← Back
CWE-79

46,021 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (46,021)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Projectsend
1Projectsend
Nov 21, 2024
Mar 6, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in ProjectSend (formerly cFTP) before commit 6c3710430be26feb5371cb0377e5355d6f9a27ca allows remote attackers to inject arbitrary web script or HTML via the Description field in a...Show more
Cross-site scripting (XSS) vulnerability in ProjectSend (formerly cFTP) before commit 6c3710430be26feb5371cb0377e5355d6f9a27ca allows remote attackers to inject arbitrary web script or HTML via the Description field in a Site name updated.Show less
1Hot Scripts Clone Project
1Hot Scripts Clone
Jun 17, 2026
Mar 6, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
PHP Scripts Mall Hot Scripts Clone:Script Classified Version 3.1 Application is vulnerable to stored XSS within the "Add New" function for a Management User. Within the "Add New" section, the application does not sanitiz...Show more
PHP Scripts Mall Hot Scripts Clone:Script Classified Version 3.1 Application is vulnerable to stored XSS within the "Add New" function for a Management User. Within the "Add New" section, the application does not sanitize user supplied input to the name parameter, and renders injected JavaScript code to the user's browser. This is different from CVE-2018-6878.Show less
1Kubik Rubik
1Simple Image Gallery Extended
Jun 17, 2026
Mar 5, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The htmlImageAddTitleAttribute function in sige.php in the Kubik-Rubik Simple Image Gallery Extended (SIGE) extension 3.2.3 for Joomla! has XSS via a crafted image header, as demonstrated by the Caption-Abstract header o...Show more
The htmlImageAddTitleAttribute function in sige.php in the Kubik-Rubik Simple Image Gallery Extended (SIGE) extension 3.2.3 for Joomla! has XSS via a crafted image header, as demonstrated by the Caption-Abstract header object in a JPEG file. This is fixed in 3.3.1.Show less
1Invoiceplane
1Invoiceplane
Nov 21, 2024
Mar 5, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in InvoicePlane before 1.5.5. It was observed that the Email address and Web address parameters are vulnerable to Cross Site Scripting, related to application/modules/clients/views/view.php, appli...Show more
An issue was discovered in InvoicePlane before 1.5.5. It was observed that the Email address and Web address parameters are vulnerable to Cross Site Scripting, related to application/modules/clients/views/view.php, application/modules/invoices/views/view.php, and application/modules/quotes/views/view.php.Show less
1Netiq
1Privileged Account Manager
Nov 21, 2024
Mar 5, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
NetIQ Privileged Account Manager before 3.1 Patch Update 3 allowed cross site scripting attacks via the "type" and "account" parameters of json requests.
1Netiq
1Identity Manager
Nov 21, 2024
Mar 5, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Multiple cross site scripting attacks were found in the Identity Manager Plug-in, hosted on iManager 2.7.7.7, before Identity Manager 4.6.1. In certain scenarios it was possible to execute arbitrary JavaScript code in th...Show more
Multiple cross site scripting attacks were found in the Identity Manager Plug-in, hosted on iManager 2.7.7.7, before Identity Manager 4.6.1. In certain scenarios it was possible to execute arbitrary JavaScript code in the context of vulnerable application, via user.Context in the Object Selector, via vdtData in the Version discovery and via nextFrame in the Object Inspector and via Host GUID in the System details plugins.Show less
1Voten
1Voten
Jun 17, 2026
Mar 5, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in resources/views/layouts/app.blade.php in Voten.co before 2017-08-25. An unescaped template literal in the bio field of a user profile (resources/views/layouts/app.blade.php) allows for server-s...Show more
An issue was discovered in resources/views/layouts/app.blade.php in Voten.co before 2017-08-25. An unescaped template literal in the bio field of a user profile (resources/views/layouts/app.blade.php) allows for server-side template injection of arbitrary JavaScript.Show less
1Yzmcms
1Yzmcms
Jun 17, 2026
Mar 4, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In YzmCMS 3.6, index.php has XSS via the a, c, or m parameter.
1Zonemaster
1Zonemaster Web Gui
Jun 17, 2026
Mar 4, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
lib/Zonemaster/GUI/Dancer/Export.pm in Zonemaster Web GUI before 1.0.11 has XSS.
