← Back
CWE-79

45,998 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (45,998)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Iwcnetwork
1Biometric Shift Employee Management System
May 13, 2026
Dec 30, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Biometric Shift Employee Management System has XSS via the amount parameter in an index.php?user=addition_deduction request.
1Iwcnetwork
1Biometric Shift Employee Management System
May 13, 2026
Dec 30, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Biometric Shift Employee Management System has XSS via the expense_name parameter in an index.php?user=expenses request.
1Iwcnetwork
1Biometric Shift Employee Management System
May 13, 2026
Dec 30, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Biometric Shift Employee Management System has XSS via the index.php holiday_name parameter in an edit_holiday action.
1Muslim Matrimonial Script Project
1Muslim Matrimonial Script
May 13, 2026
Dec 30, 2017
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
PHP Scripts Mall Muslim Matrimonial Script has XSS via the admin/event_add.php event_title parameter.
1Muslim Matrimonial Script Project
1Muslim Matrimonial Script
May 13, 2026
Dec 30, 2017
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
PHP Scripts Mall Muslim Matrimonial Script has XSS via the admin/caste_view.php comm_id parameter.
1Muslim Matrimonial Script Project
1Muslim Matrimonial Script
May 13, 2026
Dec 30, 2017
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
PHP Scripts Mall Muslim Matrimonial Script has XSS via the admin/state_view.php cou_id parameter.
1Muslim Matrimonial Script Project
1Muslim Matrimonial Script
May 13, 2026
Dec 30, 2017
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
PHP Scripts Mall Muslim Matrimonial Script has XSS via the admin/event_edit.php edit_id parameter.
1Muslim Matrimonial Script Project
1Muslim Matrimonial Script
May 13, 2026
Dec 30, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
PHP Scripts Mall Muslim Matrimonial Script has XSS via the admin/slider_edit.php edit_id parameter.
1Dolibarr
1Dolibarr Erp/crm
May 13, 2026
Dec 29, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The test_sql_and_script_inject function in htdocs/main.inc.php in Dolibarr ERP/CRM 6.0.4 blocks some event attributes but neither onclick nor onscroll, which allows XSS.
1Netwin
1Surgeftp
May 13, 2026
Dec 29, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
cgi/surgeftpmgr.cgi (aka the Web Manager interface on TCP port 7021 or 9021) in NetWin SurgeFTP version 23f2 has XSS via the classid, domainid, or username parameter.
2Fedoraproject
Mistune Project
2Fedora
Mistune
May 13, 2026
Dec 29, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in the _keyify function in mistune.py in Mistune before 0.8.1 allows remote attackers to inject arbitrary web script or HTML by leveraging failure to escape the "key" argument.
1Php Multivendor Ecommerce Project
1Php Multivendor Ecommerce
May 13, 2026
Dec 28, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
PHP Scripts Mall PHP Multivendor Ecommerce has XSS via the my_wishlist.php fid parameter.
1Php Multivendor Ecommerce Project
1Php Multivendor Ecommerce
May 13, 2026
Dec 28, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
PHP Scripts Mall PHP Multivendor Ecommerce has XSS via the admin/sellerupd.php companyname parameter.
1Php Multivendor Ecommerce Project
1Php Multivendor Ecommerce
May 13, 2026
Dec 28, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
PHP Scripts Mall PHP Multivendor Ecommerce has XSS via the shopping-cart.php cusid parameter.
1Php Multivendor Ecommerce Project
1Php Multivendor Ecommerce
May 13, 2026
Dec 28, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
PHP Scripts Mall PHP Multivendor Ecommerce has XSS via the seller-view.php usid parameter.
1Php Multivendor Ecommerce Project
1Php Multivendor Ecommerce
May 13, 2026
Dec 28, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
PHP Scripts Mall PHP Multivendor Ecommerce has XSS via the category.php chid1 parameter.
1Cells
1Blog
May 13, 2026
Dec 28, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cells Blog 3.5 has XSS via the pub_readpost.php fmid parameter.
1Cells
1Blog
May 13, 2026
Dec 28, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cells Blog 3.5 has XSS via the jfdname parameter in an act=showpic request.
1Synology
1Chat
May 13, 2026
Dec 28, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Multiple cross-site scripting (XSS) vulnerabilities in Slash Command Creator in Synology Chat before 2.0.0-1124 allow remote authenticated users to inject arbitrary web script or HTML via (1) COMMAND, (2) COMMANDS INSTRU...Show more
Multiple cross-site scripting (XSS) vulnerabilities in Slash Command Creator in Synology Chat before 2.0.0-1124 allow remote authenticated users to inject arbitrary web script or HTML via (1) COMMAND, (2) COMMANDS INSTRUCTION, or (3) DESCRIPTION parameter.Show less
1Single Theater Booking Script Project
1Single Theater Booking Script
May 13, 2026
Dec 28, 2017
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
PHP Scripts Mall Single Theater Booking has XSS via the title parameter to admin/sitesettings.php.