← Back
CWE-79

45,938 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (45,938)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Finecms Project
1Finecms
May 13, 2026
Jul 13, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
FineCMS through 2017-07-12 allows XSS in visitors.php because JavaScript in visited URLs is not restricted either during logging or during the reading of logs, a different vulnerability than CVE-2017-11180.
1Finecms Project
1Finecms
May 13, 2026
Jul 13, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
application/core/controller/images.php in FineCMS through 2017-07-12 allows remote authenticated admins to conduct XSS attacks by uploading an image via a route=images action.
1Finecms Project
1Finecms
May 13, 2026
Jul 13, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in /application/lib/ajax/get_image.php in FineCMS through 2017-07-12 allows remote attackers to inject arbitrary web script or HTML via the folder, id, or name parameter.
1Pulsesecure
1Pulse Connect Secure
May 13, 2026
Jul 12, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Pulse Connect Secure 8.3R1 has Reflected XSS in launchHelp.cgi. The helpLaunchPage parameter is reflected in an IFRAME element, if the value contains two quotes. It properly sanitizes quotes and tags, so one cannot simpl...Show more
Pulse Connect Secure 8.3R1 has Reflected XSS in launchHelp.cgi. The helpLaunchPage parameter is reflected in an IFRAME element, if the value contains two quotes. It properly sanitizes quotes and tags, so one cannot simply close the src with a quote and inject after that. However, an attacker can use javascript: or data: to abuse this.Show less
1Pulsesecure
1Pulse Connect Secure
May 13, 2026
Jul 12, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Pulse Connect Secure 8.3R1 has Reflected XSS in adminservercacertdetails.cgi. In the admin panel, the certid parameter of adminservercacertdetails.cgi is reflected in the application's response and is not properly saniti...Show more
Pulse Connect Secure 8.3R1 has Reflected XSS in adminservercacertdetails.cgi. In the admin panel, the certid parameter of adminservercacertdetails.cgi is reflected in the application's response and is not properly sanitized, allowing an attacker to inject tags. An attacker could come up with clever payloads to make the system run commands such as ping, ping6, traceroute, nslookup, arp, etc.Show less
1Ibm
2Infosphere Information Server
Infosphere Information Server On Cloud
May 13, 2026
Jul 12, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
IBM InfoSphere Information Server 9.1, 11.3, and 11.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality poten...Show more
IBM InfoSphere Information Server 9.1, 11.3, and 11.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 125916.Show less
1Ibm
1Emptoris Sourcing
May 13, 2026
Jul 12, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM Emptoris Sourcing 9.5.x through 10.1.x is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially lead...Show more
IBM Emptoris Sourcing 9.5.x through 10.1.x is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 118837.Show less
1Ibm
1Emptoris Sourcing
May 13, 2026
Jul 12, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM Emptoris Sourcing 9.5.x through 10.1.x is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially lead...Show more
IBM Emptoris Sourcing 9.5.x through 10.1.x is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 118835.Show less
1Ibm
1Emptoris Sourcing
May 13, 2026
Jul 12, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM Emptoris Sourcing 9.5.x through 10.1.x is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially lead...Show more
IBM Emptoris Sourcing 9.5.x through 10.1.x is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 118833.Show less
1Ibm
1Emptoris Sourcing
May 13, 2026
Jul 12, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM Emptoris Sourcing 9.5.x through 10.1.x is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially lead...Show more
IBM Emptoris Sourcing 9.5.x through 10.1.x is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 118352.Show less
1Apache
1Spark
May 13, 2026
Jul 12, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In Apache Spark before 2.2.0, it is possible for an attacker to take advantage of a user's trust in the server to trick them into visiting a link that points to a shared Spark cluster and submits data including MHTML to...Show more
In Apache Spark before 2.2.0, it is possible for an attacker to take advantage of a user's trust in the server to trick them into visiting a link that points to a shared Spark cluster and submits data including MHTML to the Spark master, or history server. This data, which could contain a script, would then be reflected back to the user and could be evaluated and executed by MS Windows-based clients. It is not an attack on Spark itself, but on the user, who may then execute the script inadvertently when viewing elements of the Spark web UIs.Show less
1Fairsketch
1Rise Ultimate Project Manager
May 13, 2026
Jul 12, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
In Rise Ultimate Project Manager v1.8, XSS vulnerabilities were found in the My Profile section. All input fields are vulnerable.
1Fairsketch
1Rise Ultimate Project Manager
May 13, 2026
Jul 12, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
In Rise Ultimate Project Manager v1.8, XSS vulnerabilities were found in the Messaging section. Subject and Message fields are vulnerable.
1Finecms Project
1Finecms
May 13, 2026
Jul 12, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
FineCMS through 2017-07-11 has stored XSS in the logging functionality, as demonstrated by an XSS payload in (1) the User-Agent header of an HTTP request or (2) the username entered on the login screen.
1Finecms Project
1Finecms
May 13, 2026
Jul 12, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
FineCMS through 2017-07-11 has stored XSS in route=admin when modifying user information, and in route=register when registering a user account.
1Microsoft
1Sharepoint Server
May 13, 2026
Jul 11, 2017
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Microsoft SharePoint Server allows an elevation of privilege vulnerability due to the way that it sanitizes a specially crafted web request to an affected SharePoint server, aka "SharePoint Server XSS Vulnerability".
1Microsoft
1Exchange Server
May 13, 2026
Jul 11, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Microsoft Exchange Server 2010 SP3, Exchange Server 2013 SP3, Exchange Server 2013 CU16, and Exchange Server 2016 CU5 allows an elevation of privilege vulnerability due to the way that Exchange Outlook Web Access (OWA) h...Show more
Microsoft Exchange Server 2010 SP3, Exchange Server 2013 SP3, Exchange Server 2013 CU16, and Exchange Server 2016 CU5 allows an elevation of privilege vulnerability due to the way that Exchange Outlook Web Access (OWA) handles web requests, aka "Microsoft Exchange Cross-Site Scripting Vulnerability". This CVE ID is unique from CVE-2017-8559.Show less
1Microsoft
1Exchange Server
May 13, 2026
Jul 11, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Microsoft Exchange Server 2010 SP3, Exchange Server 2013 SP3, Exchange Server 2013 CU16, and Exchange Server 2016 CU5 allows an elevation of privilege vulnerability due to the way that Exchange Outlook Web Access (OWA) h...Show more
Microsoft Exchange Server 2010 SP3, Exchange Server 2013 SP3, Exchange Server 2013 CU16, and Exchange Server 2016 CU5 allows an elevation of privilege vulnerability due to the way that Exchange Outlook Web Access (OWA) handles web requests, aka "Microsoft Exchange Cross-Site Scripting Vulnerability". This CVE ID is unique from CVE-2017-8560.Show less
1Cisco
1Identity Services Engine
May 13, 2026
Jul 10, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) Software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the we...Show more
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) Software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web interface of an affected device, related to the Guest Portal. More Information: CSCvd74794. Known Affected Releases: 1.3(0.909) 2.1(0.800).Show less
1Cisco
1Identity Services Engine
May 13, 2026
Jul 10, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A vulnerability in the web-based application interface of the Cisco Identity Services Engine (ISE) portal could allow an unauthenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a us...Show more
A vulnerability in the web-based application interface of the Cisco Identity Services Engine (ISE) portal could allow an unauthenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the web interface of an affected system. More Information: CSCvd87482. Known Affected Releases: 2.1(102.101) 2.2(0.283) 2.3(0.151).Show less