← Back
CWE-79

46,037 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (46,037)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Gitlab
1Gitlab
Jun 17, 2026
Apr 5, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
GitLab Community and Enterprise Editions version 9.2 up to 10.4 are vulnerable to XSS because a lack of input validation in the milestones component leads to cross site scripting (specifically, data-milestone-id in the m...Show more
GitLab Community and Enterprise Editions version 9.2 up to 10.4 are vulnerable to XSS because a lack of input validation in the milestones component leads to cross site scripting (specifically, data-milestone-id in the milestone dropdown feature). This is fixed in 10.6.3, 10.5.7, and 10.4.7.Show less
1Gitlab
1Gitlab
Jun 17, 2026
Apr 5, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
GitLab Community and Enterprise Editions version 8.4 up to 10.4 are vulnerable to XSS because a lack of input validation in the merge request component leads to cross site scripting (specifically, filenames in changes ta...Show more
GitLab Community and Enterprise Editions version 8.4 up to 10.4 are vulnerable to XSS because a lack of input validation in the merge request component leads to cross site scripting (specifically, filenames in changes tabs of merge requests). This is fixed in 10.6.3, 10.5.7, and 10.4.7.Show less
1Gleezcms
1Gleez Cms
Jun 17, 2026
Apr 5, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-site scripting (XSS) vulnerability in Gleez CMS 1.2.0 and 2.0 might allow remote attackers (users) to inject JavaScript via HTML content in an editor, which will result in Stored XSS when an Administrator tries to...Show more
Cross-site scripting (XSS) vulnerability in Gleez CMS 1.2.0 and 2.0 might allow remote attackers (users) to inject JavaScript via HTML content in an editor, which will result in Stored XSS when an Administrator tries to edit the same content, as demonstrated by use of the source editor for HTML mode in an Add Blog action.Show less
1Zammad
1Zammad
Nov 21, 2024
Apr 5, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Zammad GmbH Zammad version 2.3.0 and earlier contains a Improper Neutralization of Script-Related HTML Tags in a Web Page (CWE-80) vulnerability in the subject of emails which are not html quoted in certain cases. This c...Show more
Zammad GmbH Zammad version 2.3.0 and earlier contains a Improper Neutralization of Script-Related HTML Tags in a Web Page (CWE-80) vulnerability in the subject of emails which are not html quoted in certain cases. This can result in the embedding and execution of java script code on users browser. This attack appear to be exploitable via the victim openning a ticket. This vulnerability appears to have been fixed in 2.3.1, 2.2.2 and 2.1.3.Show less
1Jenkins
1Cucumber Living Documentation
Nov 21, 2024
Apr 5, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A cross site scripting vulnerability exists in Jenkins Cucumber Living Documentation Plugin 1.0.12 and older in CukedoctorBaseAction#doDynamic that disables the Content-Security-Policy protection for archived artifacts a...Show more
A cross site scripting vulnerability exists in Jenkins Cucumber Living Documentation Plugin 1.0.12 and older in CukedoctorBaseAction#doDynamic that disables the Content-Security-Policy protection for archived artifacts and workspace files, allowing attackers able to control the content of these files to attack Jenkins users.Show less
1Dsmall Project
1Dsmall
Jun 17, 2026
Apr 4, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
dsmall v20180320 allows XSS via the pdr_sn parameter to public/index.php/home/predeposit/index.html.
1Moodle
1Moodle
Nov 21, 2024
Apr 4, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
A flaw was found in Moodle 3.4 to 3.4.1, 3.3 to 3.3.4, 3.2 to 3.2.7, 3.1 to 3.1.10 and earlier unsupported versions. Unauthenticated users can trigger custom messages to admin via paypal enrol script. Paypal IPN callback...Show more
A flaw was found in Moodle 3.4 to 3.4.1, 3.3 to 3.3.4, 3.2 to 3.2.7, 3.1 to 3.1.10 and earlier unsupported versions. Unauthenticated users can trigger custom messages to admin via paypal enrol script. Paypal IPN callback script should only send error emails to admin after request origin was verified, otherwise admin email can be spammed.Show less
1Relevanssi
1Relevanssi
Jun 17, 2026
Apr 4, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-site scripting (XSS) vulnerability in lib/interface.php of the Relevanssi plugin 4.0.4 for WordPress allows remote attackers to inject arbitrary JavaScript or HTML via the tab GET parameter.
