CWE-79
45,938 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (45,938)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Openmediavault 1Openmediavault May 13, 2026 Jul 17, 2017 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Multiple Cross-site scripting (XSS) vulnerabilities in rpc.php in OpenMediaVault release 2.1 in Access Rights Management(Users) functionality allows attackers to inject arbitrary web scripts and execute malicious scripts...Show more |
kittoframework kitto version 0.5.1 is vulnerable to an XSS in the 404 page resulting in information disclosure |
1Livehelperchat 1Live Helper Chat May 13, 2026 Jul 17, 2017 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Live Helper Chat version 2.06v and older is vulnerable to Cross-Site Scripting in the HTTP Header handling resulting in the execution of any user provided Javascript code in the session of other users. |
Stored XSS vulnerabilities in chevereto CMS before version 3.8.11, one in the user profile and one in the Exif data parser. |
Rocket.Chat version 0.8.0 and newer is vulnerable to XSS in the markdown link parsing code for messages. |
Cross-site scripting (XSS) vulnerability in pad export in XWiki labs CryptPad before 1.1.1 allows remote attackers to inject arbitrary web script or HTML via the pad content |
Mapbox.js versions 1.x prior to 1.6.6 and 2.x prior to 2.2.4 are vulnerable to a cross-site-scripting attack in certain uncommon usage scenarios via TileJSON name and map share control |
Mapbox.js versions 1.x prior to 1.6.5 and 2.x prior to 2.1.7 are vulnerable to a cross-site-scripting attack in certain uncommon usage scenarios via TileJSON Name. |
WordPress plugin Relevanssi version 3.5.7.1 is vulnerable to stored XSS resulting in attacker being able to execute JavaScript on the affected site |
Tiny Tiny RSS before 829d478f is vulnerable to XSS window.opener attack |
1Vospari Forms Project 1Vospari Forms May 13, 2026 Jul 17, 2017 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Wordpress Plugin Vospari Forms version < 1.4 is vulnerable to a reflected cross site scripting in the form submission resulting in javascript code execution in the context on the current user. |
Cross-Site scripting (XSS) vulnerabilities in Cacti 0.8.8b allow remote attackers to inject arbitrary web script or HTML via the parent_id parameter to tree.php and drp_action parameter to data_sources.php. |
LogicalDoc Community Edition 7.5.3 and prior is vulnerable to an XSS when using preview on HTML document. |
phpMyAdmin 4.0, 4.4, and 4.6 are vulnerable to a CSS injection attack through crafted cookie parameters |
MySQL Dumper version 1.24 is vulnerable to stored XSS when displaying the data in the database to the user |
MyWebSQL version 3.6 is vulnerable to stored XSS in the database manager component resulting in account takeover or stealing of information |
Plotly, Inc. plotly.js versions prior to 1.16.0 are vulnerable to an XSS issue. |
1Phpminiadmin Project 1Phpminiadmin May 13, 2026 Jul 17, 2017 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 PHPMiniAdmin version 1.9.160630 is vulnerable to stored XSS in the name of databases, tables and columns resulting in potential account takeover and scraping of data (stealing data). |
1Ibm 1Emptoris Strategic Supply Management May 13, 2026 Jul 13, 2017 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 IBM Emptoris Strategic Supply Management Platform 10.0.0.x through 10.1.1.x is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intend...Show more |
1Ibm 1Emptoris Strategic Supply Management May 13, 2026 Jul 13, 2017 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 IBM Emptoris Strategic Supply Management Platform 10.0.0.x through 10.1.1.x is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intend...Show more |