← Back
CWE-79

45,999 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (45,999)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Wpshopmart
1Tabs Responsive
Nov 21, 2024
Jan 9, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The tabs-responsive plugin 1.8.0 for WordPress has XSS via the post_title parameter to wp-admin/post.php.
1Tonjoostudio
1Easy Custom Auto Excerpt
Nov 21, 2024
Jan 9, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The Easy Custom Auto Excerpt plugin 2.4.6 for WordPress has XSS via the tonjoo_ecae_options[custom_css] parameter to the wp-admin/admin.php?page=tonjoo_excerpt URI.
1Stackideas
1Easydiscuss
Nov 21, 2024
Jan 8, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The StackIdeas EasyDiscuss (aka com_easydiscuss) extension before 4.0.21 for Joomla! allows XSS.
1Gespage
1Gespage
Nov 21, 2024
Jan 8, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Multiple cross-site scripting (XSS) vulnerabilities in Gespage before 7.4.9 allow remote attackers to inject arbitrary web script or HTML via the (1) printer name when adding a printer in the admin panel or (2) username...Show more
Multiple cross-site scripting (XSS) vulnerabilities in Gespage before 7.4.9 allow remote attackers to inject arbitrary web script or HTML via the (1) printer name when adding a printer in the admin panel or (2) username parameter to webapp/users/user_reg.jsp.Show less
1Microsemi
1S350i Firmware
Nov 21, 2024
Jan 8, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in Symmetricom s350i 2.70.15 allows remote attackers to inject arbitrary web script or HTML via vectors involving system logs.
1Sonicwall
1Sonicos
Nov 21, 2024
Jan 8, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
SonicWall SonicOS on Network Security Appliance (NSA) 2017 Q4 devices has XSS via the CFS Custom Category and Cloud AV DB Exclusion Settings screens.
1Sonicwall
1Sonicos
Nov 21, 2024
Jan 8, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
SonicWall SonicOS on Network Security Appliance (NSA) 2016 Q4 devices has XSS via the Configure SSO screens.
1Gd Rating System Project
1Gd Rating System
Nov 21, 2024
Jan 8, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The GD Rating System plugin 2.3 for WordPress has XSS via the wp-admin/admin.php panel parameter for the gd-rating-system-tools page.
1Gd Rating System Project
1Gd Rating System
Nov 21, 2024
Jan 8, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The GD Rating System plugin 2.3 for WordPress has XSS via the wp-admin/admin.php panel parameter for the gd-rating-system-information page.
1Gd Rating System Project
1Gd Rating System
Nov 21, 2024
Jan 8, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The GD Rating System plugin 2.3 for WordPress has XSS via the wp-admin/admin.php panel parameter for the gd-rating-system-transfer page.
1Gd Rating System Project
1Gd Rating System
Nov 21, 2024
Jan 8, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The GD Rating System plugin 2.3 for WordPress has XSS via the wp-admin/admin.php panel parameter for the gd-rating-system-about page.
1Wpscoop
1Imageinject
Nov 21, 2024
Jan 8, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The ImageInject plugin 1.15 for WordPress has XSS via the flickr_appid parameter to wp-admin/options-general.php.
1Cobham
1Sea Tel 116 Firmware
Nov 21, 2024
Jan 8, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Persistent XSS exists in the web server on Cobham Sea Tel 116 build 222429 satellite communication system devices: remote attackers can inject malicious JavaScript code using the device's TELNET shell built-in commands,...Show more
Persistent XSS exists in the web server on Cobham Sea Tel 116 build 222429 satellite communication system devices: remote attackers can inject malicious JavaScript code using the device's TELNET shell built-in commands, as demonstrated by the "set ship name" command. This is similar to a Cross Protocol Injection with SNMP.Show less
1Shaarli Project
1Shaarli
Nov 21, 2024
Jan 5, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in Shaarli before 0.8.5 and 0.9.x before 0.9.3 allows remote attackers to inject arbitrary code via the login form's username field (aka the login parameter to the ban_canLogin fu...Show more
Cross-site scripting (XSS) vulnerability in Shaarli before 0.8.5 and 0.9.x before 0.9.3 allows remote attackers to inject arbitrary code via the login form's username field (aka the login parameter to the ban_canLogin function in index.php).Show less
1Radiantcms
1Radiant Cms
Nov 21, 2024
Jan 4, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Radiant CMS 1.1.4 has XSS via crafted Markdown input in the part_body_content parameter to an admin/pages/*/edit resource.
1Fork Cms
1Fork Cms
Nov 21, 2024
Jan 4, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Fork CMS 5.0.7 has XSS in /private/en/pages/edit via the title parameter.
1Add Link To Facebook Project
1Add Link To Facebook
Nov 21, 2024
Jan 4, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The "Add Link to Facebook" plugin through 2.3 for WordPress has XSS via the al2fb_facebook_id parameter to wp-admin/profile.php.
1Simple Download Monitor Project
1Simple Download Monitor
Nov 21, 2024
Jan 4, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The Simple Download Monitor plugin before 3.5.4 for WordPress has XSS via the sdm_upload (aka Downloadable File) parameter in an edit action to wp-admin/post.php.
1Simple Download Monitor Project
1Simple Download Monitor
Nov 21, 2024
Jan 4, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The Simple Download Monitor plugin before 3.5.4 for WordPress has XSS via the sdm_upload_thumbnail (aka File Thumbnail) parameter in an edit action to wp-admin/post.php.
1Ibm
1Security Key Lifecycle Manager
Nov 21, 2024
Jan 4, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
IBM Tivoli Key Lifecycle Manager 2.5, 2.6, and 2.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentia...Show more
IBM Tivoli Key Lifecycle Manager 2.5, 2.6, and 2.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 133640.Show less