1Netiq
1Access Manager
Nov 21, 2024
Mar 2, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Novell Access Manager iManager before 4.3.3 did not validate parameters so that cross site scripting content could be reflected back into the result page using the "a" parameter.
1Netiq
1Privileged Account Manager
Nov 21, 2024
Mar 2, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
NetIQ Privileged Account Manager before 3.1 Patch Update 3 allowed cross site scripting attacks via javascript DOM modification using the supplied cookie parameter.
1Netiq
1Access Manager
Nov 21, 2024
Mar 2, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A OAuth application in NetIQ Access Manager 4.3 before 4.3.2 and 4.2 before 4.2.4 allowed cross site scripting attacks due to unescaped "description" field that could be specified by the provider.
1Netiq
1Access Manager
Nov 21, 2024
Mar 2, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Reflected XSS in the NetIQ Access Manager before 4.3.3 allowed attackers to reflect back xss into the called page using the url parameter.
2Debian
Drupal
2Debian Linux
Drupal
Nov 21, 2024
Mar 1, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A jQuery cross site scripting vulnerability is present when making Ajax requests to untrusted domains. This vulnerability is mitigated by the fact that it requires contributed or custom modules in order to exploit. For D...Show more
A jQuery cross site scripting vulnerability is present when making Ajax requests to untrusted domains. This vulnerability is mitigated by the fact that it requires contributed or custom modules in order to exploit. For Drupal 8, this vulnerability was already fixed in Drupal 8.4.0 in the Drupal core upgrade to jQuery 3. For Drupal 7, it is fixed in the current release (Drupal 7.57) for jQuery 1.4.4 (the version that ships with Drupal 7 core) as well as for other newer versions of jQuery that might be used on the site, for example using the jQuery Update module.Show less
2Debian
Drupal
2Debian Linux
Drupal
Nov 21, 2024
Mar 1, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Drupal 8.4.x versions before 8.4.5 and Drupal 7.x versions before 7.57 has a Drupal.checkPlain() JavaScript function which is used to escape potentially dangerous text before outputting it to HTML (as JavaScript output d...Show more
Drupal 8.4.x versions before 8.4.5 and Drupal 7.x versions before 7.57 has a Drupal.checkPlain() JavaScript function which is used to escape potentially dangerous text before outputting it to HTML (as JavaScript output does not typically go through Twig autoescaping). This function does not correctly handle all methods of injecting malicious HTML, leading to a cross-site scripting vulnerability under certain circumstances. The PHP functions which Drupal provides for HTML escaping are not affected.Show less
1Wowza
1Streaming Engine
Jun 17, 2026
Mar 1, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in Wowza Streaming Engine before 4.7.1. There is an XSS vulnerability in the HTTP providers (com.wowza.wms.http.HTTPProviderMediaList and com.wowza.wms.http.streammanager.HTTPStreamManager) causin...Show more
An issue was discovered in Wowza Streaming Engine before 4.7.1. There is an XSS vulnerability in the HTTP providers (com.wowza.wms.http.HTTPProviderMediaList and com.wowza.wms.http.streammanager.HTTPStreamManager) causing script injection and/or reflection via a crafted HTTP request.Show less
1Netiq
1Access Manager
Nov 21, 2024
Mar 1, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A reflected cross site scripting attack in the NetIQ Access Manager before 4.3.3 using the "typecontainerid" parameter of the policy editor could allowed code injection into pages of authenticated users.
1Netiq
1Access Manager
Nov 21, 2024
Mar 1, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A cross site scripting attack in handling the ESP login parameter handling in NetIQ Access Manager before 4.3.3 could be used to inject javascript code into the login page.
1Sap
1Netweaver Portal
Nov 21, 2024
Mar 1, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
SAP NetWeaver Portal, WebDynpro Java, 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.
1Entrepreneur Job Portal Script Project
1Entrepreneur Job Portal Script
Jun 17, 2026
Feb 28, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
PHP Scripts Mall Entrepreneur Job Portal Script 2.0.9 has XSS via the p_name (aka Edit Category Name) field to admin/categories_industry.php (aka Categories - Industry Type).