CWE-79
46,005 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (46,005)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Multiple cross-site scripting (XSS) vulnerabilities in Java number format exception handling in FortiGate FortiDB before 4.4.2 allow remote attackers to inject arbitrary web script or HTML via the conversationContext par...Show more |
Multiple cross-site scripting (XSS) vulnerabilities in FortiWeb before 4.4.4 allow remote attackers to inject arbitrary web script or HTML via the (1) redir or (2) mkey parameter to waf/pcre_expression/validate. |
1Hot Scripts Clone Project 1Hot Scripts Clone Jun 17, 2026 Feb 9, 2018 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 Cross Site Scripting (XSS) exists in the review section in PHP Scripts Mall Hot Scripts Clone Script Classified 3.1 via the title or description field. |
IBM WebSphere Portal 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading...Show more |
IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially lea...Show more |
Cross-site scripting (XSS) vulnerability in the WooCommerce plugin before 2.3.6 for WordPress allows remote attackers to inject arbitrary web script or HTML via a crafted order. |
Multiple cross-site scripting (XSS) vulnerabilities in Fortinet FortiGate UTM WAF appliances with FortiOS 4.3.x before 4.3.6 allow remote attackers to inject arbitrary web script or HTML via vectors involving the (1) End...Show more |
2Broadcom Brocade2Fabric Operating System Fabric OsNov 21, 2024 Feb 8, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Cross-site scripting (XSS) vulnerability in the web-based management interface of Brocade Fibre Channel SAN products running Brocade Fabric OS (FOS) versions before 7.4.2b, 8.1.2 and 8.2.0 could allow remote attackers to...Show more |
Versions of Epson AirPrint released prior to January 19, 2018 contain a reflective cross-site scripting (XSS) vulnerability, which can allow untrusted users on the network to hijack a session cookie or perform other refl...Show more |
1Mtssb.mt Systems 1Simple Booking Nov 21, 2024 Feb 8, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Cross-site scripting vulnerability in MTS Simple Booking C, MTS Simple Booking Business version 1.28.0 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. |
MyBB 1.8.14 has XSS via the Title or Description field on the Edit Forum screen. |
static/js/pad_utils.js in Etherpad Lite before v1.6.3 has XSS via window.location.href. |
1Cisco 1Data Center Analytics Framework Nov 21, 2024 Feb 8, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 A vulnerability in the web-based management interface of Cisco Data Center Analytics Framework could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of th...Show more |
1Cisco 1Data Center Analytics Framework Nov 21, 2024 Feb 8, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 A vulnerability in the web-based management interface of Cisco Data Center Analytics Framework could allow an unauthenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the w...Show more |
2Debian Google2Chrome Debian LinuxNov 21, 2024 Feb 7, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Incorrect application of sandboxing in Blink in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted MHTML page. |
1Multilanguage Real Estate Mlm Script Project 1Multilanguage Real Estate Mlm Script Jun 17, 2026 Feb 7, 2018 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 PHP Scripts Mall Multilanguage Real Estate MLM Script 3.0 has Stored XSS via every profile input field. |
1Naukri Clone Script Project 1Naukri Clone Script Jun 17, 2026 Feb 7, 2018 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 PHP Scripts Mall Naukri Clone Script 3.0.3 has Stored XSS via every profile input field. |
1Doctor Search Script Project 1Doctor Search Script Jun 17, 2026 Feb 7, 2018 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 PHP Scripts Mall Doctor Search Script 1.0.2 has Stored XSS via an arbitrary profile field. |
Cozy version 2 has XSS allowing remote attackers to obtain administrative access via JavaScript code in the url parameter to the /api/proxy URI, as demonstrated by an XMLHttpRequest call with an 'email:"attacker@example....Show more |
IBM API Connect 5.0.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials...Show more |