape characters, and the creation of clickable link...Show more
OpenShift Enterprise version 3.x is vulnerable to a stored XSS via the log viewer for pods. The flaw is due to lack of sanitation of user input, specifically terminal escape characters, and the creation of clickable links automatically when viewing the log files for a pod.Show less
1Yzmcms
1Yzmcms
Nov 21, 2024
Apr 11, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The WeChat module in YzmCMS 3.7.1 has reflected XSS via the admin/module/init.html echostr parameter, related to the valid function in application/wechat/controller/index.class.php.
1Catfish Cms
1Catfish Cms
Nov 21, 2024
Apr 11, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Catfish CMS V4.7.21 allows XSS via the pinglun parameter to cat/index/index/pinglun (aka an authenticated comment).
1Ibm
1Websphere Portal
Nov 21, 2024
Apr 11, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
IBM WebSphere Portal 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to cre...Show more
IBM WebSphere Portal 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 140918.Show less
1Broadcom
2Advanced Secure Gateway
Symantec Proxysg
Nov 21, 2024
Apr 11, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Stored XSS vulnerability in the Symantec Advanced Secure Gateway (ASG) and ProxySG management consoles. A malicious appliance administrator can inject arbitrary JavaScript code in the management console web client applic...Show more
Stored XSS vulnerability in the Symantec Advanced Secure Gateway (ASG) and ProxySG management consoles. A malicious appliance administrator can inject arbitrary JavaScript code in the management console web client application.Show less
1Frog Cms Project
1Frog Cms
Jun 17, 2026
Apr 11, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Frog CMS 0.9.5 has XSS via the name field of a new "File" or "Directory" on the admin/?/plugin/file_manager/browse/ screen.
1Frog Cms Project
1Frog Cms
Jun 17, 2026
Apr 11, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Frog CMS 0.9.5 has XSS via the /admin/?/user/add Name or Username parameter.
1Opentext
1Documentum D2
Jun 17, 2026
Apr 11, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
In OpenText Documentum D2 Webtop v4.6.0030 build 059, a Reflected Cross-Site Scripting Vulnerability could potentially be exploited by malicious users to compromise the affected system via the servlet/Download _docbase o...Show more
In OpenText Documentum D2 Webtop v4.6.0030 build 059, a Reflected Cross-Site Scripting Vulnerability could potentially be exploited by malicious users to compromise the affected system via the servlet/Download _docbase or _username parameter.Show less
1Opentext
1Documentum D2
Jun 17, 2026
Apr 11, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
In OpenText Documentum D2 Webtop v4.6.0030 build 059, a Stored Cross-Site Scripting Vulnerability could potentially be exploited by malicious users to compromise the affected system via a filename of an uploaded image fi...Show more
In OpenText Documentum D2 Webtop v4.6.0030 build 059, a Stored Cross-Site Scripting Vulnerability could potentially be exploited by malicious users to compromise the affected system via a filename of an uploaded image file.Show less
1Videodownloaderultimate
1Video Downloader
Nov 21, 2024
Apr 11, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Video Downloader professional extension before 2018-04-05 for Chrome has Universal XSS (UXSS) via vectors related to a link64_msgAddLinks event.