← Back
CWE-79

45,998 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (45,998)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Liferay
1Liferay Portal
Nov 21, 2024
Jan 2, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in the /html/portal/flash.jsp page in Liferay Portal CE 7.0 GA4 and older allows remote attackers to inject arbitrary web script or HTML via a javascript: URI in the "movie" param...Show more
Cross-site scripting (XSS) vulnerability in the /html/portal/flash.jsp page in Liferay Portal CE 7.0 GA4 and older allows remote attackers to inject arbitrary web script or HTML via a javascript: URI in the "movie" parameter.Show less
1Omniscale
1Mapproxy
Nov 21, 2024
Jan 2, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
MapProxy version 1.10.3 and older is vulnerable to a Cross Site Scripting attack in the demo service resulting in possible information disclosure.
1Ez
1Ez Publish
Nov 21, 2024
Jan 2, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
eZ Systems eZ Publish version 5.4.0 to 5.4.9, and 5.3.12 and older, is vulnerable to an XSS issue in the search module, resulting in a risk of attackers injecting scripts which may e.g. steal authentication credentials.
1Mojoportal
1Mojoportal
Nov 21, 2024
Jan 2, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Cross-site scripting (XSS) vulnerability in Help.aspx in mojoPortal version 2.5.0.0 allows remote attackers to inject arbitrary web script or HTML via the helpkey parameter. Exploitation requires authenticated reflected...Show more
Cross-site scripting (XSS) vulnerability in Help.aspx in mojoPortal version 2.5.0.0 allows remote attackers to inject arbitrary web script or HTML via the helpkey parameter. Exploitation requires authenticated reflected cross-site scripting for user accounts assigned either the "Administrators" or "Content Administrators" role.Show less
1Openhacker Project
1Openhacker
Nov 21, 2024
Jan 2, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Eleix Openhacker version 0.1.47 is vulnerable to a XSS vulnerability in the bank transactions component resulting in arbitrary code execution in the browser.
1Passbolt
1Passbolt Api
Nov 21, 2024
Jan 2, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Passbolt API version 1.6.4 and older are vulnerable to a XSS in the url field on the password workspace
1Wp Unit
1Share This Image
Nov 21, 2024
Jan 2, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The ILLID Share This Image plugin before 1.04 for WordPress has XSS via the sharer.php url parameter.
1Z Url Preview Project
1Z Url Preview
Nov 21, 2024
Jan 1, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Z-URL Preview plugin 1.6.1 for WordPress has XSS via the class.zlinkpreview.php url parameter.
1Clickbank
1Affiliate Ads For Clickbank Products
Nov 21, 2024
Jan 1, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The MyCBGenie Affiliate Ads for Clickbank Products plugin through 1.6 for WordPress has XSS via the text_ads_ajax.php border_color parameter.
1E Goi
1Smart Marketing Sms And Newsletters Forms
Nov 21, 2024
Jan 1, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The E-goi Smart Marketing SMS and Newsletters Forms plugin before 2.0.0 for WordPress has XSS via the admin/partials/custom/egoi-for-wp-form_egoi.php url parameter.
1Extensis
1Portfolio Netpublish
May 13, 2026
Jan 1, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
netpub/server.np in Extensis Portfolio NetPublish has XSS in the quickfind parameter, aka Open Bug Bounty ID OBB-290447.
1Zurmo
1Zurmo Crm
May 13, 2026
Dec 31, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Zurmo 3.2.3 allows XSS via the latitude or longitude parameter to maps/default/mapAndPoint.
1Magento
1Magento
May 13, 2026
Dec 30, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Magento Community Edition and Enterprise Edition before 2.0.10 and 2.1.x before 2.1.2 have XSS via e-mail templates that are mishandled during a preview, aka APPSEC-1503.
1Webmin
1Webmin
May 13, 2026
Dec 30, 2017
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
custom/run.cgi in Webmin before 1.870 allows remote authenticated administrators to conduct XSS attacks via the description field in the custom command functionality.
1Stivasoft
1Phpjabbers File Sharing Script
May 13, 2026
Dec 30, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
PHPJabbers File Sharing Script 1.0 has stored XSS in the comments section.
1Stivasoft
1Phpjabbers Night Club Booking Software
May 13, 2026
Dec 30, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
PHPJabbers Night Club Booking Software has stored XSS in the name parameter in the reservations tab.
1Stivasoft
1Phpjabbers Star Rating Script
May 13, 2026
Dec 30, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
PHPJabbers Star Rating Script 4.0 has stored XSS via a rating item.
1Stivasoft
1Phpjabbers Newsletter Script
May 13, 2026
Dec 30, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
PHPJabbers PHP Newsletter Script 4.2 has stored XSS in lists in the admin panel.
1Iwcnetwork
1Biometric Shift Employee Management System
May 13, 2026
Dec 30, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Biometric Shift Employee Management System has XSS via the Last_Name parameter in an index.php?user=ajax request.
1Iwcnetwork
1Biometric Shift Employee Management System
May 13, 2026
Dec 30, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Biometric Shift Employee Management System has XSS via the criteria parameter in an index.php?user=competency_criteria request.