← Back
CWE-79

46,003 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (46,003)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Atlassian
1Bamboo
Nov 21, 2024
Feb 2, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The viewDeploymentVersionCommits resource in Atlassian Bamboo before version 6.2.0 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the name of a release.
1Atlassian
1Jira
Nov 21, 2024
Feb 2, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The IncomingMailServers resource in Atlassian Jira from version 6.2.1 before version 7.4.4 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the messagesThre...Show more
The IncomingMailServers resource in Atlassian Jira from version 6.2.1 before version 7.4.4 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the messagesThreshold parameter.Show less
1Atlassian
2Crucible
Fisheye
Nov 21, 2024
Feb 2, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The source browse resource in Atlassian Fisheye and Crucible before version 4.5.1 and 4.6.0 allows allows remote attackers that have write access to an indexed repository to inject arbitrary HTML or JavaScript via a cros...Show more
The source browse resource in Atlassian Fisheye and Crucible before version 4.5.1 and 4.6.0 allows allows remote attackers that have write access to an indexed repository to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in via a specially crafted repository branch name when trying to display deleted files of the branch.Show less
1Monstra
1Monstra
Jun 17, 2026
Feb 2, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Monstra CMS through 3.0.4 has XSS in the title function in plugins/box/pages/pages.plugin.php via a page title to admin/index.php.
1Ipswitch
1Moveit
Jun 17, 2026
Feb 2, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Ipswitch MoveIt v8.1 is vulnerable to a Stored Cross-Site Scripting (XSS) vulnerability, as demonstrated by human.aspx. Attackers can leverage this vulnerability to send malicious messages to other users in order to stea...Show more
Ipswitch MoveIt v8.1 is vulnerable to a Stored Cross-Site Scripting (XSS) vulnerability, as demonstrated by human.aspx. Attackers can leverage this vulnerability to send malicious messages to other users in order to steal session cookies and launch client-side attacks.Show less
1Meowapps
1Wp Retina 2x
Nov 21, 2024
Feb 1, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting vulnerability in WP Retina 2x prior to version 5.2.2 allows an attacker to inject arbitrary web script or HTML via unspecified vectors.
1Kkcald Project
1Kkcald
Nov 21, 2024
Feb 1, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting vulnerability in epg search result viewer (kkcald) 0.7.21 and earlier allows an attacker to inject arbitrary web script or HTML via unspecified vectors.
1Wp Property Hive
1Propertyhive
Jun 17, 2026
Jan 31, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The PropertyHive plugin before 1.4.15 for WordPress has XSS via the body parameter to includes/admin/views/html-preview-applicant-matches-email.php.
1Mycolorway
1Simditor
Jun 17, 2026
Jan 31, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Simditor v2.3.11 allows XSS via crafted use of svg/onload=alert in a TEXTAREA element, as demonstrated by Firefox 54.0.1.
1Splashing Images Project
1Splashing Images
Jun 17, 2026
Jan 30, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
A cross-site scripting (XSS) vulnerability in admin/partials/wp-splashing-admin-sidebar.php in the Splashing Images plugin (wp-splashing-images) before 2.1.1 for WordPress allows remote attackers to inject arbitrary web...Show more
A cross-site scripting (XSS) vulnerability in admin/partials/wp-splashing-admin-sidebar.php in the Splashing Images plugin (wp-splashing-images) before 2.1.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the search parameter to wp-admin/upload.php.Show less
1Joomla
1Joomla
Jun 17, 2026
Jan 30, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In Joomla! before 3.8.4, lack of escaping in the module chromes leads to XSS vulnerabilities in the module system.
1Joomla
1Joomla
Jun 17, 2026
Jan 30, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In Joomla! before 3.8.4, inadequate input filtering in the Uri class (formerly JUri) leads to an XSS vulnerability.
1Joomla
1Joomla
Jun 17, 2026
Jan 30, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In Joomla! before 3.8.4, inadequate input filtering in com_fields leads to an XSS vulnerability in multiple field types, i.e., list, radio, and checkbox
1Iball
1Ib Wrb302n Firmware
Jun 17, 2026
Jan 30, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
/goform/setLang on iBall 300M devices with "iB-WRB302N_1.0.1-Sep 8 2017" firmware has Unauthenticated Stored Cross Site Scripting via the lang parameter.
1Fortinet
1Fortios
Nov 21, 2024
Jan 29, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A Cross-site Scripting vulnerability in Fortinet FortiOS 5.6.0 to 5.6.2, 5.4.0 to 5.4.7, 5.2 and earlier, allows attacker to inject arbitrary web script or HTML via maliciously crafted "Host" header in user HTTP requests...Show more
A Cross-site Scripting vulnerability in Fortinet FortiOS 5.6.0 to 5.6.2, 5.4.0 to 5.4.7, 5.2 and earlier, allows attacker to inject arbitrary web script or HTML via maliciously crafted "Host" header in user HTTP requests.Show less
1Acurax
1Social Media Widget
Jun 17, 2026
Jan 27, 2018
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
The acx_asmw_saveorder_callback function in function.php in the acurax-social-media-widget plugin before 3.2.6 for WordPress has CSRF via the recordsArray parameter to wp-admin/admin-ajax.php, with resultant social_widge...Show more
The acx_asmw_saveorder_callback function in function.php in the acurax-social-media-widget plugin before 3.2.6 for WordPress has CSRF via the recordsArray parameter to wp-admin/admin-ajax.php, with resultant social_widget_icon_array_order XSS.Show less
1Formspree
1Formspree
Jun 17, 2026
Jan 27, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
templates/forms/thanks.html in Formspree before 2018-01-23 allows XSS related to the _next parameter.
1Ibm
7Rational Collaborative Lifecycle Management
Rational Doors Next GenerationRational Engineering Lifecycle Manager+4 more
Nov 21, 2024
Jan 26, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM Jazz Foundation (IBM Rational Collaborative Lifecycle Management 6.0.x) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intend...Show more
IBM Jazz Foundation (IBM Rational Collaborative Lifecycle Management 6.0.x) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 133268.Show less
1Ibm
1Engineering Requirements Management Doors
Feb 5, 2025
Jan 26, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM Doors Web Access 9.5 and 9.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to cre...Show more
IBM Doors Web Access 9.5 and 9.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 131769.Show less
1Ibm
1Engineering Requirements Management Doors
Feb 5, 2025
Jan 26, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM Doors Web Access 9.5 and 9.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to cre...Show more
IBM Doors Web Access 9.5 and 9.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 131763.Show less