← Back
CWE-79

45,999 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (45,999)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Dragonbyte Tech
1Vbshout
Nov 21, 2024
Jan 11, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in vbshout.php in DragonByte Technologies vBShout module for vBulletin allows remote attackers to inject arbitrary web script or HTML via the shout parameter in a shout action.
1Cisco
1Unified Communications Manager
Nov 21, 2024
Jan 11, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A vulnerability in the web-based management interface of Cisco Unified Communications Manager could allow an unauthenticated, remote attacker to perform a cross-site scripting (XSS) attack against a user of the web-based...Show more
A vulnerability in the web-based management interface of Cisco Unified Communications Manager could allow an unauthenticated, remote attacker to perform a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. The vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of an affected device. An attacker could exploit this vulnerability by persuading a user of the web-based management interface to click a link that is designed to submit malicious input to the interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface or allow the attacker to access sensitive browser-based information on the targeted device. Cisco Bug IDs: CSCvg51264.Show less
1Juniper
1Junos Space
Nov 21, 2024
Jan 10, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A reflected cross site scripting (XSS) vulnerability in Junos Space may potentially allow a remote authenticated user to inject web script or HTML and steal sensitive data and credentials from a session, and to perform a...Show more
A reflected cross site scripting (XSS) vulnerability in Junos Space may potentially allow a remote authenticated user to inject web script or HTML and steal sensitive data and credentials from a session, and to perform administrative actions on the Junos Space network management device.Show less
1Avantfax
1Avantfax
Nov 21, 2024
Jan 10, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
AvantFAX 3.3.3 has XSS via an arbitrary parameter name to the default URI, as demonstrated by a parameter whose name contains a SCRIPT element and whose value is 1.
1Officetracker
1Officetracker
Nov 21, 2024
Jan 10, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Office Tracker 11.2.5 has XSS via the logincount parameter to the /otweb/OTPClientLogin URI.
1Paloaltonetworks
1Pan Os
Nov 21, 2024
Jan 10, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in the Captive Portal function in Palo Alto Networks PAN-OS before 8.0.7 allows remote attackers to inject arbitrary web script or HTML by leveraging an unspecified configuration.
1Paloaltonetworks
1Pan Os
Nov 21, 2024
Jan 10, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.14, and 8.0.x before 8.0.7, when the GlobalProtect gateway or portal is configured, allows remote...Show more
Cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.14, and 8.0.x before 8.0.7, when the GlobalProtect gateway or portal is configured, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.Show less
1Websitebaker
1Websitebaker
Nov 21, 2024
Jan 10, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Multiple persistent stored Cross-Site-Scripting (XSS) vulnerabilities in the files /wb/admin/admintools/tool.php (Droplet Description) and /install/index.php (Site Title) in WebsiteBaker 2.10.0 allow attackers to insert...Show more
Multiple persistent stored Cross-Site-Scripting (XSS) vulnerabilities in the files /wb/admin/admintools/tool.php (Droplet Description) and /install/index.php (Site Title) in WebsiteBaker 2.10.0 allow attackers to insert persistent JavaScript code that gets reflected back to users in multiple areas in the application.Show less
1Ibm
1Qradar Security Information And Event Manager
Nov 21, 2024
Jan 10, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
IBM QRadar 7.2 and 7.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials d...Show more
IBM QRadar 7.2 and 7.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 133121.Show less
1Ibm
1Security Access Manager 9.0 Firmware
Nov 21, 2024
Jan 10, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
IBM Security Access Manager Appliance 9.0.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially lea...Show more
IBM Security Access Manager Appliance 9.0.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 130675.Show less
1Apache
1Activemq
Nov 21, 2024
Jan 10, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In Apache ActiveMQ 5.x before 5.14.2, an instance of a cross-site scripting vulnerability was identified to be present in the web based administration console. The root cause of this issue is improper user data output va...Show more
In Apache ActiveMQ 5.x before 5.14.2, an instance of a cross-site scripting vulnerability was identified to be present in the web based administration console. The root cause of this issue is improper user data output validation.Show less
1Apache
2Sling Xss Protection Api
Sling Xss Protection Api Compat
Nov 21, 2024
Jan 10, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A flaw in the way URLs are escaped and encoded in the org.apache.sling.xss.impl.XSSAPIImpl#getValidHref and org.apache.sling.xss.impl.XSSFilterImpl#isValidHref allows special crafted URLs to pass as valid, although they...Show more
A flaw in the way URLs are escaped and encoded in the org.apache.sling.xss.impl.XSSAPIImpl#getValidHref and org.apache.sling.xss.impl.XSSFilterImpl#isValidHref allows special crafted URLs to pass as valid, although they carry XSS payloads. The affected versions are Apache Sling XSS Protection API 1.0.4 to 1.0.18, Apache Sling XSS Protection API Compat 1.1.0 and Apache Sling XSS Protection API 2.0.0.Show less
1Discuz
1Discuzx
Nov 21, 2024
Jan 10, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Discuz! DiscuzX X3.4 has XSS via the view parameter to include/space/space_poll.php, as demonstrated by a mod=space do=poll request to home.php.
