← Back
CWE-79

45,998 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (45,998)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Cloudfoundry
Pivotal
3Cf Release
UaaUaa Bosh
Nov 21, 2024
Jan 4, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in these Pivotal Cloud Foundry products: all versions prior to cf-release v270, UAA v3.x prior to v3.20.2, and UAA bosh v30.x versions prior to v30.8 and all other versions prior to v45.0. A cross...Show more
An issue was discovered in these Pivotal Cloud Foundry products: all versions prior to cf-release v270, UAA v3.x prior to v3.20.2, and UAA bosh v30.x versions prior to v30.8 and all other versions prior to v45.0. A cross-site scripting (XSS) attack is possible in the clientId parameter of a request to the UAA OpenID Connect check session iframe endpoint used for single logout session management.Show less
1Dell
2Emc Vnx1 Firmware
Emc Vnx2 Firmware
Nov 21, 2024
Jan 4, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In Dell EMC VNX2 versions prior to Operating Environment for File 8.1.9.217 and VNX1 versions prior to Operating Environment for File 7.1.80.8, a web server error page in VNX Control Station is impacted by a reflected cr...Show more
In Dell EMC VNX2 versions prior to Operating Environment for File 8.1.9.217 and VNX1 versions prior to Operating Environment for File 7.1.80.8, a web server error page in VNX Control Station is impacted by a reflected cross-site scripting vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability to execute arbitrary HTML code in the user's browser session in the context of the affected web application.Show less
1Advanced Real Estate Script Project
1Advanced Real Estate Script
Nov 21, 2024
Jan 3, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Online Ticket Booking has XSS via the admin/eventlist.php cast parameter.
1Advanced Real Estate Script Project
1Advanced Real Estate Script
Nov 21, 2024
Jan 3, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Online Ticket Booking has XSS via the admin/movieedit.php moviename parameter.
1Advanced Real Estate Script Project
1Advanced Real Estate Script
Nov 21, 2024
Jan 3, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Online Ticket Booking has XSS via the admin/newsedit.php newstitle parameter.
1Advanced Real Estate Script Project
1Advanced Real Estate Script
Nov 21, 2024
Jan 3, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Online Ticket Booking has XSS via the admin/snacks_edit.php snacks_name parameter.
1Advanced Real Estate Script Project
1Advanced Real Estate Script
Nov 21, 2024
Jan 3, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Online Ticket Booking has XSS via the admin/manageownerlist.php contact parameter.
1Advanced Real Estate Script Project
1Advanced Real Estate Script
Nov 21, 2024
Jan 3, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Online Ticket Booking has XSS via the admin/sitesettings.php keyword parameter.
1Bookstackapp
1Bookstack
Nov 21, 2024
Jan 3, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
BookStack version 0.18.4 is vulnerable to stored cross-site scripting, within the page creation page, which can result in disruption of service and execution of javascript code.
1Plone
1Plone
Nov 21, 2024
Jan 3, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A member of the Plone 2.5-5.1rc1 site could set javascript in the home_page property of his profile, and have this executed when a visitor click the home page link on the author page.
1Elabftw
1Elabftw
Nov 21, 2024
Jan 3, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
ELabftw version 1.7.8 is vulnerable to stored cross-site scripting in the experiment infos component resulting in arbitrary execution of JavaScript and denial of service.
2Acquia
Mautic
2Mautic
Mautic
Nov 21, 2024
Jan 3, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Mautic version 2.1.0 - 2.11.0 is vulnerable to an inline JS XSS attack when using Mautic forms on a Mautic landing page using GET parameters to pre-populate the form.
1Lavalite
1Lavalite
Nov 21, 2024
Jan 3, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
LavaLite version 5.2.4 is vulnerable to stored cross-site scripting vulnerability, within the blog creation page, which can result in disruption of service and execution of javascript code.
1Quickappscms
1Quickapps Cms
Nov 21, 2024
Jan 3, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
QuickApps CMS version 2.0.0 is vulnerable to Stored Cross-site Scripting in the user's real name field resulting in denial of service and performing unauthorised actions with an administrator user's account
1Leanote
1Desktop
Nov 21, 2024
Jan 3, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Leanote-desktop version v2.5 is vulnerable to a XSS which leads to code execution due to enabled node integration
1Shiba Project
1Shiba
Nov 21, 2024
Jan 3, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Shiba markdown live preview app version 1.1.0 is vulnerable to XSS which leads to code execution due to enabled node integration.
1Invoiceninja
1Invoice Ninja
Nov 21, 2024
Jan 3, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Invoice Ninja version 3.8.1 is vulnerable to stored cross-site scripting vulnerability, within the invoice creation page, which can result in disruption of service and execution of javascript code.
1Leafpub
1Leafpub
Nov 21, 2024
Jan 3, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Leafpub version 1.2.0-beta6 is vulnerable to stored cross-site scripting vulnerability, within the edit blog post page, which can result in disruption of service and execution of javascript code.
1Leanote
1Leanote
Nov 21, 2024
Jan 3, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Leanote version <= 2.5 is vulnerable to XSS due to not sanitized input in markdown notes
1Marked Project
1Marked
Nov 21, 2024
Jan 2, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
marked version 0.3.6 and earlier is vulnerable to an XSS attack in the data: URI parser.