← Back
CWE-79

45,953 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (45,953)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Testlink
1Testlink
May 13, 2026
Sep 26, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Multiple cross-site scripting (XSS) vulnerabilities in TestLink before 1.9.14 allow remote attackers to inject arbitrary web script or HTML via the (1) selected_end_date or (2) selected_start_date parameter to lib/result...Show more
Multiple cross-site scripting (XSS) vulnerabilities in TestLink before 1.9.14 allow remote attackers to inject arbitrary web script or HTML via the (1) selected_end_date or (2) selected_start_date parameter to lib/results/tcCreatedPerUserOnTestProject.php; the (3) containerType parameter to lib/testcases/containerEdit.php; the (4) filter_tc_id or (5) filter_testcase_name parameter to lib/testcases/listTestCases.php; the (6) useRecursion parameter to lib/testcases/tcImport.php; the (7) targetTestCase or (8) created_by parameter to lib/testcases/tcSearch.php; or the (9) HTTP Referer header to third_party/user_contribution/fakeRemoteExecServer/client4fakeXMLRPCTestRunner.php.Show less
1Baidu
1Ueditor
May 13, 2026
Sep 26, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
UEditor 1.4.3.3 has XSS via the SRC attribute of an IFRAME element.
1Antisamy Project
1Antisamy
May 13, 2026
Sep 25, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
OWASP AntiSamy before 1.5.7 allows XSS via HTML5 entities, as demonstrated by use of : to construct a javascript: URL.
1Php Fusion
1Php Fusion
May 13, 2026
Sep 25, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-site scripting (XSS) vulnerability in PHP-Fusion 9.
1Redhat
1Jboss A Mq
May 13, 2026
Sep 25, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The JBoss console in A-MQ allows remote attackers to execute arbitrary JavaScript.
1Apache
1Struts
May 13, 2026
Sep 25, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in Apache Struts before 2.3.20.
1Plone
1Plone
May 13, 2026
Sep 25, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in Plone 3.3.0 through 3.3.6, 4.0.0 through 4.0.10, 4.1.0 through 4.1.6, 4.2.0 through 4.2.7, 4.3.x before 4.3.7, and 5.0rc1.
2Debian
Jsoup
2Debian Linux
Jsoup
May 13, 2026
Sep 25, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in jsoup before 1.8.3.
1Theforeman
1Foreman
May 13, 2026
Sep 25, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in Foreman 1.7.0 and after.
1Mahara
1Mahara
May 13, 2026
Sep 25, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Mahara 15.04 before 15.04.14 and 16.04 before 16.04.8 and 16.10 before 16.10.5 and 17.04 before 17.04.3 are vulnerable to a user submitting potential dangerous payload, e.g. XSS code, to be saved as their name in the usr...Show more
Mahara 15.04 before 15.04.14 and 16.04 before 16.04.8 and 16.10 before 16.10.5 and 17.04 before 17.04.3 are vulnerable to a user submitting potential dangerous payload, e.g. XSS code, to be saved as their name in the usr_registration table. The values are then emailed to the the user and administrator and if accepted become part of the new user's account.Show less
1Ibm
1Business Process Manager
May 13, 2026
Sep 25, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM Business Process Manager 8.5.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to c...Show more
IBM Business Process Manager 8.5.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 127477.Show less
1Geminabox Project
1Geminabox
May 13, 2026
Sep 25, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
geminabox (aka Gem in a Box) before 0.13.6 has XSS, as demonstrated by uploading a gem file that has a crafted gem.homepage value in its .gemspec file.
1Wordpress
1Wordpress
May 13, 2026
Sep 23, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Before version 4.8.2, WordPress was vulnerable to a cross-site scripting attack via shortcodes in the TinyMCE visual editor.
1Wordpress
1Wordpress
May 13, 2026
Sep 23, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Before version 4.8.2, WordPress was vulnerable to cross-site scripting in oEmbed discovery.
1Wordpress
1Wordpress
May 13, 2026
Sep 23, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Before version 4.8.2, WordPress allowed Cross-Site scripting in the plugin editor via a crafted plugin name.
1Wordpress
1Wordpress
May 13, 2026
Sep 23, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Before version 4.8.2, WordPress allowed a Cross-Site scripting attack in the template list view via a crafted template name.
1Wordpress
1Wordpress
May 13, 2026
Sep 23, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Before version 4.8.2, WordPress was susceptible to a Cross-Site Scripting attack in the link modal via a javascript: or data: URL.
1Telaxius
1Epesi
May 13, 2026
Sep 22, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
In EPESI 1.8.2 rev20170830, there is Stored XSS in the Tasks Description parameter.
1Telaxius
1Epesi
May 13, 2026
Sep 22, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
In EPESI 1.8.2 rev20170830, there is Stored XSS in the Tasks Title parameter.
1Telaxius
1Epesi
May 13, 2026
Sep 22, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
In EPESI 1.8.2 rev20170830, there is Stored XSS in the Tasks Alerts Title parameter.