← Back
CWE-79

46,029 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (46,029)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Dsmall Project
1Dsmall
Jun 17, 2026
Mar 25, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
dsmall v20180320 allows XSS via the public/index.php/home/predeposit/index.html pdr_sn parameter (aka the CMS search box).
1Otcms
1Otcms
Jun 17, 2026
Mar 24, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
OTCMS 3.20 allows XSS by adding a keyword or link to an article, as demonstrated by an admin/keyWord_deal.php?mudi=add request.
1Bmc
1Remedy Action Request System
Nov 21, 2024
Mar 24, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
BMC Remedy Action Request (AR) System 9.0 before 9.0.00 Service Pack 2 hot fix 1 has persistent XSS.
1Bose
1Soundtouch
Nov 21, 2024
Mar 24, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Bose SoundTouch devices allow XSS via a crafted public playlist from Spotify.
1Bose
1Soundtouch
Nov 21, 2024
Mar 24, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Bose SoundTouch devices allow XSS via crafted song data from a music service, as demonstrated by Pandora.
1Covercms Project
1Covercms
Jun 17, 2026
Mar 23, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
CoverCMS v1.1.6 has XSS via the fourth input box to index.php, related to admina/mconfigs.inc.php.
1Scilico
1I, Librarian
Dec 5, 2025
Mar 23, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
I, Librarian version 4.8 and earlier contains a Cross Site Scripting (XSS) vulnerability in "id" parameter in stable.php that can result in an attacker using the XSS to send a malicious script to an unsuspecting user.
1Ibm
1Mq Appliance
Nov 21, 2024
Mar 23, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM MQ Appliance 9.0.1, 9.0.2, 9.0.3, amd 9.0.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially...Show more
IBM MQ Appliance 9.0.1, 9.0.2, 9.0.3, amd 9.0.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 139077.Show less
1Ibm
7Rational Collaborative Lifecycle Management
Rational Doors Next GenerationRational Engineering Lifecycle Manager+4 more
Nov 21, 2024
Mar 23, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM Jazz Foundation (IBM Rational Collaborative Lifecycle Management 5.0 and 6.0) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the...Show more
IBM Jazz Foundation (IBM Rational Collaborative Lifecycle Management 5.0 and 6.0) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 136006.Show less
1Ibm
7Rational Collaborative Lifecycle Management
Rational Doors Next GenerationRational Engineering Lifecycle Manager+4 more
Nov 21, 2024
Mar 23, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM Jazz Foundation (IBM Rational Collaborative Lifecycle Management 5.0 and 6.0) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the...Show more
IBM Jazz Foundation (IBM Rational Collaborative Lifecycle Management 5.0 and 6.0) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 133379.Show less
1Ibm
7Rational Collaborative Lifecycle Management
Rational Doors Next GenerationRational Engineering Lifecycle Manager+4 more
Nov 21, 2024
Mar 23, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM Jazz Foundation (IBM Rational Collaborative Lifecycle Management 5.0 and 6.0) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the...Show more
IBM Jazz Foundation (IBM Rational Collaborative Lifecycle Management 5.0 and 6.0) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 133127.Show less
1Misp Project
1Misp
Jun 17, 2026
Mar 23, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In MISP before 2.4.89, app/View/Events/resolved_attributes.ctp has multiple XSS issues via a malicious MISP module.
1Xiuno Bbs Project
1Xiuno Bbs
Jun 17, 2026
Mar 22, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Xiuno BBS 4.0.0 has XSS in the adminpage sitename parameter.
1Open Audit
1Open Audit
Jun 17, 2026
Mar 22, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Open-AudIT Professional 2.1 allows XSS via the Name or Description field on the Credentials screen.
1Geutebrueck
2G Cam/efd 2250 Firmware
Topfd 2125 Firmware
Jun 17, 2026
Mar 22, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A cross-site scripting vulnerability has been identified in Geutebruck G-Cam/EFD-2250 Version 1.12.0.4 and Topline TopFD-2125 Version 3.15.1 IP cameras, which may allow remote code execution.
1Synology
1Photo Station
Nov 21, 2024
Mar 22, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in Log Viewer in Synology Photo Station before 6.8.3-3463 and before 6.3-2971 allows remote attackers to inject arbitrary web script or HTML via the username parameter.
1Qqq Systems Project
1Qqq Systems
Nov 21, 2024
Mar 22, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting vulnerability in QQQ SYSTEMS ver2.24 allows an attacker to inject arbitrary web script or HTML via unspecified vectors.
1Qqq Systems Project
1Qqq Systems
Nov 21, 2024
Mar 22, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting vulnerability in QQQ SYSTEMS ver2.24 allows an attacker to inject arbitrary web script or HTML via quiz_op.cgi.
1Qqq Systems Project
1Qqq Systems
Nov 21, 2024
Mar 22, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting vulnerability in QQQ SYSTEMS ver2.24 allows an attacker to inject arbitrary web script or HTML via quiz.cgi.
1Php 2chbbs Project
1Php 2chbbs
Nov 21, 2024
Mar 22, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting vulnerability in PHP 2chBBS version bbs18c allows an attacker to inject arbitrary web script or HTML via unspecified vectors.