← Back
CWE-79

45,971 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (45,971)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Horde
1Groupware
May 13, 2026
Nov 20, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
In Horde Groupware 5.2.19, there is XSS via the Name field during creation of a new Resource. This can be leveraged for remote code execution after compromising an administrator account, because the CVE-2015-7984 CSRF pr...Show more
In Horde Groupware 5.2.19, there is XSS via the Name field during creation of a new Resource. This can be leveraged for remote code execution after compromising an administrator account, because the CVE-2015-7984 CSRF protection mechanism can then be bypassed.Show less
1Horde
1Groupware
May 13, 2026
Nov 20, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
In Horde Groupware 5.2.19 and 5.2.21, there is XSS via the Color field in a Create Task List action.
1Horde
1Groupware
May 13, 2026
Nov 20, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
In Horde Groupware 5.2.19-5.2.22, there is XSS via the URL field in a "Calendar -> New Event" action.
1Lvyecms Project
1Lvyecms
May 13, 2026
Nov 20, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Public tologin feature in admin.php in LvyeCMS through 3.1 allows XSS via a crafted username that is mishandled during later log viewing by an administrator.
1Symphony Project
1Symphony
May 13, 2026
Nov 18, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
b3log Symphony (aka Sym) 2.2.0 does not properly address XSS in JSON objects, as demonstrated by a crafted userAvatarURL value to /settings/avatar, related to processor/AdminProcessor.java, processor/ArticleProcessor.jav...Show more
b3log Symphony (aka Sym) 2.2.0 does not properly address XSS in JSON objects, as demonstrated by a crafted userAvatarURL value to /settings/avatar, related to processor/AdminProcessor.java, processor/ArticleProcessor.java, processor/UserProcessor.java, service/ArticleQueryService.java, service/AvatarQueryService.java, and service/CommentQueryService.java.Show less
1Whoops Project
1Whoops
May 13, 2026
Nov 17, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The dump function in Util/TemplateHelper.php in filp whoops before 2.1.13 has XSS.
1Parallelus
1Salutation
May 13, 2026
Nov 17, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Stored XSS in Salutation Responsive WordPress + BuddyPress Theme version 3.0.15 could allow logged-in users to do almost anything an admin can
1Moxa
1Eds G512e Firmware
May 13, 2026
Nov 17, 2017
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
An issue was discovered on MOXA EDS-G512E 5.1 build 16072215 devices. There is XSS in the administration interface.
1Icontime
1Rtc 1000 Firmware
May 13, 2026
Nov 17, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A stored cross-site scripting vulnerability in the Icon Time Systems RTC-1000 v2.5.7458 and earlier time clock allows remote attackers to inject arbitrary JavaScript in the nameFirst (aka First Name) field for the employ...Show more
A stored cross-site scripting vulnerability in the Icon Time Systems RTC-1000 v2.5.7458 and earlier time clock allows remote attackers to inject arbitrary JavaScript in the nameFirst (aka First Name) field for the employee details page (/employee.html) that is then reflected in multiple pages where that field data is utilized, resulting in session hijacking and possible elevation of privileges.Show less
1Vmware
1Nsx Edge
May 13, 2026
Nov 17, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
VMware NSX Edge (6.2.x before 6.2.9 and 6.3.x before 6.3.5) contains a moderate Cross-Site Scripting (XSS) issue which may lead to information disclosure.
1Cs Cart
2Cs Cart
Cs Cart Multivendor
May 13, 2026
Nov 17, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-site scripting vulnerability in CS-Cart Japanese Edition v4.3.10 and earlier (excluding v2 and v3), CS-Cart Multivendor Japanese Edition v4.3.10 and earlier (excluding v2 and v3) allows an attacker to inject arbitr...Show more
Cross-site scripting vulnerability in CS-Cart Japanese Edition v4.3.10 and earlier (excluding v2 and v3), CS-Cart Multivendor Japanese Edition v4.3.10 and earlier (excluding v2 and v3) allows an attacker to inject arbitrary web script or HTML via unspecified vectors.Show less
1Relevanssi
1Relevanssi
May 13, 2026
Nov 17, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Reflected XSS in Relevanssi Premium version 1.14.8 when using relevanssi_didyoumean() could allow unauthenticated attacker to do almost anything an admin can
1Modx
1Modx Revolution
May 13, 2026
Nov 17, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A stored web content injection vulnerability (WCI, a.k.a XSS) is present in MODX Revolution CMS version 2.5.6 and earlier. An authenticated user with permissions to edit users can save malicious JavaScript as a User Grou...Show more
A stored web content injection vulnerability (WCI, a.k.a XSS) is present in MODX Revolution CMS version 2.5.6 and earlier. An authenticated user with permissions to edit users can save malicious JavaScript as a User Group name and potentially take control over victims' accounts. This can lead to an escalation of privileges providing complete administrative control over the CMS.Show less
1Tine20
1Tine 2.0
May 13, 2026
Nov 17, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Tine 2.0 version 2017.02.4 is vulnerable to XSS in the Addressbook resulting code execution and privilege escalation
1Expressionengine
1Expressionengine
May 13, 2026
Nov 17, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
EllisLab ExpressionEngine 3.4.2 is vulnerable to cross-site scripting resulting in PHP code injection
1Scilico
1I, Librarian
Dec 5, 2025
Nov 17, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
I, Librarian version <=4.6 & 4.7 is vulnerable to Reflected Cross-Site Scripting in the temp.php resulting in an attacker being able to inject malicious client side scripting which will be executed in the browser of user...Show more
I, Librarian version <=4.6 & 4.7 is vulnerable to Reflected Cross-Site Scripting in the temp.php resulting in an attacker being able to inject malicious client side scripting which will be executed in the browser of users if they visit the manipulated site.Show less
1Open Emr
1Openemr
May 13, 2026
Nov 17, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The application OpenEMR is affected by multiple reflected & stored Cross-Site Scripting (XSS) vulnerabilities affecting version 5.0.0 and prior versions. These vulnerabilities could allow remote authenticated attackers t...Show more
The application OpenEMR is affected by multiple reflected & stored Cross-Site Scripting (XSS) vulnerabilities affecting version 5.0.0 and prior versions. These vulnerabilities could allow remote authenticated attackers to inject arbitrary web script or HTML.Show less
1Invoiceplane
1Invoiceplane
May 13, 2026
Nov 17, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
InvoicePlane version 1.4.10 is vulnerable to a Stored Cross Site Scripting resulting in allowing an authenticated user to inject malicious client side script which will be executed in the browser of users if they visit t...Show more
InvoicePlane version 1.4.10 is vulnerable to a Stored Cross Site Scripting resulting in allowing an authenticated user to inject malicious client side script which will be executed in the browser of users if they visit the manipulated site.Show less
1Ejs
1Ejs
May 13, 2026
Nov 17, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
nodejs ejs version older than 2.5.5 is vulnerable to a Cross-site-scripting in the ejs.renderFile() resulting in code injection
1Octobercms
1October
May 13, 2026
Nov 17, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
October CMS build 412 is vulnerable to stored WCI (a.k.a XSS) in brand logo image name resulting in JavaScript code execution in the victim's browser.