CWE-79
45,953 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (45,953)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Multiple cross-site scripting (XSS) vulnerabilities in TestLink before 1.9.14 allow remote attackers to inject arbitrary web script or HTML via the (1) selected_end_date or (2) selected_start_date parameter to lib/result...Show more |
UEditor 1.4.3.3 has XSS via the SRC attribute of an IFRAME element. |
OWASP AntiSamy before 1.5.7 allows XSS via HTML5 entities, as demonstrated by use of : to construct a javascript: URL. |
Cross-site scripting (XSS) vulnerability in PHP-Fusion 9. |
The JBoss console in A-MQ allows remote attackers to execute arbitrary JavaScript. |
Cross-site scripting (XSS) vulnerability in Apache Struts before 2.3.20. |
Cross-site scripting (XSS) vulnerability in Plone 3.3.0 through 3.3.6, 4.0.0 through 4.0.10, 4.1.0 through 4.1.6, 4.2.0 through 4.2.7, 4.3.x before 4.3.7, and 5.0rc1. |
2Debian Jsoup2Debian Linux JsoupMay 13, 2026 Sep 25, 2017 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Cross-site scripting (XSS) vulnerability in jsoup before 1.8.3. |
Cross-site scripting (XSS) vulnerability in Foreman 1.7.0 and after. |
Mahara 15.04 before 15.04.14 and 16.04 before 16.04.8 and 16.10 before 16.10.5 and 17.04 before 17.04.3 are vulnerable to a user submitting potential dangerous payload, e.g. XSS code, to be saved as their name in the usr...Show more |
IBM Business Process Manager 8.5.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to c...Show more |
geminabox (aka Gem in a Box) before 0.13.6 has XSS, as demonstrated by uploading a gem file that has a crafted gem.homepage value in its .gemspec file. |
Before version 4.8.2, WordPress was vulnerable to a cross-site scripting attack via shortcodes in the TinyMCE visual editor. |
Before version 4.8.2, WordPress was vulnerable to cross-site scripting in oEmbed discovery. |
Before version 4.8.2, WordPress allowed Cross-Site scripting in the plugin editor via a crafted plugin name. |
Before version 4.8.2, WordPress allowed a Cross-Site scripting attack in the template list view via a crafted template name. |
Before version 4.8.2, WordPress was susceptible to a Cross-Site Scripting attack in the link modal via a javascript: or data: URL. |
In EPESI 1.8.2 rev20170830, there is Stored XSS in the Tasks Description parameter. |
In EPESI 1.8.2 rev20170830, there is Stored XSS in the Tasks Title parameter. |
In EPESI 1.8.2 rev20170830, there is Stored XSS in the Tasks Alerts Title parameter. |