← Back
CWE-79

45,953 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (45,953)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Floating Social Bar Project
1Floating Social Bar
May 13, 2026
Sep 19, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in the Floating Social Bar plugin before 1.1.7 for WordPress allows remote attackers to inject arbitrary web script or HTML via vectors related to original service order.
1Kallithea Scm
1Kallithea
May 13, 2026
Sep 19, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Multiple cross-site scripting (XSS) vulnerabilities in the administration pages in Kallithea before 0.2.1 allow remote attackers to inject arbitrary web script or HTML via the (1) first name or (2) last name user details...Show more
Multiple cross-site scripting (XSS) vulnerabilities in the administration pages in Kallithea before 0.2.1 allow remote attackers to inject arbitrary web script or HTML via the (1) first name or (2) last name user details, or the (3) repository, (4) repository group, or (5) user group description.Show less
1Ibm
1Curam Social Program Management
May 13, 2026
Sep 19, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-site scripting (XSS) vulnerability in IBM Curam Social Program Management 6.0 SP2, 6.0.4, and 6.0.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. IBM X-Force ID: 98568.
1Afterlogic
2Aurora
Webmail
May 13, 2026
Sep 19, 2017
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
AdminPanel in AfterLogic WebMail 7.7 and Aurora 7.7.5 has XSS via the txtDomainName field to adminpanel/modules/pro/inc/ajax.php during addition of a domain.
1Nexusphp Project
1Nexusphp
May 13, 2026
Sep 18, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross Site Scripting (XSS) exists in NexusPHP 1.5.beta5.20120707 via the PATH_INFO to location.php, related to PHP_SELF.
1Moodle
1Moodle
May 13, 2026
Sep 18, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Moodle 3.x has XSS in the contact form on the "non-respondents" page in non-anonymous feedback.
1Sugarcrm
1Sugarcrm
May 13, 2026
Sep 17, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in SugarCRM before 7.7.2.3, 7.8.x before 7.8.2.2, and 7.9.x before 7.9.2.0 (and Sugar Community Edition 6.5.26). The WebToLeadCapture functionality is found vulnerable to unauthenticated cross-sit...Show more
An issue was discovered in SugarCRM before 7.7.2.3, 7.8.x before 7.8.2.2, and 7.9.x before 7.9.2.0 (and Sugar Community Edition 6.5.26). The WebToLeadCapture functionality is found vulnerable to unauthenticated cross-site scripting (XSS) attacks. This attack vector is mitigated by proper validating the redirect URL values being passed along.Show less
1Silverstripe
1Silverstripe
May 13, 2026
Sep 15, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
SilverStripe CMS before 3.6.1 has XSS via an SVG document that is mishandled by (1) the Insert Media option in the content editor or (2) an admin/assets/add pathname, as demonstrated by the admin/pages/edit/EditorToolbar...Show more
SilverStripe CMS before 3.6.1 has XSS via an SVG document that is mishandled by (1) the Insert Media option in the content editor or (2) an admin/assets/add pathname, as demonstrated by the admin/pages/edit/EditorToolbar/MediaForm/field/AssetUploadField/upload URI, aka issue SS-2017-017.Show less
1Vmware
1Vcenter Server
May 13, 2026
Sep 15, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
VMware vCenter Server (6.5 prior to 6.5 U1) contains a vulnerability that may allow for stored cross-site scripting (XSS). An attacker with VC user privileges can inject malicious java-scripts which will get executed whe...Show more
VMware vCenter Server (6.5 prior to 6.5 U1) contains a vulnerability that may allow for stored cross-site scripting (XSS). An attacker with VC user privileges can inject malicious java-scripts which will get executed when other VC users access the page.Show less
1Bobcares
1Gift Certificate Creator
May 13, 2026
Sep 14, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Vulnerability in wordpress plugin gift-certificate-creator v1.0, The code in gc-list.php doesn't sanitize user input to prevent a stored XSS vulnerability.
1Anblik
1Image Gallery With Slideshow
May 13, 2026
Sep 14, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Vulnerability in wordpress plugin image-gallery-with-slideshow v1.5.2, There is a stored XSS vulnerability via the $value->gallery_name and $value->gallery_description where anyone with privileges to modify or add galler...Show more
Vulnerability in wordpress plugin image-gallery-with-slideshow v1.5.2, There is a stored XSS vulnerability via the $value->gallery_name and $value->gallery_description where anyone with privileges to modify or add galleries/images and inject javascript into the database.Show less
1Dlink
1Dir 850l Firmware
May 13, 2026
Sep 13, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
D-Link DIR-850L REV. A (with firmware through FW114WWb07_h2ab_beta1) devices have XSS in the action parameter to htdocs/web/wandetect.php.
1Dlink
1Dir 850l Firmware
May 13, 2026
Sep 13, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
D-Link DIR-850L REV. A (with firmware through FW114WWb07_h2ab_beta1) devices have XSS in the action parameter to htdocs/web/sitesurvey.php.
1Dlink
1Dir 850l Firmware
May 13, 2026
Sep 13, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
D-Link DIR-850L REV. A (with firmware through FW114WWb07_h2ab_beta1) devices have XSS in the action parameter to htdocs/web/shareport.php.
1Dlink
1Dir 850l Firmware
May 13, 2026
Sep 13, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
D-Link DIR-850L REV. A (with firmware through FW114WWb07_h2ab_beta1) devices have XSS in the action parameter to htdocs/web/wpsacts.php.
1Apache
1Brooklyn
May 13, 2026
Sep 13, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
In Apache Brooklyn before 0.10.0, the REST server is vulnerable to cross-site scripting where one authenticated user can cause scripts to run in the browser of another user authorized to access the first user's resources...Show more
In Apache Brooklyn before 0.10.0, the REST server is vulnerable to cross-site scripting where one authenticated user can cause scripts to run in the browser of another user authorized to access the first user's resources. This is due to improper escaping of server-side content. There is known to be a proof-of-concept exploit using this vulnerability.Show less
1Axesstel
1Mu553s Firmware
May 13, 2026
Sep 13, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
On the Axesstel MU553S MU55XS-V1.14, there is a Stored Cross Site Scripting vulnerability in the APN parameter under the "Basic Settings" page.
1Microsoft
1Exchange Server
May 13, 2026
Sep 13, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Microsoft Exchange Server 2016 allows an elevation of privilege vulnerability when Microsoft Exchange Outlook Web Access (OWA) fails to properly handle web requests, aka "Microsoft Exchange Cross-Site Scripting Vulnerabi...Show more
Microsoft Exchange Server 2016 allows an elevation of privilege vulnerability when Microsoft Exchange Outlook Web Access (OWA) fails to properly handle web requests, aka "Microsoft Exchange Cross-Site Scripting Vulnerability."Show less
1Microsoft
1Sharepoint Foundation
May 13, 2026
Sep 13, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
An elevation of privilege vulnerability exists in Microsoft SharePoint Foundation 2013 Service Pack 1 when it does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft Sh...Show more
An elevation of privilege vulnerability exists in Microsoft SharePoint Foundation 2013 Service Pack 1 when it does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint Cross Site Scripting Vulnerability".Show less
1Microsoft
1Sharepoint Server
May 13, 2026
Sep 13, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Microsoft SharePoint Server 2013 Service Pack 1 allows an elevation of privilege vulnerability when it fails to properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoin...Show more
Microsoft SharePoint Server 2013 Service Pack 1 allows an elevation of privilege vulnerability when it fails to properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint XSS Vulnerability".Show less