← Back
CWE-79

45,951 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (45,951)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ibm
1Qradar Network Security
May 13, 2026
Sep 5, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
IBM QRadar Network Security 5.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to cred...Show more
IBM QRadar Network Security 5.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 128376.Show less
1Xnau
1Participants Database
May 13, 2026
Sep 4, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Participants Database plugin before 1.7.5.10 for WordPress has XSS.
1Atutor
1Atutor
May 13, 2026
Aug 31, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in popuphelp.php in ATutor 2.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the h parameter.
1Icewarp
1Server
May 13, 2026
Aug 31, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In the webmail component in IceWarp Server 11.3.1.5, there was an XSS vulnerability discovered in the "language" parameter.
2Debian
Kohanaframework
2Debian Linux
Kohana
May 13, 2026
Aug 31, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in the Security component of Kohana before 3.3.6 allows remote attackers to inject arbitrary web script or HTML by bypassing the strip_image_tags protection mechanism in system/cl...Show more
Cross-site scripting (XSS) vulnerability in the Security component of Kohana before 3.3.6 allows remote attackers to inject arbitrary web script or HTML by bypassing the strip_image_tags protection mechanism in system/classes/Kohana/Security.php.Show less
1Phpthumb Project
1Phpthumb
May 13, 2026
Aug 31, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Multiple cross-site scripting (XSS) vulnerabilities in phpThumb() before 1.7.14 allow remote attackers to inject arbitrary web script or HTML via parameters in demo/phpThumb.demo.showpic.php.
1Nexusphp
1Nexusphp
May 13, 2026
Aug 31, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross Site Scripting (XSS) exists in NexusPHP 1.5.beta5.20120707 via the PATH_INFO to ipsearch.php, related to PHP_SELF.
1Ibm
1Emptoris Sourcing
May 13, 2026
Aug 31, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM Emptoris Sourcing 9.5 - 10.1.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to c...Show more
IBM Emptoris Sourcing 9.5 - 10.1.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 128172.Show less
1Ibm
1Emptoris Sourcing
May 13, 2026
Aug 31, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM Emptoris Sourcing 9.5 - 10.1.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to c...Show more
IBM Emptoris Sourcing 9.5 - 10.1.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 128110.Show less
1Cloudfoundry
1Cf Release
May 13, 2026
Aug 31, 2017
N/A· v4
4.7 MEDIUM· v3
2.6 LOW· v2
Gorouter in Cloud Foundry cf-release v141 through v228 allows man-in-the-middle attackers to conduct cross-site scripting (XSS) attacks via vectors related to modified requests.
1Blackcat Cms
1Blackcat Cms
May 13, 2026
Aug 31, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
In BlackCat CMS 1.2, backend/settings/ajax_save_settings.php allows remote authenticated users to conduct XSS attacks via the Website header or Website footer field.
1Ibm
1Emptoris Spend Analysis
May 13, 2026
Aug 30, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM Emptoris Spend Analysis 9.5.0.0 through 10.1.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentia...Show more
IBM Emptoris Spend Analysis 9.5.0.0 through 10.1.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 128171.Show less
1Ibm
1Emptoris Spend Analysis
May 13, 2026
Aug 30, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM Emptoris Spend Analysis 9.5.0.0 through 10.1.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentia...Show more
IBM Emptoris Spend Analysis 9.5.0.0 through 10.1.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 128170.Show less
1Ibm
1Emptoris Services Procurement
May 13, 2026
Aug 30, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
IBM Emptoris Services Procurement 10.0.0.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially lead...Show more
IBM Emptoris Services Procurement 10.0.0.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 128109.Show less
1Crushftp
1Crushftp
May 13, 2026
Aug 30, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
CrushFTP before 7.8.0 and 8.x before 8.2.0 has XSS.
1Apache
1Ofbiz
May 13, 2026
Aug 30, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The default configuration of the Apache OFBiz framework offers a blog functionality. Different users are able to operate blogs which are related to specific parties. In the form field for the creation of new blog article...Show more
The default configuration of the Apache OFBiz framework offers a blog functionality. Different users are able to operate blogs which are related to specific parties. In the form field for the creation of new blog articles the user input of the summary field as well as the article field is not properly sanitized. It is possible to inject arbitrary JavaScript code in these form fields. This code gets executed from the browser of every user who is visiting this article. Mitigation: Upgrade to Apache OFBiz 16.11.01.Show less
1Fiyo
1Fiyo Cms
May 13, 2026
Aug 30, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Fiyo CMS 2.0.7 has XSS in dapur\apps\app_config\sys_config.php via the site_name parameter.
1Onosproject
1Onos
May 13, 2026
Aug 30, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
ONOS versions 1.8.0, 1.9.0, and 1.10.0 are vulnerable to XSS.
1Ibm
1Cognos Analytics
May 13, 2026
Aug 29, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM Cognos Analytics 11.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credential...Show more
IBM Cognos Analytics 11.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 130677.Show less
1Ibm
1Cognos Analytics
May 13, 2026
Aug 29, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM Cognos Analytics 11.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credential...Show more
IBM Cognos Analytics 11.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 128623.Show less