CWE-79
46,022 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (46,022)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Ibm 8Rational Collaborative Lifecycle Management Rational Doors Next GenerationRational Engineering Lifecycle Manager+5 moreNov 21, 2024 Mar 15, 2018 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 Cross-site scripting (XSS) vulnerability in IBM Rational Collaborative Lifecycle Management (CLM) 3.0.1 before 3.0.1.6 iFix7 Interim Fix 1, 4.0.x before 4.0.7 iFix10, 5.0.x before 5.0.2 iFix15, and 6.0.x before 6.0.1 iFi...Show more |
1Ibm 8Rational Collaborative Lifecycle Management Rational Doors Next GenerationRational Engineering Lifecycle Manager+5 moreNov 21, 2024 Mar 15, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Cross-site scripting (XSS) vulnerability in IBM Rational Collaborative Lifecycle Management (CLM) 3.0.1 before 3.0.1.6 iFix7 Interim Fix 1, 4.0.x before 4.0.7 iFix10, 5.0.x before 5.0.2 iFix15, and 6.0.x before 6.0.1 iFi...Show more |
1Trendmicro 1Email Encryption Gateway Jun 17, 2026 Mar 15, 2018 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 A stored cross-site scripting (XSS) vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to inject client-side scripts into vulnerable systems. |
1Trendmicro 1Email Encryption Gateway Jun 17, 2026 Mar 15, 2018 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 Reflected cross-site scripting (XSS) vulnerabilities in two Trend Micro Email Encryption Gateway 5.5 configuration files could allow an attacker to inject client-side scripts into vulnerable systems. |
Multiple cross-site scripting (XSS) vulnerabilities in the Activity Log plugin before 2.4.1 for WordPress allow remote attackers to inject arbitrary JavaScript or HTML via a title that is not escaped. |
server/app/views/static/code.html in Kontena before 1.5.0 allows XSS in "kontena master login --remote" code display, as demonstrated by /code#code= in a URI. |
1Servicenow 1It Service Management Jun 17, 2026 Mar 15, 2018 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 ServiceNow ITSM 2016-06-02 has XSS via the First Name or Last Name field of My Profile (aka navpage.do), or the Search bar of My Portal (aka search_results.do). |
1Zohocorp 1Manageengine Desktop Central Jun 17, 2026 Mar 15, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Zoho ManageEngine Desktop Central version 9.1.0 build 91099 has multiple XSS issues that were fixed in build 92026. |
1Zohocorp 1Manageengine Eventlog Analyzer Jun 17, 2026 Mar 15, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Zoho ManageEngine EventLog Analyzer version 11.0 build 11000 has Stored XSS related to the index2.do?url=editAlertForm&tab=alert&alert=profile URI and the Edit Alert Profile screen |
Cross-site scripting (XSS) vulnerability in SecurEnvoy SecurMail before 9.2.501 allows remote attackers to inject arbitrary web script or HTML via an HTML-formatted e-mail message. |
Cross-site scripting (XSS) vulnerability in SecurEnvoy SecurMail before 9.2.501 allows remote attackers to inject arbitrary web script or HTML via the mailboxid parameter to secmail/getmessage.exe. |
1Sap 1Process Monitoring Infrastructure Nov 21, 2024 Mar 14, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Cross-Site Scripting in Process Monitoring Infrastructure, from 7.10 to 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, due to inefficient encoding of user controlled inputs. |
1Sap 1Businessobjects Business Intelligence Platform Nov 21, 2024 Mar 14, 2018 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 In SAP Business Objects Business Intelligence Platform, 4.00, 4.10, 4.20, 4.30, the Central Management Console (CMC) does not sufficiently encode user controlled inputs which results in Cross-Site Scripting. |
1Osisoft 2Pi Vision Pi Web ApiJun 17, 2026 Mar 14, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 A Cross-site Scripting issue was discovered in OSIsoft PI Web API versions 2017 R2 and prior. Cross-site scripting may occur when input is incorrectly neutralized. |
A Protection Mechanism Failure issue was discovered in OSIsoft PI Vision versions 2017 and prior. The X-XSS-Protection response header is not set to block, allowing attempts at reflected cross-site scripting. |
1Microsoft 1Sharepoint Enterprise Server Nov 21, 2024 Mar 14, 2018 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Microsoft SharePoint Foundation 2013 SP1 and Microsoft SharePoint Enterprise Server 2016 allow an elevation of privilege vulnerability to due how specially crafted web requests are sanitized, aka "Microsoft SharePoint El...Show more |
1Microsoft 2Project Server Sharepoint Enterprise ServerNov 21, 2024 Mar 14, 2018 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Microsoft Project Server 2013 SP1 and Microsoft SharePoint Enterprise Server 2016 allows an elevation of privilege vulnerability to due how specially crafted web requests are sanitized, aka "Microsoft SharePoint Elevatio...Show more |
1Microsoft 1Sharepoint Enterprise Server Nov 21, 2024 Mar 14, 2018 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Microsoft SharePoint Enterprise Server 2016 allows an elevation of privilege vulnerability to due how specially crafted web requests are sanitized, aka "Microsoft SharePoint Elevation of Privilege Vulnerability". This CV...Show more |
1Microsoft 1Sharepoint Enterprise Server Nov 21, 2024 Mar 14, 2018 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Microsoft SharePoint Enterprise Server 2016 allows an elevation of privilege vulnerability to due how specially crafted web requests are sanitized, aka "Microsoft SharePoint Elevation of Privilege Vulnerability". This CV...Show more |
1Microsoft 1Sharepoint Enterprise Server Nov 21, 2024 Mar 14, 2018 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Microsoft SharePoint Enterprise Server 2016 allows an elevation of privilege vulnerability to due how specially crafted web requests are sanitized, aka "Microsoft SharePoint Elevation of Privilege Vulnerability". This CV...Show more |