← Back
CWE-79

45,998 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (45,998)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Huawei
1Smartcare
May 13, 2026
Dec 22, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Huawei SmartCare V200R003C10 has a stored XSS (cross-site scripting) vulnerability in the dashboard module. A remote authenticated attacker could exploit this vulnerability to inject malicious scripts in the affected dev...Show more
Huawei SmartCare V200R003C10 has a stored XSS (cross-site scripting) vulnerability in the dashboard module. A remote authenticated attacker could exploit this vulnerability to inject malicious scripts in the affected device.Show less
1Microfocus
1Operations Manager I
May 13, 2026
Dec 21, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-Site Scripting (XSS) vulnerability has been identified in Micro Focus Operations Manager i, versions 10.60, 10.61, 10.62. The vulnerability could be remotely exploited to allow Cross-Site Scripting (XSS).
1Doditsolutions
1Busbooking Script
May 13, 2026
Dec 21, 2017
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Bus Booking Script has XSS via the results.php datepicker parameter or the admin/new_master.php spemail parameter.
1Piwigo
1Piwigo
May 13, 2026
Dec 21, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Configuration component of Piwigo 2.9.2 is vulnerable to Persistent Cross Site Scripting via the gallery_title parameter in an admin.php?page=configuration&section=main request. An attacker can exploit this to hijack...Show more
The Configuration component of Piwigo 2.9.2 is vulnerable to Persistent Cross Site Scripting via the gallery_title parameter in an admin.php?page=configuration&section=main request. An attacker can exploit this to hijack a client's browser along with the data stored in it.Show less
1Piwigo
1Piwigo
May 13, 2026
Dec 21, 2017
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The Batch Manager component of Piwigo 2.9.2 is vulnerable to Persistent Cross Site Scripting via tags-* array parameters in an admin.php?page=batch_manager&mode=unit request. An attacker can exploit this to hijack a clie...Show more
The Batch Manager component of Piwigo 2.9.2 is vulnerable to Persistent Cross Site Scripting via tags-* array parameters in an admin.php?page=batch_manager&mode=unit request. An attacker can exploit this to hijack a client's browser along with the data stored in it.Show less
1Cambiumnetworks
2Epmp 1000 Firmware
Epmp 2000 Firmware
May 13, 2026
Dec 20, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
In version 3.5 and prior of Cambium Networks ePMP firmware, an attacker who knows or can guess the RW community string can provide a URL for a configuration file over SNMP with XSS strings in certain SNMP OIDs, serve it...Show more
In version 3.5 and prior of Cambium Networks ePMP firmware, an attacker who knows or can guess the RW community string can provide a URL for a configuration file over SNMP with XSS strings in certain SNMP OIDs, serve it via HTTP, and the affected device will perform a configuration restore using the attacker's supplied config file, including the inserted XSS strings.Show less
1Cambiumnetworks
2Epmp 1000 Firmware
Epmp 2000 Firmware
May 13, 2026
Dec 20, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
In version 3.5 and prior of Cambium Networks ePMP firmware, an attacker who knows (or guesses) the SNMP read/write (RW) community string can insert XSS strings in certain SNMP OIDs which will execute in the context of th...Show more
In version 3.5 and prior of Cambium Networks ePMP firmware, an attacker who knows (or guesses) the SNMP read/write (RW) community string can insert XSS strings in certain SNMP OIDs which will execute in the context of the currently-logged on user.Show less
1Cambiumnetworks
2Epmp 1000 Firmware
Epmp 2000 Firmware
May 13, 2026
Dec 20, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
In version 3.5 and prior of Cambium Networks ePMP firmware, all authenticated users have the ability to update the Device Name and System Description fields in the web administration console, and those fields are vulnera...Show more
In version 3.5 and prior of Cambium Networks ePMP firmware, all authenticated users have the ability to update the Device Name and System Description fields in the web administration console, and those fields are vulnerable to persistent cross-site scripting (XSS) injection.Show less
1Bsuite Project
1Bsuite
May 13, 2026
Dec 20, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Multiple cross-site scripting (XSS) vulnerabilities in ui_stats.php in the bSuite plugin before 5 alpha 3 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) s or (2) p parameters to i...Show more
Multiple cross-site scripting (XSS) vulnerabilities in ui_stats.php in the bSuite plugin before 5 alpha 3 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) s or (2) p parameters to index.php.Show less
1Tp Link
1Tl Sg108e Firmware
May 13, 2026
Dec 20, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-site scripting (XSS) vulnerability in system_name_set.cgi in TP-Link TL-SG108E 1.0.0 allows authenticated remote attackers to submit arbitrary java script via the 'sysName' parameter.
