← Back
CWE-79

46,037 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (46,037)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Iptanus
1Wordpress File Upload
Jun 17, 2026
Apr 1, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The Iptanus WordPress File Upload plugin before 4.3.3 for WordPress mishandles shortcode attributes.
1Lynxtechnology
1Twonky Server
Jun 17, 2026
Mar 30, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in Twonky Server 7.0.11 through 8.5 allows remote attackers to inject arbitrary web script or HTML via the friendlyname parameter to rpc/set_all.
1Rsa
1Authentication Agent For Web
Nov 21, 2024
Mar 30, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
RSA Authentication Agent version 8.0.1 and earlier for Web for both IIS and Apache Web Server are affected by a cross-site scripting vulnerability. The attackers could potentially exploit this vulnerability to execute ar...Show more
RSA Authentication Agent version 8.0.1 and earlier for Web for both IIS and Apache Web Server are affected by a cross-site scripting vulnerability. The attackers could potentially exploit this vulnerability to execute arbitrary HTML or JavaScript code in the user's browser session in the context of the affected website.Show less
1Elastic
1Kibana
Nov 21, 2024
Mar 30, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Kibana versions after 5.1.1 and before 5.6.7 and 6.1.3 had a cross-site scripting (XSS) vulnerability in the tag cloud visualization that could allow an attacker to obtain sensitive information from or perform destructiv...Show more
Kibana versions after 5.1.1 and before 5.6.7 and 6.1.3 had a cross-site scripting (XSS) vulnerability in the tag cloud visualization that could allow an attacker to obtain sensitive information from or perform destructive actions on behalf of other Kibana users.Show less
1Elastic
1Kibana
Nov 21, 2024
Mar 30, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Kibana versions after 6.1.0 and before 6.1.3 had a cross-site scripting (XSS) vulnerability in labs visualizations that could allow an attacker to obtain sensitive information from or perform destructive actions on behal...Show more
Kibana versions after 6.1.0 and before 6.1.3 had a cross-site scripting (XSS) vulnerability in labs visualizations that could allow an attacker to obtain sensitive information from or perform destructive actions on behalf of other Kibana users.Show less
1Elastic
1Kibana
Nov 21, 2024
Mar 30, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Kibana versions 5.1.1 to 6.1.2 and 5.6.6 had a cross-site scripting (XSS) vulnerability via the colored fields formatter that could allow an attacker to obtain sensitive information from or perform destructive actions on...Show more
Kibana versions 5.1.1 to 6.1.2 and 5.6.6 had a cross-site scripting (XSS) vulnerability via the colored fields formatter that could allow an attacker to obtain sensitive information from or perform destructive actions on behalf of other Kibana users.Show less
1Rubyonrails
1Html Sanitizer
Nov 21, 2024
Mar 30, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
There is a possible XSS vulnerability in all rails-html-sanitizer gem versions below 1.0.4 for Ruby. The gem allows non-whitelisted attributes to be present in sanitized output when input with specially-crafted HTML frag...Show more
There is a possible XSS vulnerability in all rails-html-sanitizer gem versions below 1.0.4 for Ruby. The gem allows non-whitelisted attributes to be present in sanitized output when input with specially-crafted HTML fragments, and these attributes can lead to an XSS attack on target applications. This issue is similar to CVE-2018-8048 in Loofah. All users running an affected release should either upgrade or use one of the workarounds immediately.Show less
1Sanitize Project
1Sanitize
Nov 21, 2024
Mar 30, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A specially crafted HTML fragment can cause Sanitize gem for Ruby to allow non-whitelisted attributes to be used on a whitelisted HTML element.
1Gespage
1Gespage
Jun 17, 2026
Mar 30, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerabilities in version 7.5.7 of Gespage software allow remote attackers to inject arbitrary web script or HTML via the email, passwd, and repasswd parameters to webapp/users/user_reg.jsp.
1Ibm
1Financial Transaction Manager
Nov 21, 2024
Mar 30, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM Financial Transaction Manager for Check Services for Multi-Platform 3.0, 3.0.2, and 3.0.2.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus...Show more
IBM Financial Transaction Manager for Check Services for Multi-Platform 3.0, 3.0.2, and 3.0.2.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 138221.Show less
1Ibm
4Business Process Manager
Business Process Manager Enterprise Service BusWebsphere Enterprise Service Bus+1 more
Nov 21, 2024
Mar 30, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM Business Process Manager 8.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to cre...Show more
IBM Business Process Manager 8.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 138135.Show less
1Ibm
1Business Process Manager
Nov 21, 2024
Mar 30, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM Business Process Manager 8.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to cre...Show more
IBM Business Process Manager 8.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 136152.Show less
1Zohocorp
1Manageengine Servicedesk Plus
Jun 17, 2026
Mar 30, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In Zoho ManageEngine ServiceDesk Plus before 9403, an XSS issue allows an attacker to run arbitrary JavaScript via a /api/request/?OPERATION_NAME= URI, aka SD-69139.
1Samsung
1Samsung Mobile
Jun 17, 2026
Mar 30, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
On Samsung mobile devices with M(6.0) software, the Email application allows XSS via an event attribute and arbitrary file loading via a src attribute, aka SVE-2017-10747.
1Ibos
1Ibos
Jun 17, 2026
Mar 30, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
IBOS 4.4.3 has XSS via a company full name.
1Subscribe2 Project
1Subscribe2
Nov 21, 2024
Mar 29, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in class-s2-list-table.php in the Subscribe2 plugin before 10.16 for WordPress allows remote attackers to inject arbitrary web script or HTML via the ip parameter.
1Ca
1Api Developer Portal
Jun 17, 2026
Mar 29, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
CA API Developer Portal 3.5 up to and including 3.5 CR5 has a reflected cross-site scripting vulnerability related to the apiExplorer.
1Ca
1Api Developer Portal
Jun 17, 2026
Mar 29, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
CA API Developer Portal 3.5 up to and including 3.5 CR6 has a reflected cross-site scripting vulnerability related to the widgetID variable.
1Ca
1Api Developer Portal
Jun 17, 2026
Mar 29, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
CA API Developer Portal 3.5 up to and including 3.5 CR6 has a stored cross-site scripting vulnerability related to profile picture processing.
1Crea8social
1Crea8social
Jun 17, 2026
Mar 29, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
In Crea8social 2018.2, there is Stored Cross-Site Scripting via a User Profile.