← Back
CWE-79

46,005 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (46,005)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Netfortris
1Trixbox
Nov 21, 2024
Feb 16, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
trixbox 2.8.0.4 has XSS via the PATH_INFO to /maint/index.php or /user/includes/language/langChooser.php.
1Microfocus
1Project And Portfolio Management
Nov 21, 2024
Feb 15, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A Remote Cross-Site Scripting vulnerability in HPE Project and Portfolio Management (PPM) version v9.30, v9.31, v9.32, v9.40 was found.
1Hp
2Loadrunner
Performance Center
Nov 21, 2024
Feb 15, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A Remote Cross-Site Scripting (XSS) vulnerability in HPE LoadRunner v12.53 and earlier and HPE Performance Center version v12.53 and earlier was found.
1Hp
1Aruba Clearpass Policy Manager
Nov 21, 2024
Feb 15, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A reflected cross site scripting vulnerability in HPE Aruba ClearPass Policy Manager version 6.6.x was found.
1Hp
1Operations Bridge Analytics
Nov 21, 2024
Feb 15, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A Remote Cross-Site Scripting (XSS) vulnerability in HPE Operations Bridge Analytics version v3.0 was found.
1Hp
1Opencall Media Platform
Nov 21, 2024
Feb 15, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A Remote Code Execution vulnerability in HPE OpenCall Media Platform (OCMP) was found. The vulnerability impacts OCMP versions prior to 3.4.2 RP201 (for OCMP 3.x), all versions prior to 4.4.7 RP702 (for OCMP 4.x).
1Hp
1System Management Homepage
Nov 21, 2024
Feb 15, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A cross-site scripting vulnerability in HPE System Management Homepage for Windows and Linux version prior to v7.6.1 was found.
1Hp
1Matrix Operating Environment
Nov 21, 2024
Feb 15, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A cross site scripting vulnerability in HPE Matrix Operating Environment version 7.6 was found.
1Hp
1Diagnostics
Nov 21, 2024
Feb 15, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A cross-site scripting vulnerability in HPE Diagnostics version 9.24 IP1, 9.26 , 9.26IP1 was found.
1Hp
1Systems Insight Manager
Nov 21, 2024
Feb 15, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A cross site scripting vulnerability in HPE Systems Insight Manager in all versions prior to 7.6 was found.
1Emberjs
1Ember.js
Nov 21, 2024
Feb 15, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Ember.js 1.0.x before 1.0.1, 1.1.x before 1.1.3, 1.2.x before 1.2.1, 1.3.x before 1.3.1, and 1.4.x before 1.4.0-beta.2 allows remote attackers to conduct cross-site scripting (XSS) attacks by leveraging an application us...Show more
Ember.js 1.0.x before 1.0.1, 1.1.x before 1.1.3, 1.2.x before 1.2.1, 1.3.x before 1.3.1, and 1.4.x before 1.4.0-beta.2 allows remote attackers to conduct cross-site scripting (XSS) attacks by leveraging an application using the "{{group}}" Helper and a crafted payload.Show less
1Emberjs
1Ember.js
Nov 21, 2024
Feb 15, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Ember.js 1.0.x before 1.0.1, 1.1.x before 1.1.3, 1.2.x before 1.2.1, 1.3.x before 1.3.1, and 1.4.x before 1.4.0-beta.2 allows remote attackers to conduct cross-site scripting (XSS) attacks by leveraging an application th...Show more
Ember.js 1.0.x before 1.0.1, 1.1.x before 1.1.3, 1.2.x before 1.2.1, 1.3.x before 1.3.1, and 1.4.x before 1.4.0-beta.2 allows remote attackers to conduct cross-site scripting (XSS) attacks by leveraging an application that contains templates whose context is set to a user-supplied primitive value and also contain the `{{this}}` special Handlebars variable.Show less
1Steelcase
1Roomwizard Firmware
Jun 17, 2026
Feb 15, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
RoomWizard before 4.4.x allows XSS via the HelpAction.action pageName parameter.
1Microsoft
1Sharepoint Enterprise Server
Nov 21, 2024
Feb 15, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
SharePoint Server 2016 allows an elevation of privilege vulnerability due to how web requests are handled, aka "Microsoft SharePoint Elevation of Privilege Vulnerability".
1Microsoft
1Sharepoint Server
Nov 21, 2024
Feb 15, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
SharePoint Project Server 2013 and SharePoint Enterprise Server 2016 allow an information disclosure vulnerability due to how web requests are handled, aka "Microsoft SharePoint Information Disclosure Vulnerability".
1Ibm
1Connections
Nov 21, 2024
Feb 14, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM Connections 4.0, 4.5, 5.0, 5.5, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially lea...Show more
IBM Connections 4.0, 4.5, 5.0, 5.5, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 134004.Show less
1Sap
1Internet Graphics Server
Nov 21, 2024
Feb 14, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Stored cross-site scripting vulnerability in SAP internet Graphics Server, 7.20, 7.20EXT, 7.45, 7.49, 7.53.
1Sap
1Internet Graphics Server
Nov 21, 2024
Feb 14, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Reflected cross-site scripting vulnerability in SAP internet Graphics Server, 7.20, 7.20EXT, 7.45, 7.49, 7.53.
1Sap
1Netweaver Java Web Application
Nov 21, 2024
Feb 14, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The SAML 2.0 service provider of SAP Netweaver AS Java Web Application, 7.50, does not sufficiently encode user controlled inputs, which results in Cross-Site Scripting (XSS) vulnerability.
1Sap
2Customer Relationship Management Webclient Ui
S4fnd
Nov 21, 2024
Feb 14, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
SAP CRM WebClient UI 7.01, 7.31, 7.46, 7.47, 7.48, 8.00, 8.01, S4FND 1.02, does not sufficiently validate and/or encode hidden fields, resulting in Cross-Site Scripting (XSS) vulnerability.