CWE-79
45,999 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (45,999)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The tabs-responsive plugin 1.8.0 for WordPress has XSS via the post_title parameter to wp-admin/post.php. |
1Tonjoostudio 1Easy Custom Auto Excerpt Nov 21, 2024 Jan 9, 2018 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 The Easy Custom Auto Excerpt plugin 2.4.6 for WordPress has XSS via the tonjoo_ecae_options[custom_css] parameter to the wp-admin/admin.php?page=tonjoo_excerpt URI. |
The StackIdeas EasyDiscuss (aka com_easydiscuss) extension before 4.0.21 for Joomla! allows XSS. |
Multiple cross-site scripting (XSS) vulnerabilities in Gespage before 7.4.9 allow remote attackers to inject arbitrary web script or HTML via the (1) printer name when adding a printer in the admin panel or (2) username...Show more |
Cross-site scripting (XSS) vulnerability in Symmetricom s350i 2.70.15 allows remote attackers to inject arbitrary web script or HTML via vectors involving system logs. |
SonicWall SonicOS on Network Security Appliance (NSA) 2017 Q4 devices has XSS via the CFS Custom Category and Cloud AV DB Exclusion Settings screens. |
SonicWall SonicOS on Network Security Appliance (NSA) 2016 Q4 devices has XSS via the Configure SSO screens. |
1Gd Rating System Project 1Gd Rating System Nov 21, 2024 Jan 8, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The GD Rating System plugin 2.3 for WordPress has XSS via the wp-admin/admin.php panel parameter for the gd-rating-system-tools page. |
1Gd Rating System Project 1Gd Rating System Nov 21, 2024 Jan 8, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The GD Rating System plugin 2.3 for WordPress has XSS via the wp-admin/admin.php panel parameter for the gd-rating-system-information page. |
1Gd Rating System Project 1Gd Rating System Nov 21, 2024 Jan 8, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The GD Rating System plugin 2.3 for WordPress has XSS via the wp-admin/admin.php panel parameter for the gd-rating-system-transfer page. |
1Gd Rating System Project 1Gd Rating System Nov 21, 2024 Jan 8, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The GD Rating System plugin 2.3 for WordPress has XSS via the wp-admin/admin.php panel parameter for the gd-rating-system-about page. |
The ImageInject plugin 1.15 for WordPress has XSS via the flickr_appid parameter to wp-admin/options-general.php. |
Persistent XSS exists in the web server on Cobham Sea Tel 116 build 222429 satellite communication system devices: remote attackers can inject malicious JavaScript code using the device's TELNET shell built-in commands,...Show more |
Cross-site scripting (XSS) vulnerability in Shaarli before 0.8.5 and 0.9.x before 0.9.3 allows remote attackers to inject arbitrary code via the login form's username field (aka the login parameter to the ban_canLogin fu...Show more |
Radiant CMS 1.1.4 has XSS via crafted Markdown input in the part_body_content parameter to an admin/pages/*/edit resource. |
Fork CMS 5.0.7 has XSS in /private/en/pages/edit via the title parameter. |
1Add Link To Facebook Project 1Add Link To Facebook Nov 21, 2024 Jan 4, 2018 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 The "Add Link to Facebook" plugin through 2.3 for WordPress has XSS via the al2fb_facebook_id parameter to wp-admin/profile.php. |
1Simple Download Monitor Project 1Simple Download Monitor Nov 21, 2024 Jan 4, 2018 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 The Simple Download Monitor plugin before 3.5.4 for WordPress has XSS via the sdm_upload (aka Downloadable File) parameter in an edit action to wp-admin/post.php. |
1Simple Download Monitor Project 1Simple Download Monitor Nov 21, 2024 Jan 4, 2018 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 The Simple Download Monitor plugin before 3.5.4 for WordPress has XSS via the sdm_upload_thumbnail (aka File Thumbnail) parameter in an edit action to wp-admin/post.php. |
1Ibm 1Security Key Lifecycle Manager Nov 21, 2024 Jan 4, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 IBM Tivoli Key Lifecycle Manager 2.5, 2.6, and 2.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentia...Show more |