CWE-79
45,971 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (45,971)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Debian Wordpress2Debian Linux WordpressMay 13, 2026 Dec 2, 2017 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 wp-includes/feed.php in WordPress before 4.9.1 does not properly restrict enclosures in RSS and Atom fields, which might allow attackers to conduct XSS attacks via a crafted URL. |
2Debian Wordpress2Debian Linux WordpressMay 13, 2026 Dec 2, 2017 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 wp-includes/general-template.php in WordPress before 4.9.1 does not properly restrict the lang attribute of an HTML element, which might allow attackers to conduct XSS attacks via the language setting of a site. |
2Debian Wordpress2Debian Linux WordpressMay 13, 2026 Dec 2, 2017 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 wp-includes/functions.php in WordPress before 4.9.1 does not require the unfiltered_html capability for upload of .js files, which might allow remote attackers to conduct XSS attacks via a crafted file. |
Adobe RoboHelp has a cross-site scripting (XSS) vulnerability. This affects versions before RH12.0.4.460 and RH2017 before RH2017.0.2. |
Adobe ColdFusion has a cross-site scripting (XSS) vulnerability. This affects Update 4 and earlier versions for ColdFusion 2016, and Update 12 and earlier versions for ColdFusion 11. |
1Cisco 1Webex Meeting Center May 13, 2026 Nov 30, 2017 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 A vulnerability in Cisco WebEx Meeting Center could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of an affected system. The vulnerability is due to insufficient...Show more |
A vulnerability in the web-based management interface of Cisco Jabber for Windows, Mac, Android, and iOS could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the...Show more |
1Cisco 1Unified Communications Manager May 13, 2026 Nov 30, 2017 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 A vulnerability in the web-based management interface of Cisco Unified Communications Manager could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based m...Show more |
A vulnerability in the web-based management interface of Cisco Jabber for Windows, Mac, Android, and iOS could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of th...Show more |
1Cisco 1Unified Computing System Central Software May 13, 2026 Nov 30, 2017 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 Multiple vulnerabilities in the web-based management interface of Cisco UCS Central Software could allow a remote attacker to conduct a cross-site scripting (XSS) attack against a user of the affected interface or hijack...Show more |
1Cisco 1Unified Computing System Central Software May 13, 2026 Nov 30, 2017 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 Multiple vulnerabilities in the web-based management interface of Cisco UCS Central Software could allow a remote attacker to conduct a cross-site scripting (XSS) attack against a user of the affected interface or hijack...Show more |
1Cisco 1Data Center Network Manager May 13, 2026 Nov 30, 2017 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Multiple vulnerabilities in Cisco Data Center Network Manager (DCNM) Software could allow a remote attacker to inject arbitrary values into DCNM configuration parameters, redirect a user to a malicious website, inject ma...Show more |
1Cisco 1Data Center Network Manager May 13, 2026 Nov 30, 2017 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Multiple vulnerabilities in Cisco Data Center Network Manager (DCNM) Software could allow a remote attacker to inject arbitrary values into DCNM configuration parameters, redirect a user to a malicious website, inject ma...Show more |
1Cisco 1Data Center Network Manager May 13, 2026 Nov 30, 2017 N/A· v4 4.7 MEDIUM· v3 4.3 MEDIUM· v2 Multiple vulnerabilities in Cisco Data Center Network Manager (DCNM) Software could allow a remote attacker to inject arbitrary values into DCNM configuration parameters, redirect a user to a malicious website, inject ma...Show more |
1Cisco 1Data Center Network Manager May 13, 2026 Nov 30, 2017 N/A· v4 6.1 MEDIUM· v3 5.8 MEDIUM· v2 Multiple vulnerabilities in Cisco Data Center Network Manager (DCNM) Software could allow a remote attacker to inject arbitrary values into DCNM configuration parameters, redirect a user to a malicious website, inject ma...Show more |
1Cisco 1Data Center Network Manager May 13, 2026 Nov 30, 2017 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Multiple vulnerabilities in Cisco Data Center Network Manager (DCNM) Software could allow a remote attacker to inject arbitrary values into DCNM configuration parameters, redirect a user to a malicious website, inject ma...Show more |
An issue was discovered in Squiz Matrix before 5.3.6.1 and 5.4.x before 5.4.1.3. There are multiple reflected Cross-Site Scripting (XSS) issues in Matrix WYSIWYG plugins. |
A Cross-site Scripting (XSS) vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.7, 5.4 and below versions under SSL VPN web portal allows a remote user to inject arbitrary web script or HTML in the context of...Show more |
1Amtythumb Project 1Amtythumb May 13, 2026 Nov 29, 2017 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 XSS exists in the amtyThumb amty-thumb-recent-post (aka amtyThumb posts or wp-thumb-post) plugin 8.1.3 for WordPress via the query string to amtyThumbPostsAdminPg.php. |
1Zitec 1Emag Marketplace Connector May 13, 2026 Nov 28, 2017 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The Emag Marketplace Connector plugin 1.0.0 for WordPress has reflected XSS because the parameter "post" to /wp-content/plugins/emag-marketplace-connector/templates/order/awb-meta-box.php is not filtered correctly. |