← Back
CWE-79

46,021 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (46,021)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Yzmcms
1Yzmcms
Jun 17, 2026
Mar 13, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
YzmCMS 3.7 has Stored XSS via the title parameter to advertisement/adver/edit.html.
1Redhat
1Ovirt Engine
Nov 21, 2024
Mar 13, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
oVirt version 4.2.0 to 4.2.2 contains a Cross Site Scripting (XSS) vulnerability in the name/description of VMs portion of the web admin application. This vulnerability appears to have been fixed in version 4.2.3.
1Bmc
1Remedy Action Request System
Nov 21, 2024
Mar 12, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Remedy Mid Tier in BMC Remedy AR System 9.1 allows XSS via the ATTKey parameter in an arsys/servlet/AttachServlet request.
1Glpi Project
1Glpi
Jun 17, 2026
Mar 12, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in GLPI through 9.2.1. The application is affected by XSS in the query string to front/preference.php. An attacker is able to create a malicious URL that, if opened by an authenticated user with d...Show more
An issue was discovered in GLPI through 9.2.1. The application is affected by XSS in the query string to front/preference.php. An attacker is able to create a malicious URL that, if opened by an authenticated user with debug privilege, will execute JavaScript code supplied by the attacker. The attacker-supplied code can perform a wide variety of actions, such as stealing the victim's session token or login credentials, performing arbitrary actions on the victim's behalf, and logging their keystrokes.Show less
1Ibm
2Care Management
Curam Social Program Management
Nov 21, 2024
Mar 12, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-site scripting (XSS) vulnerability in IBM Curam Social Program Management 6.0.0 before SP2 EP29, 6.0.4 before 6.0.4.6 iFix3, 6.0.5 before 6.0.5.9 iFix2, 6.1.0 before 6.1.0.1 iFix1, and 6.1.1 before 6.1.1.1 iFix1; a...Show more
Cross-site scripting (XSS) vulnerability in IBM Curam Social Program Management 6.0.0 before SP2 EP29, 6.0.4 before 6.0.4.6 iFix3, 6.0.5 before 6.0.5.9 iFix2, 6.1.0 before 6.1.0.1 iFix1, and 6.1.1 before 6.1.1.1 iFix1; and IBM Care Management 6.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. IBM X-Force ID: 110604.Show less
1Clusterlabs
1Pcs
Nov 21, 2024
Mar 12, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
ClusterLabs pcs before version 0.9.157 is vulnerable to a cross-site scripting vulnerability due to improper validation of Node name field when creating new cluster or adding existing cluster.
1Wicket Jquery Ui Project
1Wicket Jquery Ui
Nov 21, 2024
Mar 12, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In Wicket jQuery UI 6.28.0 and earlier, 7.9.1 and earlier, and 8.0.0-M8 and earlier, a security issue has been discovered in the WYSIWYG editor that allows an attacker to submit arbitrary JS code to WYSIWYG editor.
1Qcms
1Qcms
Jun 17, 2026
Mar 12, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
QCMS version 3.0 has XSS via the title parameter to the /guest/index.html URI.
1Qcms
1Qcms
Jun 17, 2026
Mar 12, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
QCMS version 3.0 has XSS via the webname parameter to the /backend/system.html URI.
1Cmsmadesimple
1Cms Made Simple
Jun 17, 2026
Mar 12, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
CMS Made Simple (CMSMS) 2.2.6 has XSS in admin/moduleinterface.php via the pagedata parameter.
1Cmsmadesimple
1Cms Made Simple
Jun 17, 2026
Mar 12, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
CMS Made Simple (CMSMS) 2.2.6 has stored XSS in admin/moduleinterface.php via the metadata parameter.
1Tiki
1Tikiwiki Cms/groupware
Jun 17, 2026
Mar 9, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross Site Scripting (XSS) exists in Tiki before 12.13, 15.6, 17.2, and 18.1.
1Ibm
1Financial Transaction Manager
Nov 21, 2024
Mar 9, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-site scripting (XSS) vulnerability in IBM Financial Transaction Manager (FTM) for ACH Services for Multi-Platform 2.1.1.2 and 3.0.0.x before fp0013, Financial Transaction Manager (FTM) for Check Services for Multi-...Show more
Cross-site scripting (XSS) vulnerability in IBM Financial Transaction Manager (FTM) for ACH Services for Multi-Platform 2.1.1.2 and 3.0.0.x before fp0013, Financial Transaction Manager (FTM) for Check Services for Multi-Platform 2.1.1.2 and 3.0.0.x before fp0013, and Financial Transaction Manager (FTM) for Corporate Payment Services (CPS) for Multi-Platform 2.1.1.2 and 3.0.0.x before fp0013 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. IBM X-Force ID: 110562.Show less
1Eramba
1Eramba
Jun 17, 2026
Mar 9, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Eramba e1.0.6.033 has Reflected XSS on the Error page of the CSV file inclusion tab of the /importTool/preview URI, with a CSV file polluted with malicious JavaScript.
1Eramba
1Eramba
Jun 17, 2026
Mar 9, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Eramba e1.0.6.033 has Stored XSS on the tooltip box via the /programScopes description parameter.
1Soflyy
1Wp All Import
Nov 21, 2024
Mar 9, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting vulnerability in WP All Import plugin prior to version 3.4.7 for WordPress allows an attacker to inject arbitrary web script or HTML via unspecified vectors.
1Soflyy
1Wp All Import
Nov 21, 2024
Mar 9, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting vulnerability in WP All Import plugin prior to version 3.4.6 for WordPress allows an attacker to inject arbitrary web script or HTML via unspecified vectors.
1Eramba
1Eramba
Jun 17, 2026
Mar 9, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Eramba e1.0.6.033 has Reflected XSS in reviews/filterIndex/ThirdPartyRiskReview via the advanced_filter parameter (aka the Search Parameter).
1Qnap
1Media Streaming Add On
Nov 21, 2024
Mar 8, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in QNAP NAS application Media Streaming add-on version 421.1.0.2, 430.1.2.0, and earlier allows remote attackers to inject arbitrary web script or HTML. The injected code will onl...Show more
Cross-site scripting (XSS) vulnerability in QNAP NAS application Media Streaming add-on version 421.1.0.2, 430.1.2.0, and earlier allows remote attackers to inject arbitrary web script or HTML. The injected code will only be triggered by a crafted link, not the normal page.Show less
1Cisco
1Security Manager
Nov 21, 2024
Mar 8, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A vulnerability in DesktopServlet in the web-based management interface of Cisco Security Manager could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of...Show more
A vulnerability in DesktopServlet in the web-based management interface of Cisco Security Manager could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the web-based interface. The vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of an affected device. An attacker could exploit this vulnerability by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface or allow the attacker to access sensitive browser-based information. Cisco Bug IDs: CSCuy79668.Show less