CWE-79
46,005 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (46,005)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Promise Technology WebPam Pro-E devices allow remote attackers to conduct XSS, HTTP Response Splitting, and CRLF Injection attacks via JavaScript code in a PHPSESSID cookie. |
tiki wiki cms groupware <=15.2 has a xss vulnerability, allow attackers steal user's cookie. |
Cross-site scripting (XSS) vulnerability in assets/js/vm2admin.js in the VirtueMart component before 3.0.8 for Joomla! allows remote attackers to inject arbitrary web script or HTML via vectors involving a "double encode...Show more |
1Nagios 1Business Process Intelligence Nov 21, 2024 Feb 6, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Cross-site scripting (XSS) vulnerability in Nagios Business Process Intelligence (BPI) before 2.3.4 allows remote attackers to inject arbitrary web script or HTML via vectors involving index.php. |
1Kaspersky 1Secure Mail Gateway Jun 17, 2026 Feb 6, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 WebConsole Cross-Site Scripting in Kaspersky Secure Mail Gateway version 1.1. |
A cross-site scripting (XSS) vulnerability in flickrRSS.php in the flickrRSS plugin 5.3.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the flickrRSS_tags parameter to wp-admin/options-...Show more |
A cross-site scripting (XSS) vulnerability in flickrRSS.php in the flickrRSS plugin 5.3.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the flickrRSS_id parameter to wp-admin/options-ge...Show more |
A cross-site scripting (XSS) vulnerability in flickrRSS.php in the flickrRSS plugin 5.3.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the flickrRSS_set parameter to wp-admin/options-g...Show more |
1Synacor 1Zimbra Collaboration Suite Nov 21, 2024 Feb 4, 2018 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 Synacor Zimbra Collaboration Suite (ZCS) before 8.7.10 has Persistent XSS. |
1Synacor 1Zimbra Collaboration Suite Nov 21, 2024 Feb 4, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Synacor Zimbra Collaboration Suite (ZCS) before 8.8.3 has Persistent XSS. |
1Ibm 1Tivoli Business Service Manager Nov 21, 2024 Feb 2, 2018 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 Cross-site scripting (XSS) vulnerability in IBM Tivoli Business Service Manager 6.1.0 before 6.1.0-TIV-BSM-FP0004 and 6.1.1 before 6.1.1-TIV-BSM-FP0004 allows remote attackers to inject arbitrary web script or HTML via u...Show more |
Cross-site scripting (XSS) vulnerability in IBM Tivoli Integrated Portal 2.2.0.0 through 2.2.0.15 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. |
Multiple cross-site scripting (XSS) vulnerabilities in Project-Pier ProjectPier-Core allow remote attackers to inject arbitrary web script or HTML via the search_for parameter to (1) search_by_tag.php, (2) search_contact...Show more |
dijit.Editor in Dojo Toolkit 1.13 allows XSS via the onload attribute of an SVG element. |
2Debian Simplesamlphp2Debian Linux SimplesamlphpNov 21, 2024 Feb 2, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The consentAdmin module in SimpleSAMLphp through 1.14.15 is vulnerable to a Cross-Site Scripting attack, allowing an attacker to craft links that could execute arbitrary JavaScript code on the victim's web browser. |
Various resources in Atlassian Confluence Server before version 6.4.2 allow remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the issuesURL parameter. |
The viewdefaultdecorator resource in Atlassian Confluence Server before version 6.6.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the key paramete...Show more |
The usermacros resource in Atlassian Confluence Server before version 6.3.4 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the description of a macro...Show more |
The editinword resource in Atlassian Confluence Server before version 6.4.0 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the contents of an uploade...Show more |
The plan configure branches resource in Atlassian Bamboo before version 6.2.3 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the name of a branch. |