CWE-79
45,954 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (45,954)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Solarwinds 1Network Performance Monitor May 13, 2026 Oct 3, 2017 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 Persistent cross-site scripting (XSS) in the Add Node function of SolarWinds Network Performance Monitor version 12.0.15300.90 allows remote attackers to introduce arbitrary JavaScript into various vulnerable parameters. |
Cross-site scripting (XSS) vulnerability in the EyesOfNetwork web interface (aka eonweb) 5.1-0 allows remote authenticated users to inject arbitrary web script or HTML via the url parameter to module/module_frame/index.p...Show more |
Cross-site scripting (XSS) vulnerability in the EyesOfNetwork web interface (aka eonweb) 5.1-0 allows remote authenticated users to inject arbitrary web script or HTML via the bp_name parameter to /module/admin_bp/add_se...Show more |
Cross-site scripting (XSS) vulnerability in the EyesOfNetwork web interface (aka eonweb) 5.1-0 allows remote authenticated administrators to inject arbitrary web script or HTML via the object parameter to module/admin_co...Show more |
Cross-Site Scripting (XSS) was discovered in ATutor before 2.2.3. The vulnerability exists due to insufficient filtration of data (url in /mods/_standard/rss_feeds/edit_feed.php). An attacker could inject arbitrary HTML...Show more |
1Opentext 1Document Sciences Xpression May 13, 2026 Oct 3, 2017 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 OpenText Document Sciences xPression (formerly EMC Document Sciences xPression) v4.5SP1 Patch 13 (older versions might be affected as well) is prone to Cross-Site Scripting: /xAdmin/html/Deployment (cat_id). |
1Opentext 1Document Sciences Xpression May 13, 2026 Oct 3, 2017 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 OpenText Document Sciences xPression (formerly EMC Document Sciences xPression) v4.5SP1 Patch 13 (older versions might be affected as well) is prone to Cross-Site Scripting: /xAdmin/html/XPressoDoc, parameter: categoryId...Show more |
1Ibm 1Rational Engineering Lifecycle Manager May 13, 2026 Oct 3, 2017 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 IBM RELM 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentia...Show more |
1Ibm 1Rational Engineering Lifecycle Manager May 13, 2026 Oct 3, 2017 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 IBM RELM 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentia...Show more |
1Ibm 1Rational Engineering Lifecycle Manager May 13, 2026 Oct 3, 2017 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 IBM RELM 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentia...Show more |
1Ibm 1Rational Engineering Lifecycle Manager May 13, 2026 Oct 3, 2017 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 IBM RELM 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentia...Show more |
1Ibm 1Insights Foundation For Energy May 13, 2026 Oct 3, 2017 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 IBM Insights Foundation for Energy 2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading...Show more |
1Ibm 1Rational Engineering Lifecycle Manager May 13, 2026 Oct 3, 2017 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 IBM RELM 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentia...Show more |
1Ibm 1Rational Engineering Lifecycle Manager May 13, 2026 Oct 3, 2017 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 IBM RELM 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentia...Show more |
1Ibm 1Rational Engineering Lifecycle Manager May 13, 2026 Oct 3, 2017 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 IBM RELM 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentia...Show more |
Multiple cross-site request forgery (CSRF) vulnerabilities in NexusPHP 1.5 allow remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via the (1) li...Show more |
1Compass Rose Project 1Compass Rose May 13, 2026 Oct 3, 2017 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Cross-site scripting (XSS) vulnerability in the Compass Rose module 6.x-1.x before 6.x-1.1 for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to "embedding a JavaSc...Show more |
Cross-site scripting (XSS) vulnerability in the uDesign (aka U-Design) theme 2.3.0 before 2.7.10 for WordPress allows remote attackers to inject arbitrary web script or HTML via a fragment identifier, as demonstrated by...Show more |
1Blogotext Project 1Blogotext May 13, 2026 Oct 2, 2017 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Stored XSS vulnerability via a comment in inc/conv.php in BlogoText before 3.7.6 allows an unauthenticated attacker to inject JavaScript. If the victim is an administrator, an attacker can (for example) change global set...Show more |
Stored XSS vulnerability via IMG element at "Leadname" of CRM in Tine 2.0 Community Edition before 2017.08.4 allows an authenticated user to inject JavaScript, which is mishandled during rendering by the application admi...Show more |