← Back
CWE-79

45,916 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (45,916)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Sophos
1Web Appliance
May 13, 2026
Jun 9, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Sophos Web Appliance before 4.3.2 has XSS in the FTP redirect page, aka NSWA-1342.
1Ibm
1Business Process Manager
May 13, 2026
Jun 8, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM Business Process Manager 8.0 and 8.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leadi...Show more
IBM Business Process Manager 8.0 and 8.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.Show less
1Open Xchange
2Open Xchange Appsuite
Open Xchange Server
May 13, 2026
Jun 8, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Multiple cross-site scripting (XSS) vulnerabilities in Open-Xchange Server 6 and OX AppSuite before 7.4.2-rev43, 7.6.0-rev38, and 7.6.1-rev21.
1Craftcms
1Craft Cms
May 13, 2026
Jun 8, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Craft CMS before 2.6.2982 allows for a potential XSS attack vector by uploading a malicious SVG file.
1Wordpress Backup To Dropbox Project
1Wordpress Backup To Dropbox
May 13, 2026
Jun 7, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in the WordPress Backup to Dropbox plugin before 4.1 for WordPress.
1Vindula
1Vindula
May 13, 2026
Jun 7, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-site scripting (XSS) vulnerability in Vindula 1.9.
1Igcb
1Intellect Digital Core
May 13, 2026
Jun 7, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in Intellect Design Arena Intellect Core banking software.
1Ibm
1Rational Doors Next Generation
May 13, 2026
Jun 7, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM DOORS Next Generation (DNG/RRC) 6.0.2 and 6.0.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potenti...Show more
IBM DOORS Next Generation (DNG/RRC) 6.0.2 and 6.0.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 125459.Show less
1Ibm
1Bigfix Security Compliance Analytics
May 13, 2026
Jun 7, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
IBM Endpoint Manager for Security and Compliance 1.9.70 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality pot...Show more
IBM Endpoint Manager for Security and Compliance 1.9.70 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 123430.Show less
1Sophos
1Cyberoam Firmware
May 13, 2026
Jun 7, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An XSS vulnerability allows remote attackers to execute arbitrary client side script on vulnerable installations of Sophos Cyberoam firewall devices with firmware through 10.6.4. User interaction is required to exploit t...Show more
An XSS vulnerability allows remote attackers to execute arbitrary client side script on vulnerable installations of Sophos Cyberoam firewall devices with firmware through 10.6.4. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of a request to the "LiveConnectionDetail.jsp" application. GET parameters "applicationname" and "username" are improperly sanitized allowing an attacker to inject arbitrary JavaScript into the page. This can be abused by an attacker to perform a cross-site scripting attack on the user. A vulnerable URI is /corporate/webpages/trafficdiscovery/LiveConnectionDetail.jsp.Show less
1Piwigo
1Piwigo
May 13, 2026
Jun 6, 2017
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Cross-site scripting (XSS) vulnerability in admin.php in Piwigo 2.9.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the page parameter.
1Flatcore
1Flatcore
May 13, 2026
Jun 6, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross site scripting (XSS) vulnerability in pages.edit_form.php in flatCore 1.4.6 allows remote attackers to inject arbitrary JavaScript via the PATH_INFO in an acp.php URL, due to use of unsanitized $_SERVER['PHP_SELF']...Show more
Cross site scripting (XSS) vulnerability in pages.edit_form.php in flatCore 1.4.6 allows remote attackers to inject arbitrary JavaScript via the PATH_INFO in an acp.php URL, due to use of unsanitized $_SERVER['PHP_SELF'] to generate URLs.Show less
1Cgiirc
1Cgi\
May 13, 2026
Jun 6, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
irc.cgi in CGI:IRC before 0.5.12 reflects user-supplied input from the R parameter without proper output encoding, aka XSS.
1Bigtreecms
1Bigtree Cms
May 13, 2026
Jun 6, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-site scripting (XSS) vulnerabilities in BigTree CMS through 4.2.18 allow remote authenticated users to inject arbitrary web script or HTML via the description parameter. This issue exists in core\admin\ajax\pages\s...Show more
Cross-site scripting (XSS) vulnerabilities in BigTree CMS through 4.2.18 allow remote authenticated users to inject arbitrary web script or HTML via the description parameter. This issue exists in core\admin\ajax\pages\save-revision.php and core\admin\modules\pages\revisions.php. Low-privileged (administrator) users can attack high-privileged (Developer) users.Show less
1Pivotx
1Pivotx
May 13, 2026
Jun 6, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The smarty_self function in modules/module_smarty.php in PivotX 2.3.11 mishandles the URI, allowing XSS via vectors involving quotes in the self Smarty tag.
1Bigtreecms
1Bigtree Cms
May 13, 2026
Jun 5, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Multiple cross-site scripting (XSS) vulnerabilities in BigTree CMS through 4.2.18 allow remote authenticated users to inject arbitrary web script or HTML by uploading a crafted package, triggering mishandling of the (1)...Show more
Multiple cross-site scripting (XSS) vulnerabilities in BigTree CMS through 4.2.18 allow remote authenticated users to inject arbitrary web script or HTML by uploading a crafted package, triggering mishandling of the (1) title or (2) version or (3) author_name parameter in manifest.json. This issue exists in core\admin\modules\developer\extensions\install\unpack.php and core\admin\modules\developer\packages\install\unpack.php. NOTE: the vendor states "You must implicitly trust any package or extension you install as they all have the ability to write PHP files.Show less
1Sunnythemes
1Spiffy Calendar
May 13, 2026
Jun 5, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross site scripting (XSS) vulnerability in the Spiffy Calendar plugin before 3.3.0 for WordPress allows remote attackers to inject arbitrary JavaScript via the yr parameter.
1Peplink
61350hw2 Firmware
2500 Firmware380hw6 Firmware+3 more
May 13, 2026
Jun 5, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
XSS via orig_url exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw2_710hw3_1350hw2_2500-7.0.1-build2093. The affected script is guest/preview.cgi.
1Peplink
61350hw2 Firmware
2500 Firmware380hw6 Firmware+3 more
May 13, 2026
Jun 5, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
XSS via syncid exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw2_710hw3_1350hw2_2500-7.0.1-build2093. The affected script is cgi-bin/HASync/hasync.cgi.
1Elastic
1Kibana
May 13, 2026
Jun 5, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Starting in version 5.3.0, Kibana had a cross-site scripting (XSS) vulnerability in the Discover page that could allow an attacker to obtain sensitive information from or perform destructive actions on behalf of other Ki...Show more
Starting in version 5.3.0, Kibana had a cross-site scripting (XSS) vulnerability in the Discover page that could allow an attacker to obtain sensitive information from or perform destructive actions on behalf of other Kibana users.Show less