← Back
CWE-79

45,971 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (45,971)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ca
1Identity Governance
May 13, 2026
Nov 14, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A stored cross-site scripting vulnerability in CA Identity Governance 12.6 allows remote authenticated attackers to display HTML or execute script in the context of another user.
1Snapcreek
1Duplicator
May 13, 2026
Nov 14, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
installer.php in the Snap Creek Duplicator (WordPress Site Migration & Backup) plugin before 1.2.30 for WordPress has XSS because the values "url_new" (/wp-content/plugins/duplicator/installer/build/view.step4.php) and "...Show more
installer.php in the Snap Creek Duplicator (WordPress Site Migration & Backup) plugin before 1.2.30 for WordPress has XSS because the values "url_new" (/wp-content/plugins/duplicator/installer/build/view.step4.php) and "logging" (wp-content/plugins/duplicator/installer/build/view.step2.php) are not filtered correctly.Show less
1Kodak
1Insite
May 13, 2026
Nov 14, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Multiple cross-site scripting (XSS) vulnerabilities in Kodak InSite 6.5 to 8.0 allow remote attackers to inject arbitrary web script via the (1) "paramFile" parameter to /Site/Troubleshooting/DiagnosticReport.asp, or (2)...Show more
Multiple cross-site scripting (XSS) vulnerabilities in Kodak InSite 6.5 to 8.0 allow remote attackers to inject arbitrary web script via the (1) "paramFile" parameter to /Site/Troubleshooting/DiagnosticReport.asp, or (2) "paramFile" parameter to /Site/Troubleshooting/SpeedTest.asp.Show less
1Octopus
1Octopus Deploy
May 13, 2026
Nov 14, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-site scripting (XSS) vulnerability in the All Variables tab in Octopus Deploy 3.4.0-3.13.6 (fixed in 3.13.7) allows remote attackers to inject arbitrary web script or HTML via the Variable Set Name parameter.
1Getkirby
1Panel
May 13, 2026
Nov 13, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A cross-site Scripting (XSS) vulnerability in Kirby Panel before 2.3.3, 2.4.x before 2.4.2, and 2.5.x before 2.5.7 exists when displaying a specially prepared SVG document that has been uploaded as a content file.
1Misp Project
1Misp
May 13, 2026
Nov 13, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
In the sharingGroupPopulateOrganisations function in app/webroot/js/misp.js in MISP 2.4.82, there is XSS via a crafted organisation name that is manually added.
1Fortinet
1Fortios
May 13, 2026
Nov 13, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A reflected Cross-site Scripting (XSS) vulnerability in web proxy disclaimer response web pages in Fortinet FortiOS 5.6.0, 5.4.0 to 5.4.5, 5.2.0 to 5.2.11 allows an unauthenticated attacker to inject arbitrary web script...Show more
A reflected Cross-site Scripting (XSS) vulnerability in web proxy disclaimer response web pages in Fortinet FortiOS 5.6.0, 5.4.0 to 5.4.5, 5.2.0 to 5.2.11 allows an unauthenticated attacker to inject arbitrary web script or HTML in the context of the victim's browser via sending a maliciously crafted URL to the victim.Show less
1Octopus
1Octopus Deploy
May 13, 2026
Nov 13, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-site scripting (XSS) vulnerability in Octopus Deploy 3.7.0-3.17.13 (fixed in 3.17.14) allows remote authenticated users to inject arbitrary web script or HTML via the Step Template Name parameter.
