← Back
CWE-79

45,998 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (45,998)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Single Theater Booking Script Project
1Single Theater Booking Script
May 13, 2026
Dec 28, 2017
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
PHP Scripts Mall Single Theater Booking has XSS via the admin/viewtheatre.php theatreid parameter.
1Vanguard Project
1Marketplace Digital Products Php
May 13, 2026
Dec 28, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Vanguard Marketplace Digital Products PHP has XSS via the phps_query parameter to /search.
1Easy2map
1Easy2map
May 13, 2026
Dec 27, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in includes/MapPinImageSave.php in the Easy2Map plugin before 1.3.0 for WordPress allows remote attackers to inject arbitrary web script or HTML via the map_id parameter.
1Web Mv
1Resads
May 13, 2026
Dec 27, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Multiple cross-site scripting (XSS) vulnerabilities in (1) templates/admanagement/admanagement.php and (2) templates/adspot/adspot.php in the ResAds plugin before 1.0.2 for WordPress allow remote attackers to inject arbi...Show more
Multiple cross-site scripting (XSS) vulnerabilities in (1) templates/admanagement/admanagement.php and (2) templates/adspot/adspot.php in the ResAds plugin before 1.0.2 for WordPress allow remote attackers to inject arbitrary web script or HTML via the page parameter.Show less
1Codepeople
1Payment Form For Paypal Pro
May 13, 2026
Dec 27, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Multiple cross-site scripting (XSS) vulnerabilities in the (1) cp_updateMessageItem and (2) cp_deleteMessageItem functions in cp_ppp_admin_int_message_list.inc.php in the Payment Form for PayPal Pro plugin before 1.0.2 f...Show more
Multiple cross-site scripting (XSS) vulnerabilities in the (1) cp_updateMessageItem and (2) cp_deleteMessageItem functions in cp_ppp_admin_int_message_list.inc.php in the Payment Form for PayPal Pro plugin before 1.0.2 for WordPress allow remote attackers to inject arbitrary web script or HTML via the cal parameter.Show less
1Stackideas
1Komento
May 13, 2026
Dec 27, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Multiple cross-site scripting (XSS) vulnerabilities in helpers/comment.php in the StackIdeas Komento (com_komento) component before 2.0.5 for Joomla! allow remote attackers to inject arbitrary web script or HTML via the...Show more
Multiple cross-site scripting (XSS) vulnerabilities in helpers/comment.php in the StackIdeas Komento (com_komento) component before 2.0.5 for Joomla! allow remote attackers to inject arbitrary web script or HTML via the (1) img or (2) url tag of a new comment.Show less
1Synology
1Mailplus Server
May 13, 2026
Dec 27, 2017
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Cross-site scripting (XSS) vulnerability in User Policy editor in Synology MailPlus Server before 1.4.0-0415 allows remote authenticated users to inject arbitrary HTML via the name parameter.
1Ordermanagementscript
1Professional Service Script
May 13, 2026
Dec 27, 2017
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
PHP Scripts Mall Professional Service Script has XSS via the admin/bannerview.php view parameter.
1Ordermanagementscript
1Professional Service Script
May 13, 2026
Dec 27, 2017
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
PHP Scripts Mall Professional Service Script has XSS via the admin/general_settingupd.php website_title parameter.
1Archon
1Archon
May 13, 2026
Dec 27, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
packages/core/contact.php in Archon 3.21 rev-1 has XSS in the referer parameter in an index.php?p=core/contact request, aka Open Bug Bounty ID OBB-278503.
1Responsive Realestate Script Project
1Responsive Realestate Script
May 13, 2026
Dec 27, 2017
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
PHP Scripts Mall Responsive Realestate Script has XSS via the admin/general.php gplus parameter.
1Car Rental Script Project
1Car Rental Script
May 13, 2026
Dec 27, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
PHP Scripts Mall Car Rental Script has XSS via the admin/areaedit.php carid parameter or the admin/sitesettings.php websitename parameter.
1Fortunescripts
1Lynda Clone
May 13, 2026
Dec 27, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
FS Lynda Clone has XSS via the keywords parameter to tutorial/ or the edit_profile_first_name parameter to user/edit_profile.
1Basic Job Site Script Project
1Basic Job Site Script
May 13, 2026
Dec 27, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Readymade Job Site Script has XSS via the keyword parameter to the /job URI.
1Readymade Video Sharing Script Project
1Readymade Video Sharing Script
May 13, 2026
Dec 27, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Readymade Video Sharing Script has XSS via the search_video.php search parameter, the viewsubs.php chnlid parameter, or the user-profile-edit.php fname parameter.
1Mgl Instagram Gallery Project
1Mgl Instagram Gallery
May 13, 2026
Dec 27, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The mgl-instagram-gallery plugin for WordPress has XSS via the single-gallery.php media parameter.
1Liferay
1Liferay Portal
May 13, 2026
Dec 27, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In Liferay Portal 6.1.0, the tags section has XSS via a Public Render Parameter (p_r_p) value, as demonstrated by p_r_p_564233524_tag.
1Samsung
1Internet Browser
May 13, 2026
Dec 27, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Samsung Internet Browser 6.2.01.12 allows remote attackers to bypass the Same Origin Policy, and conduct UXSS attacks to obtain sensitive information, via vectors involving an IFRAME element inside XSLT data in one part...Show more
Samsung Internet Browser 6.2.01.12 allows remote attackers to bypass the Same Origin Policy, and conduct UXSS attacks to obtain sensitive information, via vectors involving an IFRAME element inside XSLT data in one part of an MHTML file. Specifically, JavaScript code in another part of this MHTML file does not have a document.domain value corresponding to the domain that is hosting the MHTML file, but instead has a document.domain value corresponding to an arbitrary URL within the content of the MHTML file.Show less
1Serverscheck
1Monitoring Software
May 13, 2026
Dec 27, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
ServersCheck Monitoring Software before 14.2.3 is prone to a cross-site scripting vulnerability as user supplied-data is not validated/sanitized when passed in the settings_SMS_ALERT_TYPE parameter, and JavaScript can be...Show more
ServersCheck Monitoring Software before 14.2.3 is prone to a cross-site scripting vulnerability as user supplied-data is not validated/sanitized when passed in the settings_SMS_ALERT_TYPE parameter, and JavaScript can be executed on settings-save.html (the Settings - SMS Alerts page).Show less
1Ibm
7Rational Collaborative Lifecycle Management
Rational Doors Next GenerationRational Engineering Lifecycle Manager+4 more
May 13, 2026
Dec 27, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM Team Concert (RTC including IBM Rational Collaborative Lifecycle Management 4.0, 5.0., and 6.0) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI...Show more
IBM Team Concert (RTC including IBM Rational Collaborative Lifecycle Management 4.0, 5.0., and 6.0) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-force ID: 126858.Show less