← Back
CWE-79

46,003 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (46,003)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ibm
1Engineering Requirements Management Doors
Feb 5, 2025
Jan 26, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM Doors Web Access 9.5 and 9.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to cre...Show more
IBM Doors Web Access 9.5 and 9.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 130808.Show less
1Ibm
1Engineering Requirements Management Doors
Feb 5, 2025
Jan 26, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM DOORS 9.5 and 9.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials di...Show more
IBM DOORS 9.5 and 9.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 130411.Show less
1Ibm
1Cognos Tm1
Nov 21, 2024
Jan 26, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
IBM Cognos TM1 10.2 and 10.2.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to crede...Show more
IBM Cognos TM1 10.2 and 10.2.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 129617.Show less
1Wondercms
1Wondercms
Nov 21, 2024
Jan 26, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In WonderCMS 2.3.1, the application's input fields accept arbitrary user input resulting in execution of malicious JavaScript. NOTE: the vendor disputes this issue stating that this is a feature that enables only a logge...Show more
In WonderCMS 2.3.1, the application's input fields accept arbitrary user input resulting in execution of malicious JavaScript. NOTE: the vendor disputes this issue stating that this is a feature that enables only a logged in administrator to write execute JavaScript anywhere on their websiteShow less
1Sophos
1Puremessage
Nov 21, 2024
Jan 26, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in Sophos PureMessage for UNIX before 6.3.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
1Jenkins
1Delivery Pipeline
Nov 21, 2024
Jan 26, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Jenkins Delivery Pipeline Plugin version 1.0.7 and earlier used the unescaped content of the query parameter 'fullscreen' in its JavaScript, resulting in a cross-site scripting vulnerability through specially crafted...Show more
The Jenkins Delivery Pipeline Plugin version 1.0.7 and earlier used the unescaped content of the query parameter 'fullscreen' in its JavaScript, resulting in a cross-site scripting vulnerability through specially crafted URLs.Show less
1Jenkins
1Jenkins
Nov 21, 2024
Jan 26, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Jenkins 2.88 and earlier; 2.73.2 and earlier Autocompletion suggestions for text fields were not escaped, resulting in a persisted cross-site scripting vulnerability if the source for the suggestions allowed specifying t...Show more
Jenkins 2.88 and earlier; 2.73.2 and earlier Autocompletion suggestions for text fields were not escaped, resulting in a persisted cross-site scripting vulnerability if the source for the suggestions allowed specifying text that includes HTML metacharacters like less-than and greater-than characters.Show less
1Jenkins
1Global Build Stats
Nov 21, 2024
Jan 26, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Some URLs provided by Jenkins global-build-stats plugin version 1.4 and earlier returned a JSON response that contained request parameters. These responses had the Content Type: text/html, so could have been interpreted...Show more
Some URLs provided by Jenkins global-build-stats plugin version 1.4 and earlier returned a JSON response that contained request parameters. These responses had the Content Type: text/html, so could have been interpreted as HTML by clients, resulting in a potential reflected cross-site scripting vulnerability. Additionally, some URLs provided by global-build-stats plugin that modify data did not require POST requests to be sent, resulting in a potential cross-site request forgery vulnerability.Show less
1Jenkins
1Active Choices
Nov 21, 2024
Jan 26, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Jenkins Active Choices plugin version 1.5.3 and earlier allowed users with Job/Configure permission to provide arbitrary HTML to be shown on the 'Build With Parameters' page through the 'Active Choices Reactive Reference...Show more
Jenkins Active Choices plugin version 1.5.3 and earlier allowed users with Job/Configure permission to provide arbitrary HTML to be shown on the 'Build With Parameters' page through the 'Active Choices Reactive Reference Parameter' type. This could include, for example, arbitrary JavaScript. Active Choices now sanitizes the HTML inserted on the 'Build With Parameters' page if and only if the script is executed in a sandbox. As unsandboxed scripts are subject to administrator approval, it is up to the administrator to allow or disallow problematic script output.Show less
1Wbce
1Wbce Cms
Jun 17, 2026
Jan 25, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Cross-site scripting (XSS) in WBCE CMS 1.3.1 allows remote authenticated administrators to inject arbitrary web script or HTML via the Modify Page screen, a different issue than CVE-2017-2118.
1Cmsmadesimple
1Cms Made Simple
Jun 17, 2026
Jan 25, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
CMS Made Simple (CMSMS) 2.2.5 has XSS in admin/moduleinterface.php via the m1_errors parameter.
1Cmsmadesimple
1Cms Made Simple
Jun 17, 2026
Jan 25, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
CMS Made Simple (CMSMS) 2.2.5 has XSS in admin/moduleinterface.php via the m1_messages parameter.
1Cmsmadesimple
1Cms Made Simple
Jun 17, 2026
Jan 25, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
CMS Made Simple (CMSMS) 2.2.5 has XSS in admin/addbookmark.php via the title parameter.
1Netis Systems
1Wf2419 Firmware
Jun 17, 2026
Jan 25, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Netis WF2419 V2.2.36123 devices allow XSS via the Description parameter on the Bandwidth Control Rule Settings page.
1Routers2 Project
1Routers2
Jun 17, 2026
Jan 24, 2018
N/A· v4
4.7 MEDIUM· v3
2.6 LOW· v2
A Cross-Site Scripting (XSS) vulnerability was found in Routers2 2.24, affecting the 'rtr' GET parameter in a page=graph action to cgi-bin/routers2.pl.
1Netis Systems
1Wf2419 Firmware
Jun 17, 2026
Jan 24, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Netis WF2419 V3.2.41381 devices allow XSS via the Description field on the MAC Filtering page.
1Reservo
1Image Hosting
Jun 17, 2026
Jan 24, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Reservo Image Hosting 1.6 is vulnerable to XSS attacks. The affected function is its search engine (the t parameter to the /search URI). Since there is an user/admin login interface, it's possible for attackers to steal...Show more
Reservo Image Hosting 1.6 is vulnerable to XSS attacks. The affected function is its search engine (the t parameter to the /search URI). Since there is an user/admin login interface, it's possible for attackers to steal sessions of users and thus admin(s). By sending users an infected URL, code will be executed.Show less
4Canonical
DebianGnu+1 more
9Debian Linux
Enterprise Linux DesktopEnterprise Linux Server+6 more
Jun 17, 2026
Jan 23, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in the web UI in Mailman before 2.1.26 allows remote attackers to inject arbitrary web script or HTML via a user-options URL.
1Hp
1Jetadvantage Security Manager
Nov 21, 2024
Jan 23, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Potential security vulnerabilities have been identified with HP JetAdvantage Security Manager before 3.0.1. The vulnerabilities could potentially be exploited to allow stored cross-site scripting which could allow a hack...Show more
Potential security vulnerabilities have been identified with HP JetAdvantage Security Manager before 3.0.1. The vulnerabilities could potentially be exploited to allow stored cross-site scripting which could allow a hacker to create a denial of service.Show less
1Hp
1Jetadvantage Security Manager
Nov 21, 2024
Jan 23, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Potential security vulnerabilities have been identified with HP JetAdvantage Security Manager before 3.0.1. The vulnerabilities could potentially be exploited to allow stored cross-site scripting which could allow a hack...Show more
Potential security vulnerabilities have been identified with HP JetAdvantage Security Manager before 3.0.1. The vulnerabilities could potentially be exploited to allow stored cross-site scripting which could allow a hacker to execute scripts in a user's browser.Show less