CWE-79
45,998 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (45,998)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Iwcnetwork 1Biometric Shift Employee Management System May 13, 2026 Dec 30, 2017 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 Biometric Shift Employee Management System has XSS via the amount parameter in an index.php?user=addition_deduction request. |
1Iwcnetwork 1Biometric Shift Employee Management System May 13, 2026 Dec 30, 2017 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 Biometric Shift Employee Management System has XSS via the expense_name parameter in an index.php?user=expenses request. |
1Iwcnetwork 1Biometric Shift Employee Management System May 13, 2026 Dec 30, 2017 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 Biometric Shift Employee Management System has XSS via the index.php holiday_name parameter in an edit_holiday action. |
1Muslim Matrimonial Script Project 1Muslim Matrimonial Script May 13, 2026 Dec 30, 2017 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 PHP Scripts Mall Muslim Matrimonial Script has XSS via the admin/event_add.php event_title parameter. |
1Muslim Matrimonial Script Project 1Muslim Matrimonial Script May 13, 2026 Dec 30, 2017 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 PHP Scripts Mall Muslim Matrimonial Script has XSS via the admin/caste_view.php comm_id parameter. |
1Muslim Matrimonial Script Project 1Muslim Matrimonial Script May 13, 2026 Dec 30, 2017 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 PHP Scripts Mall Muslim Matrimonial Script has XSS via the admin/state_view.php cou_id parameter. |
1Muslim Matrimonial Script Project 1Muslim Matrimonial Script May 13, 2026 Dec 30, 2017 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 PHP Scripts Mall Muslim Matrimonial Script has XSS via the admin/event_edit.php edit_id parameter. |
1Muslim Matrimonial Script Project 1Muslim Matrimonial Script May 13, 2026 Dec 30, 2017 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 PHP Scripts Mall Muslim Matrimonial Script has XSS via the admin/slider_edit.php edit_id parameter. |
The test_sql_and_script_inject function in htdocs/main.inc.php in Dolibarr ERP/CRM 6.0.4 blocks some event attributes but neither onclick nor onscroll, which allows XSS. |
cgi/surgeftpmgr.cgi (aka the Web Manager interface on TCP port 7021 or 9021) in NetWin SurgeFTP version 23f2 has XSS via the classid, domainid, or username parameter. |
2Fedoraproject Mistune Project2Fedora MistuneMay 13, 2026 Dec 29, 2017 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Cross-site scripting (XSS) vulnerability in the _keyify function in mistune.py in Mistune before 0.8.1 allows remote attackers to inject arbitrary web script or HTML by leveraging failure to escape the "key" argument. |
1Php Multivendor Ecommerce Project 1Php Multivendor Ecommerce May 13, 2026 Dec 28, 2017 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 PHP Scripts Mall PHP Multivendor Ecommerce has XSS via the my_wishlist.php fid parameter. |
1Php Multivendor Ecommerce Project 1Php Multivendor Ecommerce May 13, 2026 Dec 28, 2017 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 PHP Scripts Mall PHP Multivendor Ecommerce has XSS via the admin/sellerupd.php companyname parameter. |
1Php Multivendor Ecommerce Project 1Php Multivendor Ecommerce May 13, 2026 Dec 28, 2017 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 PHP Scripts Mall PHP Multivendor Ecommerce has XSS via the shopping-cart.php cusid parameter. |
1Php Multivendor Ecommerce Project 1Php Multivendor Ecommerce May 13, 2026 Dec 28, 2017 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 PHP Scripts Mall PHP Multivendor Ecommerce has XSS via the seller-view.php usid parameter. |
1Php Multivendor Ecommerce Project 1Php Multivendor Ecommerce May 13, 2026 Dec 28, 2017 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 PHP Scripts Mall PHP Multivendor Ecommerce has XSS via the category.php chid1 parameter. |
Cells Blog 3.5 has XSS via the pub_readpost.php fmid parameter. |
Cells Blog 3.5 has XSS via the jfdname parameter in an act=showpic request. |
Multiple cross-site scripting (XSS) vulnerabilities in Slash Command Creator in Synology Chat before 2.0.0-1124 allow remote authenticated users to inject arbitrary web script or HTML via (1) COMMAND, (2) COMMANDS INSTRU...Show more |
1Single Theater Booking Script Project 1Single Theater Booking Script May 13, 2026 Dec 28, 2017 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 PHP Scripts Mall Single Theater Booking has XSS via the title parameter to admin/sitesettings.php. |