1Ibm
1Robotic Process Automation With Automation Anywhere
May 13, 2026
Dec 20, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM Robotic Process Automation with Automation Anywhere 10.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functional...Show more
IBM Robotic Process Automation with Automation Anywhere 10.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 135546.Show less
1Ibm
1Security Guardium
May 13, 2026
Dec 20, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM Security Guardium 10.0 Database Activity Monitor is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potent...Show more
IBM Security Guardium 10.0 Database Activity Monitor is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 132613.Show less
1Ibm
1Business Process Manager
May 13, 2026
Dec 20, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM Business Process Manager 8.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to cre...Show more
IBM Business Process Manager 8.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 128692.Show less
1Synology
1Photo Station
May 13, 2026
Dec 20, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-site scripting (XSS) vulnerability in PixlrEditorHandler.php in Synology Photo Station before 6.8.0-3456 allows remote authenticated users to inject arbitrary web scripts or HTML via the id parameter.
1Codecrafters
1Ability Mail Server
May 13, 2026
Dec 20, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Ability Mail Server 3.3.2 has Cross Site Scripting (XSS) via the body of an e-mail message, with JavaScript code executed on the Read Mail screen (aka the /_readmail URI). This is fixed in version 4.2.4.
1Vmware
1Esxi
May 13, 2026
Dec 20, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The ESXi Host Client in VMware ESXi (6.5 before ESXi650-201712103-SG, 5.5 before ESXi600-201711103-SG and 5.5 before ESXi550-201709102-SG) contains a vulnerability that may allow for stored cross-site scripting (XSS). An...Show more
The ESXi Host Client in VMware ESXi (6.5 before ESXi650-201712103-SG, 5.5 before ESXi600-201711103-SG and 5.5 before ESXi550-201709102-SG) contains a vulnerability that may allow for stored cross-site scripting (XSS). An attacker can exploit this vulnerability by injecting Javascript, which might get executed when other users access the Host Client.Show less
1Blogotext Project
1Blogotext
May 13, 2026
Dec 20, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross site scripting (XSS) vulnerability in the markup_clean_href function in inc/conv.php in BlogoText through 3.7.6 allows remote attackers to inject arbitrary JavaScript via a comment.
1Mediaburst
8Booking Calendar Sms
Clockwork Sms NotficationsContact Form 7 Sms+5 more
May 13, 2026
Dec 20, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Clockwork SMS clockwork-test-message.php component has XSS via a crafted "to" parameter in a clockwork-test-message request to wp-admin/admin.php. This component code is found in the following WordPress plugins: Cloc...Show more
The Clockwork SMS clockwork-test-message.php component has XSS via a crafted "to" parameter in a clockwork-test-message request to wp-admin/admin.php. This component code is found in the following WordPress plugins: Clockwork Free and Paid SMS Notifications 2.0.3, Two-Factor Authentication - Clockwork SMS 1.0.2, Booking Calendar - Clockwork SMS 1.0.5, Contact Form 7 - Clockwork SMS 2.3.0, Fast Secure Contact Form - Clockwork SMS 2.1.2, Formidable - Clockwork SMS 1.0.2, Gravity Forms - Clockwork SMS 2.2, and WP e-Commerce - Clockwork SMS 2.0.5.Show less
1Paid To Read Script Project
1Paid To Read Script
May 13, 2026
Dec 20, 2017
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Paid To Read Script 2.0.5 has XSS via the referrals.php tier parameter or the admin/userview.php uid parameter.
1Piwigo
1Piwigo
May 13, 2026
Dec 20, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Piwigo 2.9.2 has XSS via the name parameter in an admin.php?page=album-3-properties request.