← Back
CWE-79

46,000 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (46,000)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Automattic
1Jetpack
Nov 21, 2024
Jan 12, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Jetpack plugin before 4.0.4 for WordPress has XSS via the Likes module.
1Sophos
1Sfos
Nov 21, 2024
Jan 12, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An NC-25986 issue was discovered in the Logging subsystem of Sophos XG Firewall with SFOS before 17.0.3 MR3. An unauthenticated user can trigger a persistent XSS vulnerability found in the WAF log page (Control Center ->...Show more
An NC-25986 issue was discovered in the Logging subsystem of Sophos XG Firewall with SFOS before 17.0.3 MR3. An unauthenticated user can trigger a persistent XSS vulnerability found in the WAF log page (Control Center -> Log Viewer -> in the filter option "Web Server Protection") in the webadmin interface, and execute any action available to the webadmin of the firewall (e.g., creating a new user, enabling SSH, or adding an SSH authorized key). The WAF log page will execute the "User-Agent" parameter in the HTTP POST request.Show less
1Ibm
1Security Identity Manager
Nov 21, 2024
Jan 12, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-site scripting (XSS) vulnerability in IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.0 before 7.0.1-ISS-SIM-FP0001 allows remote authenticated users to inject arbitrary web script or H...Show more
Cross-site scripting (XSS) vulnerability in IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.0 before 7.0.1-ISS-SIM-FP0001 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors. IBM X-Force ID: 111737.Show less
1Atlassian
1Jira
Nov 21, 2024
Jan 12, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The issue search resource in Atlassian Jira before version 7.4.2 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the orderby parameter.
1Atlassian
2Jira
Jira Server
Nov 21, 2024
Jan 12, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The printable searchrequest issue resource in Atlassian Jira before version 7.2.12 and from version 7.3.0 before 7.6.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulne...Show more
The printable searchrequest issue resource in Atlassian Jira before version 7.2.12 and from version 7.3.0 before 7.6.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the jqlQuery query parameter.Show less
1Discuz
1Discuzx
Nov 21, 2024
Jan 12, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Discuz! DiscuzX X3.4 has XSS via the include\spacecp\spacecp_upload.php op parameter.
1Discuz
1Discuzx
Nov 21, 2024
Jan 12, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Discuz! DiscuzX X3.4 has XSS via the include\spacecp\spacecp_space.php appid parameter in a delete action.
1Srbtranslatin Project
1Srbtranslatin
Nov 21, 2024
Jan 12, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The SrbTransLatin plugin 1.46 for WordPress has XSS via an srbtranslatoptions action to wp-admin/options-general.php with a lang_identificator parameter.
1Wpglobus
1Wpglobus
Nov 21, 2024
Jan 12, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The WPGlobus plugin 1.9.6 for WordPress has XSS via the wpglobus_option[post_type][post] parameter to wp-admin/options.php.
1Wpglobus
1Wpglobus
Nov 21, 2024
Jan 12, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The WPGlobus plugin 1.9.6 for WordPress has XSS via the wpglobus_option[more_languages] parameter to wp-admin/options.php.
1Wpglobus
1Wpglobus
Nov 21, 2024
Jan 12, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The WPGlobus plugin 1.9.6 for WordPress has XSS via the wpglobus_option[selector_wp_list_pages][show_selector] parameter to wp-admin/options.php.
1Wpglobus
1Wpglobus
Nov 21, 2024
Jan 12, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The WPGlobus plugin 1.9.6 for WordPress has XSS via the wpglobus_option[browser_redirect][redirect_by_language] parameter to wp-admin/options.php.
1Wpglobus
1Wpglobus
Nov 21, 2024
Jan 12, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The WPGlobus plugin 1.9.6 for WordPress has XSS via the wpglobus_option[enabled_languages][en] or wpglobus_option[enabled_languages][fr] (or any other language) parameter to wp-admin/options.php.
1Wpglobus
1Wpglobus
Nov 21, 2024
Jan 12, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The WPGlobus plugin 1.9.6 for WordPress has XSS via the wpglobus_option[post_type][page] parameter to wp-admin/options.php.
1Dragonbyte Tech
1Vbdownloads Module
Nov 21, 2024
Jan 11, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in downloads/actions/editdownload.php in the DragonByte Technologies vBDownloads module 1.3.2 and earlier for vBulletin allows remote attackers to inject arbitrary web script or H...Show more
Cross-site scripting (XSS) vulnerability in downloads/actions/editdownload.php in the DragonByte Technologies vBDownloads module 1.3.2 and earlier for vBulletin allows remote attackers to inject arbitrary web script or HTML via the mirrors[] parameter.Show less
1Dragonbyte Tech
1Forumon Rpg Module
Nov 21, 2024
Jan 11, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Multiple cross-site scripting (XSS) vulnerabilities in actions/main.php in the DragonByte Technologies Forumon RPG module before 1.0.8 for vBulletin when creating a new monster, allow remote attackers to inject arbitrary...Show more
Multiple cross-site scripting (XSS) vulnerabilities in actions/main.php in the DragonByte Technologies Forumon RPG module before 1.0.8 for vBulletin when creating a new monster, allow remote attackers to inject arbitrary web script or HTML via the (1) monster[title] or (2) monster[description] parameters.Show less
1Dragonbyte Tech
1Vbactivity Module
Nov 21, 2024
Jan 11, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Multiple cross-site scripting (XSS) vulnerabilities in the DragonByte Technologies vbActivity module before 3.0.1 for vBulletin allow remote attackers to inject arbitrary web script or HTML via the reason parameter in (1...Show more
Multiple cross-site scripting (XSS) vulnerabilities in the DragonByte Technologies vbActivity module before 3.0.1 for vBulletin allow remote attackers to inject arbitrary web script or HTML via the reason parameter in (1) actions/nominatemedal.php or (2) actions/requestmedal.php.Show less
1Dragonbyte Tech
1Vbshout Module
Nov 21, 2024
Jan 11, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Multiple cross-site scripting (XSS) vulnerabilities in the Shout Reports in the DragonByte Technologies vBShout module before 6.0.6 for vBulletin allow remote attackers to inject arbitrary web script or HTML via the (1)...Show more
Multiple cross-site scripting (XSS) vulnerabilities in the Shout Reports in the DragonByte Technologies vBShout module before 6.0.6 for vBulletin allow remote attackers to inject arbitrary web script or HTML via the (1) reportreason parameter in actions/doreport.php or (2) modnotes parameter in actions/updatereport.php.Show less
1Ibm
1Websphere Portal
Nov 21, 2024
Jan 11, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
IBM WebSphere Portal 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to cre...Show more
IBM WebSphere Portal 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 137158.Show less
1Ibm
1Curam Social Program Management
Nov 21, 2024
Jan 11, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM Curam Social Program Management 6.0.5, 6.1.1, 6.2.0, 7.0.1, and 7.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended...Show more
IBM Curam Social Program Management 6.0.5, 6.1.1, 6.2.0, 7.0.1, and 7.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 134922.Show less