1Ibm
1Mobilefirst Platform Foundation
Nov 21, 2024
Apr 4, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
IBM Worklight (IBM MobileFirst Platform Foundation 6.3, 7.0, 7.1, and 8.0) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intende...Show more
IBM Worklight (IBM MobileFirst Platform Foundation 6.3, 7.0, 7.1, and 8.0) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 136786.Show less
1Mcafee
1Network Security Manager
Nov 21, 2024
Apr 4, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Reflective Cross-Site Scripting (XSS) vulnerability in the web interface in McAfee Network Security Management (NSM) before 8.2.7.42.2 allows attackers to inject arbitrary web script or HTML via a URL parameter.
1Yahei
1Yahei Php Prober
Jun 17, 2026
Apr 4, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
proberv.php in Yahei-PHP Proberv 0.4.7 has XSS via the funName parameter.
1Iscripts
1Easycreate
Jun 17, 2026
Apr 4, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
iScripts EasyCreate 3.2.1 has Stored Cross-Site Scripting in the "Site Description" field.
1Iscripts
1Easycreate
Jun 17, 2026
Apr 4, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
iScripts EasyCreate 3.2.1 has Stored Cross-Site Scripting in the "Site title" field.
1Iscripts
1Sonicbb
Jun 17, 2026
Apr 4, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
iScripts SonicBB 1.0 has Reflected Cross-Site Scripting via the query parameter to search.php.
3Apple
CanonicalWebkitgtk
3Safari
Ubuntu LinuxWebkitgtk
Nov 21, 2024
Apr 3, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in certain Apple products. Safari before 11.1 is affected. The issue involves the "WebKit" component. A Safari cross-site scripting (XSS) vulnerability allows remote attackers to inject arbitrary...Show more
An issue was discovered in certain Apple products. Safari before 11.1 is affected. The issue involves the "WebKit" component. A Safari cross-site scripting (XSS) vulnerability allows remote attackers to inject arbitrary web script or HTML via a crafted URL.Show less
1Apple
3Iphone Os
SafariTvos
Nov 21, 2024
Apr 3, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS before 10.2 is affected. The issue involves the "JavaScriptCore" component. It allows remote attackers...Show more
An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS before 10.2 is affected. The issue involves the "JavaScriptCore" component. It allows remote attackers to conduct Universal XSS (UXSS) attacks via a crafted web site that triggers prototype mishandling.Show less
1Mcafee
1Epolicy Orchestrator
Jun 17, 2026
Apr 2, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Reflected Cross-Site Scripting vulnerability in McAfee ePolicy Orchestrator (ePO) 5.3.2, 5.3.1, 5.3.0 and 5.9.0 allows remote authenticated users to exploit an XSS issue via not sanitizing the user input.
1Joomsky
1Js Jobs
Jun 17, 2026
Apr 2, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The Joom Sky JS Jobs extension before 1.2.1 for Joomla! has XSS.
1Zohocorp
1Manageengine Recovery Manager Plus
Jun 17, 2026
Apr 2, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A stored Cross-site scripting (XSS) vulnerability in Zoho ManageEngine Recovery Manager Plus before 5.3 (Build 5350) allows remote authenticated users (with Add New Technician permissions) to inject arbitrary web script...Show more
A stored Cross-site scripting (XSS) vulnerability in Zoho ManageEngine Recovery Manager Plus before 5.3 (Build 5350) allows remote authenticated users (with Add New Technician permissions) to inject arbitrary web script or HTML via the loginName field to technicianAction.do.Show less
1Get Simple
1Getsimple Cms
Jun 17, 2026
Apr 2, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in admin/template/js/uploadify/uploadify.swf in GetSimple CMS 3.3.13 allows remote attackers to inject arbitrary web script or HTML, as demonstrated by the movieName parameter.