CWE-79
45,950 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (45,950)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
IBM WebSphere Portal and Web Content Manager 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended funct...Show more |
1Ibm 1Infosphere Master Data Management Server May 13, 2026 Jul 31, 2017 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 IBM InfoSphere Master Data Management Server 10.1. 11.0. 11.3, 11.4, 11.5, and 11.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering th...Show more |
1Ibm 1Infosphere Master Data Management Server May 13, 2026 Jul 31, 2017 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 IBM InfoSphere Master Data Management Server 11.0, 11.3, 11.4, 11.5, and 11.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the inte...Show more |
In MODX Revolution 2.5.7, the "key" and "name" parameters in the System Settings module are vulnerable to XSS. A malicious payload sent to connectors/index.php will be triggered by every user, when they visit this module...Show more |
interface/js/app/history.js in WebUI in Rspamd before 1.6.3 allows XSS via the Subject and Message-Id headers, which are mishandled in the history page. |
MetInfo through 5.3.17 allows stored XSS via HTML Edit Mode. |
1Netcomm 24gt101w Bootloader 4gt101w SoftwareMay 13, 2026 Jul 28, 2017 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 NetComm Wireless 4GT101W routers with Hardware: 0.01 / Software: V1.1.8.8 / Bootloader: 1.1.3 are vulnerable to stored cross-site scripting attacks. Creating an SSID with an XSS payload results in successful exploitation...Show more |
Cross-site scripting (XSS) vulnerability in auth_profile.php in Cacti 1.1.13 allows remote attackers to inject arbitrary web script or HTML via specially crafted HTTP Referer headers. |
1Zohocorp 1Manageengine Eventlog Analyzer May 13, 2026 Jul 27, 2017 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Multiple Persistent cross-site scripting (XSS) vulnerabilities in Event log parsing and Display functions in Zoho ManageEngine Event Log Analyzer 11.4 and 11.5 allow remote attackers to inject arbitrary web script or HTM...Show more |
1Zohocorp 1Manageengine Eventlog Analyzer May 13, 2026 Jul 27, 2017 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Zoho ManageEngine Event Log Analyzer 11.4 and 11.5 allows remote attackers to obtain an authenticated user's password via XSS vulnerabilities or sniffing non-SSL traffic on the network, because the password is represente...Show more |
1Zohocorp 1Manageengine Eventlog Analyzer May 13, 2026 Jul 27, 2017 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Multiple Reflective cross-site scripting (XSS) vulnerabilities in search and display of event data in Zoho ManageEngine Event Log Analyzer 11.4 and 11.5 allow remote attackers to inject arbitrary web script or HTML, as d...Show more |
Stored Cross-site scripting vulnerability in Hashtopussy 0.4.0 allows remote attackers to inject arbitrary web script or HTML via the (1) version, (2) url, or (3) rootdir parameter in hashcat.php. |
1Hashtopus Project 1Hashtopus May 13, 2026 Jul 27, 2017 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Cross-site scripting (XSS) vulnerability in Hashtopus 1.5g allows remote attackers to inject arbitrary web script or HTML via the query string to admin.php. |
Cross-site scripting (XSS) vulnerability in js/ViewerPanel.js in the file previewer plugin in Kopano WebApp versions 3.3.0 and earlier allows remote attackers to inject arbitrary web script or HTML via a specially crafte...Show more |
In Joomla! before 3.7.4, inadequate filtering of potentially malicious HTML tags leads to XSS vulnerabilities in various components. |
NexusPHP V1.5 has XSS via a javascript: or data: URL in a UBBCode url tag. |
dayrui FineCms through 5.0.10 has Cross Site Scripting (XSS) in controllers/api.php via the function parameter in a c=api&m=data2 request. |
1Ektron 1Ektron Content Management System May 13, 2026 Jul 25, 2017 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Cross-site scripting (XSS) vulnerability in Ektron Content Management System before 9.1.0.184SP3(9.1.0.184.3.127) allows remote attackers to inject arbitrary web script or HTML via the rptStatus parameter in a Report act...Show more |
1Cisco 1Prime Collaboration Provisioning May 13, 2026 Jul 25, 2017 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 A vulnerability in the web portal of the Cisco Prime Collaboration Provisioning (PCP) Tool could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web interfac...Show more |
1Cisco 2Web Security Appliance Web Security Virtual ApplianceMay 13, 2026 Jul 25, 2017 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 A vulnerability in the web-based management interface of Cisco Web Security Appliance (WSA) could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the web-ba...Show more |