1Geminabox Project
1Geminabox
May 13, 2026
Nov 13, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Stored cross-site scripting (XSS) vulnerability in "geminabox" (Gem in a Box) before 0.13.10 allows attackers to inject arbitrary web script via the "homepage" value of a ".gemspec" file, related to views/gem.erb and vie...Show more
Stored cross-site scripting (XSS) vulnerability in "geminabox" (Gem in a Box) before 0.13.10 allows attackers to inject arbitrary web script via the "homepage" value of a ".gemspec" file, related to views/gem.erb and views/index.erb.Show less
1Apple
1Mac Os X
May 13, 2026
Nov 13, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "HelpViewer" component. A cross-site scripting (XSS) vulnerability allows remote attackers to inject arbitrary w...Show more
An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "HelpViewer" component. A cross-site scripting (XSS) vulnerability allows remote attackers to inject arbitrary web script or HTML by bypassing the Same Origin Policy for quarantined HTML documents.Show less
1Cmsmadesimple
1Cmsmadesimple
May 13, 2026
Nov 12, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
In CMS Made Simple 2.2.3.1, in modules/New/action.addcategory.php, stored XSS is possible via the m1_name parameter to admin/moduleinterface.php during addition of a category, a related issue to CVE-2010-3882.
1Cmsmadesimple
1Cms Made Simple
May 13, 2026
Nov 12, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
In CMS Made Simple 2.2.3.1, the is_file_acceptable function in modules/FileManager/action.upload.php only blocks file extensions that begin or end with a "php" substring, which allows remote attackers to bypass intended...Show more
In CMS Made Simple 2.2.3.1, the is_file_acceptable function in modules/FileManager/action.upload.php only blocks file extensions that begin or end with a "php" substring, which allows remote attackers to bypass intended access restrictions or trigger XSS via other extensions, as demonstrated by .phtml, .pht, .html, or .svg.Show less
1Cacti
1Cacti
May 13, 2026
Nov 10, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cacti 1.1.27 has reflected XSS via the PATH_INFO to host.php.
1Cmsmadesimple
1Cms Made Simple
May 13, 2026
Nov 10, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In CMS Made Simple 2.2.2, there is Reflected XSS via the cntnt01detailtemplate parameter.
1Home Assistant
1Home Assistant
May 13, 2026
Nov 10, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In Home Assistant before 0.57, it is possible to inject JavaScript code into a persistent notification via crafted Markdown text, aka XSS.
1Mybb
1Mybb
May 13, 2026
Nov 10, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The installer in MyBB before 1.8.13 has XSS.
1Dlink
1Dwr 933 Firmware
May 13, 2026
Nov 10, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
XSS exists on D-Link DWR-933 1.00(WW)B17 devices via cgi-bin/gui.cgi.
1Inedo
1Buildmaster
May 13, 2026
Nov 10, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Inedo BuildMaster before 5.8.2 has XSS.
1Logitech
1Media Server
May 13, 2026
Nov 10, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Persistent Cross-Site Scripting (XSS) vulnerability in Logitech Media Server 7.9.0, affecting the "Radio" functionality. This vulnerability allows attackers to inject malicious JavaScript payloads, which become permanent...Show more
Persistent Cross-Site Scripting (XSS) vulnerability in Logitech Media Server 7.9.0, affecting the "Radio" functionality. This vulnerability allows attackers to inject malicious JavaScript payloads, which become permanently stored on the server and execute when a user plays the compromised radio stream. Exploitation of this vulnerability can lead to Session hijacking and unauthorized access, Persistent manipulation of web content within the application, and Phishing or malicious redirects to external domains. This vulnerability can be exploited to manipulate media server behavior in enterprise and home network environments.Show less
1Logitech
1Media Server
May 13, 2026
Nov 10, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Persistent Cross-Site Scripting (XSS) vulnerability in Logitech Media Server 7.9.0, affecting the "Favorites" feature. This vulnerability allows remote attackers to inject and permanently store malicious JavaScript paylo...Show more
Persistent Cross-Site Scripting (XSS) vulnerability in Logitech Media Server 7.9.0, affecting the "Favorites" feature. This vulnerability allows remote attackers to inject and permanently store malicious JavaScript payloads, which are executed when users access the affected functionality. Exploitation of this vulnerability can lead to Session Hijacking and Credential Theft, Execution of unauthorized actions on behalf of users, and Exfiltration of sensitive data. This vulnerability presents a potential risk for widespread exploitation in connected IoT environments.Show less