1Flatcore
1Flatcore Cms
Nov 21, 2024
Jan 10, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
flatCore-CMS 1.4.6 is vulnerable to reflected XSS in user_management.php due to the use of $_SERVER['PHP_SELF'] to build links and a stored XSS in the admin log panel by specifying a malformed User-Agent string.
1Broadcom
2Advanced Secure Gateway
Symantec Proxysg
Nov 21, 2024
Jan 10, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Symantec Advanced Secure Gateway (ASG) 6.6, ASG 6.7 (prior to 6.7.2.1), ProxySG 6.5 (prior to 6.5.10.6), ProxySG 6.6, and ProxySG 6.7 (prior to 6.7.2.1) management console is susceptible to a reflected XSS vulnerabil...Show more
The Symantec Advanced Secure Gateway (ASG) 6.6, ASG 6.7 (prior to 6.7.2.1), ProxySG 6.5 (prior to 6.5.10.6), ProxySG 6.6, and ProxySG 6.7 (prior to 6.7.2.1) management console is susceptible to a reflected XSS vulnerability. A remote attacker can use a crafted management console URL in a phishing attack to inject arbitrary JavaScript code into the management console web client application. This is a separate vulnerability from CVE-2016-10256.Show less
1Broadcom
1Symantec Proxysg
Nov 21, 2024
Jan 10, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Symantec ProxySG 6.5 (prior to 6.5.10.6), 6.6, and 6.7 (prior to 6.7.2.1) management console is susceptible to a reflected XSS vulnerability. A remote attacker can use a crafted management console URL in a phishing a...Show more
The Symantec ProxySG 6.5 (prior to 6.5.10.6), 6.6, and 6.7 (prior to 6.7.2.1) management console is susceptible to a reflected XSS vulnerability. A remote attacker can use a crafted management console URL in a phishing attack to inject arbitrary JavaScript code into the management console web client application. This is a separate vulnerability from CVE-2016-10257.Show less
1Microsoft
1Sharepoint Enterprise Server
Nov 21, 2024
Jan 10, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Microsoft Access in Microsoft SharePoint Enterprise Server 2013 and Microsoft SharePoint Enterprise Server 2016 allows a cross-site-scripting (XSS) vulnerability due to the way image field values are handled, aka "Micros...Show more
Microsoft Access in Microsoft SharePoint Enterprise Server 2013 and Microsoft SharePoint Enterprise Server 2016 allows a cross-site-scripting (XSS) vulnerability due to the way image field values are handled, aka "Microsoft Access Tampering Vulnerability".Show less
1Patsatech
1Sagepay Server Gateway For Woocommerce
Nov 21, 2024
Jan 9, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The "SagePay Server Gateway for WooCommerce" plugin before 1.0.9 for WordPress has XSS via the includes/pages/redirect.php page parameter.
1Sulu
1Sulu Standard
Nov 21, 2024
Jan 9, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Sulu-standard version 1.6.6 is vulnerable to stored cross-site scripting vulnerability, within the page creation page, which can result in disruption of service and execution of javascript code.
1Finecms Project
1Finecms
Nov 21, 2024
Jan 9, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
rui Li finecms 5.0.10 is vulnerable to a reflected XSS in the file Weixin.php.