← Back
CWE-79

46,005 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (46,005)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Progress
1Sitefinity
Nov 21, 2024
Feb 12, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Progress Sitefinity 9.1 has XSS via the Last name, First name, and About fields on the New User Creation Page. This is fixed in 10.1.
1Progress
1Sitefinity
Nov 21, 2024
Feb 12, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Progress Sitefinity 9.1 has XSS via file upload, because JavaScript code in an HTML file has the same origin as the application's own code. This is fixed in 10.1.
1Progress
1Sitefinity
Nov 21, 2024
Feb 12, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Progress Sitefinity 9.1 has XSS via the Content Management Template Configuration (aka Templateconfiguration), as demonstrated by the src attribute of an IMG element. This is fixed in 10.1.
1Minibb
1Minibb
Jun 17, 2026
Feb 12, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Cross-Site Scripting (XSS) exists in the Add Forum feature in the Administrative Panel in miniBB 3.2.2 via crafted use of an onload attribute of an SVG element in the supertitle field.
1Multireligion Responsive Matrimonial Project
1Multireligion Responsive Matrimonial
Jun 17, 2026
Feb 12, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross Site Scripting (XSS) exists in PHP Scripts Mall Multi religion Responsive Matrimonial 4.7.2 via a user profile update parameter.
1Bitcoin Mlm Project
1Bitcoin Mlm
Jun 17, 2026
Feb 12, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross Site Scripting (XSS) exists in PHP Scripts Mall Bitcoin MLM Software 1.0.2 via a profile field.
1Lawyer Search Script Project
1Lawyer Search Script
Jun 17, 2026
Feb 12, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross Site Scripting (XSS) exists in PHP Scripts Mall Lawyer Search Script 1.0.2 via a profile update parameter.
1Facebook Clone Script Project
1Facebook Clone Script
Jun 17, 2026
Feb 12, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross Site Scripting (XSS) exists in PHP Scripts Mall Facebook Clone Script.
1Olx Clone Script Project
1Olx Clone Script
Jun 17, 2026
Feb 12, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
PHP Scripts Mall Multi Language Olx Clone Script 2.0.6 has XSS via the Leave Comment field.
1Booking Wp Plugin
1Bookly
Jun 17, 2026
Feb 11, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Bookly #1 WordPress Booking Plugin Lite before 14.5 has XSS via a jQuery.ajax request to ng-payment_details_dialog.js.
1Wondercms
1Wondercms
Nov 21, 2024
Feb 9, 2018
N/A· v4
4.4 MEDIUM· v3
3.5 LOW· v2
WonderCMS version 2.4.0 contains a Stored Cross-Site Scripting on File Upload through SVG vulnerability in uploadFileAction(), 'svg' => 'image/svg+xml' that can result in An attacker can execute arbitrary script on an un...Show more
WonderCMS version 2.4.0 contains a Stored Cross-Site Scripting on File Upload through SVG vulnerability in uploadFileAction(), 'svg' => 'image/svg+xml' that can result in An attacker can execute arbitrary script on an unsuspecting user's browser. This attack appear to be exploitable via Crafted SVG File.Show less
1Elsa Project
1Elsa
Nov 21, 2024
Feb 9, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
mcholste Enterprise Log Search and Archive (ELSA) version revision 1205, commit 2cc17f1 and earlier contains a Cross Site Scripting (XSS) vulnerability in index view (/) that can result in . This attack appear to be expl...Show more
mcholste Enterprise Log Search and Archive (ELSA) version revision 1205, commit 2cc17f1 and earlier contains a Cross Site Scripting (XSS) vulnerability in index view (/) that can result in . This attack appear to be exploitable via Payload delivered via the type, name, and value parameters of /Query/set_preference and the name and value parameters of /Query/preference. Payload executed when the user visits the index view (/).Show less
1Open Emr
1Openemr
Nov 21, 2024
Feb 9, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
OpenEMR version 5.0.0 contains a Cross Site Scripting (XSS) vulnerability in open-flash-chart.swf and _posteddata.php that can result in . This vulnerability appears to have been fixed in 5.0.0 Patch 2 or higher.
1Croogo
1Croogo
Nov 21, 2024
Feb 9, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Croogo version 2.3.1-17-g6f82e6c contains a Cross Site Scripting (XSS) vulnerability in Page name that can result in execution of javascript code.
1Dolibarr
1Dolibarr Erp/crm
Nov 21, 2024
Feb 9, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Dolibarr version 6.0.2 contains a Cross Site Scripting (XSS) vulnerability in Product details that can result in execution of javascript code.
1Invoiceplane
1Invoiceplane
Nov 21, 2024
Feb 9, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Invoice Plane version 1.5.4 and earlier contains a Cross Site Scripting (XSS) vulnerability in Client's details that can result in execution of javascript code . This vulnerability appears to have been fixed in 1.5.5 and...Show more
Invoice Plane version 1.5.4 and earlier contains a Cross Site Scripting (XSS) vulnerability in Client's details that can result in execution of javascript code . This vulnerability appears to have been fixed in 1.5.5 and later.Show less
1Cnvs
1Canvas
Nov 21, 2024
Feb 9, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Canvs Canvas version 3.4.2 contains a Cross Site Scripting (XSS) vulnerability in User's details that can result in denial of service and execution of javascript code.
1Mautic
1Mautic
Nov 21, 2024
Feb 9, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Mautic version 2.11.0 and earlier contains a Cross Site Scripting (XSS) vulnerability in Company's name that can result in denial of service and execution of javascript code.
1Sonatype
1Nexus Repository Manager
Nov 21, 2024
Feb 9, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Multiple cross-site scripting (XSS) vulnerabilities in Sonatype Nexus Repository Manager (aka NXRM) 2.x before 2.14.6 allow remote attackers to inject arbitrary web script or HTML via (1) the repoId or (2) format paramet...Show more
Multiple cross-site scripting (XSS) vulnerabilities in Sonatype Nexus Repository Manager (aka NXRM) 2.x before 2.14.6 allow remote attackers to inject arbitrary web script or HTML via (1) the repoId or (2) format parameter to service/siesta/healthcheck/healthCheckFileDetail/.../index.html; (3) the filename in the "File Upload" functionality of the Staging Upload; (4) the username when creating a new user; or (5) the IQ Server URL field in the IQ Server Connection functionality.Show less
1Sonatype
1Nexus Repository Manager
Nov 21, 2024
Feb 9, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Multiple cross-site scripting (XSS) vulnerabilities in Sonatype Nexus Repository Manager (aka NXRM) 3.x before 3.8 allow remote attackers to inject arbitrary web script or HTML via (1) the repoId or (2) format parameter...Show more
Multiple cross-site scripting (XSS) vulnerabilities in Sonatype Nexus Repository Manager (aka NXRM) 3.x before 3.8 allow remote attackers to inject arbitrary web script or HTML via (1) the repoId or (2) format parameter to service/siesta/healthcheck/healthCheckFileDetail/.../index.html; (3) the filename in the "File Upload" functionality of the Staging Upload; (4) the username when creating a new user; or (5) the IQ Server URL field in the IQ Server Connection functionality.Show less