CWE-79
46,022 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (46,022)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Microsoft 2Project Server Sharepoint Enterprise ServerNov 21, 2024 Mar 14, 2018 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Microsoft Project Server 2013 SP1 and Microsoft SharePoint Enterprise Server 2016 allow an elevation of privilege vulnerability to due how specially crafted web requests are sanitized, aka "Microsoft SharePoint Elevation...Show more |
1Microsoft 2Project Server Sharepoint Enterprise ServerNov 21, 2024 Mar 14, 2018 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Microsoft Project Server 2013 SP1 and Microsoft SharePoint Enterprise Server 2016 allow an elevation of privilege vulnerability to due how specially crafted web requests are sanitized, aka "Microsoft SharePoint Elevation...Show more |
1Microsoft 2Project Server Sharepoint Enterprise ServerNov 21, 2024 Mar 14, 2018 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Microsoft Project Server 2013 SP1 and Microsoft SharePoint Enterprise Server 2016 allow an elevation of privilege vulnerability to due how specially crafted web requests are sanitized, aka "Microsoft SharePoint Elevation...Show more |
1Microsoft 2Project Server Sharepoint Enterprise ServerNov 21, 2024 Mar 14, 2018 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Microsoft Project Server 2013 SP1 and Microsoft SharePoint Enterprise Server 2016 allow an elevation of privilege vulnerability to due how specially crafted web requests are sanitized, aka "Microsoft SharePoint Elevation...Show more |
1Microsoft 2Project Server Sharepoint Enterprise ServerNov 21, 2024 Mar 14, 2018 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Microsoft Project Server 2013 SP1 and Microsoft SharePoint Enterprise Server 2016 allow an elevation of privilege vulnerability to due how specially crafted web requests are sanitized, aka "Microsoft SharePoint Elevation...Show more |
1Microsoft 2Project Server Sharepoint Enterprise ServerNov 21, 2024 Mar 14, 2018 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Microsoft Project Server 2013 SP1 and Microsoft SharePoint Enterprise Server 2016 allow an elevation of privilege vulnerability to due how specially crafted web requests are sanitized, aka "Microsoft SharePoint Elevation...Show more |
1Microsoft 2Project Server Sharepoint Enterprise ServerNov 21, 2024 Mar 14, 2018 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Microsoft Project Server 2013 SP1 and Microsoft SharePoint Enterprise Server 2016 allow an elevation of privilege vulnerability to due how specially crafted web requests are sanitized, aka "Microsoft SharePoint Elevation...Show more |
1Microsoft 2Project Server Sharepoint Enterprise ServerNov 21, 2024 Mar 14, 2018 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Microsoft Project Server 2013 SP1 and Microsoft SharePoint Enterprise Server 2016 allow an elevation of privilege vulnerability to due how specially crafted web requests are sanitized, aka "Microsoft SharePoint Elevation...Show more |
A cross site scripting vulnerability exist in the Administration Console in NetIQ Access Manager (NAM) 4.3 and 4.4. |
An XSS vulnerability exists in the Jolokia agent version 1.3.7 in the HTTP servlet that allows an attacker to execute malicious javascript in the victim's browser. |
The select component in bui through 2018-03-13 has XSS because it performs an escape operation on already-escaped text, as demonstrated by workGroupList text. |
IBM WebSphere Portal 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to cre...Show more |
IBM Application Performance Management - Response Time Monitoring Agent (IBM Monitoring 8.1.3 and 8.1.4) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the We...Show more |
1Zohocorp 1Manageengine Eventlog Analyzer Jun 17, 2026 Mar 13, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Cross-site scripting (XSS) in Zoho ManageEngine EventLog Analyzer before 11.12 Build 11120 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. |
1Blackberry 1Unified Endpoint Manager Nov 21, 2024 Mar 13, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 In BlackBerry UEM Management Console version 12.7.1 and earlier, a reflected cross-site scripting vulnerability that could allow an attacker to execute script commands in the context of the affected UEM Management Consol...Show more |
1Doorkeeper Project 1Doorkeeper Nov 21, 2024 Mar 13, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Doorkeeper version 2.1.0 through 4.2.5 contains a Cross Site Scripting (XSS) vulnerability in web view's OAuth app form, user authorization prompt web view that can result in Stored XSS on the OAuth Client's name will ca...Show more |
WolfCMS version version 0.8.3.1 contains a Reflected Cross Site Scripting vulnerability in "Create New File" and "Create New Directory" input box from 'files' Tab that can result in Session Hijacking, Spread Worms,Contro...Show more |
WOlfCMS WolfCMS version version 0.8.3.1 contains a Stored Cross-Site Scripting vulnerability in Layout Name (from Layout tab) that can result in low privilege user can steal the cookie of admin user and compromise the ad...Show more |
2Debian Rubygems2Debian Linux RubygemsNov 21, 2024 Mar 13, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 series: 2.5.0 and earlier, prior to trunk revision 62422 contains a Cross Site Scripti...Show more |
A cross-site scripting vulnerability exists in Jenkins TestLink Plugin 2.12 and earlier in TestLinkBuildAction/summary.jelly and others that allow an attacker who can control e.g. TestLink report names to have Jenkins se...Show more |