CWE-79
45,998 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (45,998)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Cross-site scripting (XSS) vulnerability in the /html/portal/flash.jsp page in Liferay Portal CE 7.0 GA4 and older allows remote attackers to inject arbitrary web script or HTML via a javascript: URI in the "movie" param...Show more |
MapProxy version 1.10.3 and older is vulnerable to a Cross Site Scripting attack in the demo service resulting in possible information disclosure. |
eZ Systems eZ Publish version 5.4.0 to 5.4.9, and 5.3.12 and older, is vulnerable to an XSS issue in the search module, resulting in a risk of attackers injecting scripts which may e.g. steal authentication credentials. |
Cross-site scripting (XSS) vulnerability in Help.aspx in mojoPortal version 2.5.0.0 allows remote attackers to inject arbitrary web script or HTML via the helpkey parameter. Exploitation requires authenticated reflected...Show more |
1Openhacker Project 1Openhacker Nov 21, 2024 Jan 2, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Eleix Openhacker version 0.1.47 is vulnerable to a XSS vulnerability in the bank transactions component resulting in arbitrary code execution in the browser. |
Passbolt API version 1.6.4 and older are vulnerable to a XSS in the url field on the password workspace |
The ILLID Share This Image plugin before 1.04 for WordPress has XSS via the sharer.php url parameter. |
1Z Url Preview Project 1Z Url Preview Nov 21, 2024 Jan 1, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The Z-URL Preview plugin 1.6.1 for WordPress has XSS via the class.zlinkpreview.php url parameter. |
1Clickbank 1Affiliate Ads For Clickbank Products Nov 21, 2024 Jan 1, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The MyCBGenie Affiliate Ads for Clickbank Products plugin through 1.6 for WordPress has XSS via the text_ads_ajax.php border_color parameter. |
1E Goi 1Smart Marketing Sms And Newsletters Forms Nov 21, 2024 Jan 1, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The E-goi Smart Marketing SMS and Newsletters Forms plugin before 2.0.0 for WordPress has XSS via the admin/partials/custom/egoi-for-wp-form_egoi.php url parameter. |
1Extensis 1Portfolio Netpublish May 13, 2026 Jan 1, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 netpub/server.np in Extensis Portfolio NetPublish has XSS in the quickfind parameter, aka Open Bug Bounty ID OBB-290447. |
Zurmo 3.2.3 allows XSS via the latitude or longitude parameter to maps/default/mapAndPoint. |
Magento Community Edition and Enterprise Edition before 2.0.10 and 2.1.x before 2.1.2 have XSS via e-mail templates that are mishandled during a preview, aka APPSEC-1503. |
custom/run.cgi in Webmin before 1.870 allows remote authenticated administrators to conduct XSS attacks via the description field in the custom command functionality. |
1Stivasoft 1Phpjabbers File Sharing Script May 13, 2026 Dec 30, 2017 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 PHPJabbers File Sharing Script 1.0 has stored XSS in the comments section. |
1Stivasoft 1Phpjabbers Night Club Booking Software May 13, 2026 Dec 30, 2017 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 PHPJabbers Night Club Booking Software has stored XSS in the name parameter in the reservations tab. |
1Stivasoft 1Phpjabbers Star Rating Script May 13, 2026 Dec 30, 2017 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 PHPJabbers Star Rating Script 4.0 has stored XSS via a rating item. |
1Stivasoft 1Phpjabbers Newsletter Script May 13, 2026 Dec 30, 2017 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 PHPJabbers PHP Newsletter Script 4.2 has stored XSS in lists in the admin panel. |
1Iwcnetwork 1Biometric Shift Employee Management System May 13, 2026 Dec 30, 2017 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 Biometric Shift Employee Management System has XSS via the Last_Name parameter in an index.php?user=ajax request. |
1Iwcnetwork 1Biometric Shift Employee Management System May 13, 2026 Dec 30, 2017 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 Biometric Shift Employee Management System has XSS via the criteria parameter in an index.php?user=competency_criteria request. |