CWE-79
45,998 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (45,998)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Cloudfoundry Pivotal3Cf Release UaaUaa BoshNov 21, 2024 Jan 4, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in these Pivotal Cloud Foundry products: all versions prior to cf-release v270, UAA v3.x prior to v3.20.2, and UAA bosh v30.x versions prior to v30.8 and all other versions prior to v45.0. A cross...Show more |
1Dell 2Emc Vnx1 Firmware Emc Vnx2 FirmwareNov 21, 2024 Jan 4, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 In Dell EMC VNX2 versions prior to Operating Environment for File 8.1.9.217 and VNX1 versions prior to Operating Environment for File 7.1.80.8, a web server error page in VNX Control Station is impacted by a reflected cr...Show more |
1Advanced Real Estate Script Project 1Advanced Real Estate Script Nov 21, 2024 Jan 3, 2018 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 Online Ticket Booking has XSS via the admin/eventlist.php cast parameter. |
1Advanced Real Estate Script Project 1Advanced Real Estate Script Nov 21, 2024 Jan 3, 2018 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 Online Ticket Booking has XSS via the admin/movieedit.php moviename parameter. |
1Advanced Real Estate Script Project 1Advanced Real Estate Script Nov 21, 2024 Jan 3, 2018 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 Online Ticket Booking has XSS via the admin/newsedit.php newstitle parameter. |
1Advanced Real Estate Script Project 1Advanced Real Estate Script Nov 21, 2024 Jan 3, 2018 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 Online Ticket Booking has XSS via the admin/snacks_edit.php snacks_name parameter. |
1Advanced Real Estate Script Project 1Advanced Real Estate Script Nov 21, 2024 Jan 3, 2018 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 Online Ticket Booking has XSS via the admin/manageownerlist.php contact parameter. |
1Advanced Real Estate Script Project 1Advanced Real Estate Script Nov 21, 2024 Jan 3, 2018 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 Online Ticket Booking has XSS via the admin/sitesettings.php keyword parameter. |
BookStack version 0.18.4 is vulnerable to stored cross-site scripting, within the page creation page, which can result in disruption of service and execution of javascript code. |
A member of the Plone 2.5-5.1rc1 site could set javascript in the home_page property of his profile, and have this executed when a visitor click the home page link on the author page. |
ELabftw version 1.7.8 is vulnerable to stored cross-site scripting in the experiment infos component resulting in arbitrary execution of JavaScript and denial of service. |
2Acquia Mautic2Mautic MauticNov 21, 2024 Jan 3, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Mautic version 2.1.0 - 2.11.0 is vulnerable to an inline JS XSS attack when using Mautic forms on a Mautic landing page using GET parameters to pre-populate the form. |
LavaLite version 5.2.4 is vulnerable to stored cross-site scripting vulnerability, within the blog creation page, which can result in disruption of service and execution of javascript code. |
QuickApps CMS version 2.0.0 is vulnerable to Stored Cross-site Scripting in the user's real name field resulting in denial of service and performing unauthorised actions with an administrator user's account |
Leanote-desktop version v2.5 is vulnerable to a XSS which leads to code execution due to enabled node integration |
Shiba markdown live preview app version 1.1.0 is vulnerable to XSS which leads to code execution due to enabled node integration. |
Invoice Ninja version 3.8.1 is vulnerable to stored cross-site scripting vulnerability, within the invoice creation page, which can result in disruption of service and execution of javascript code. |
Leafpub version 1.2.0-beta6 is vulnerable to stored cross-site scripting vulnerability, within the edit blog post page, which can result in disruption of service and execution of javascript code. |
Leanote version <= 2.5 is vulnerable to XSS due to not sanitized input in markdown notes |
marked version 0.3.6 and earlier is vulnerable to an XSS attack in the data: URI parser. |