← Back
CWE-79

45,916 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (45,916)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Elastic
1Kibana
May 13, 2026
Jun 5, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Kibana version 5.4.0 was affected by a Cross Site Scripting (XSS) bug in the Time Series Visual Builder. This bug could allow an attacker to obtain sensitive information from Kibana users.
1Jamroom
1Jamroom
May 13, 2026
Jun 4, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross Site Scripting (XSS) exists in Jamroom before 4.2.7 via the Status Update field.
1Epesi
1Epesi
May 13, 2026
Jun 2, 2017
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Telaxus EPESI 1.8.2 and earlier has a Stored Cross-site Scripting (XSS) vulnerability in modules/Base/Dashboard/Dashboard_0.php, which allows remote attackers to inject arbitrary web script or HTML via a crafted tab_name...Show more
Telaxus EPESI 1.8.2 and earlier has a Stored Cross-site Scripting (XSS) vulnerability in modules/Base/Dashboard/Dashboard_0.php, which allows remote attackers to inject arbitrary web script or HTML via a crafted tab_name parameter.Show less
1Websitebaker
1Websitebaker
May 13, 2026
Jun 2, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
WebsiteBaker v2.10.0 has a stored XSS vulnerability in /account/details.php.
1Flipbuilder
1Flip Pdf
May 13, 2026
Jun 1, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in FlipBuilder Flip PDF allows remote attackers to inject arbitrary web script or HTML via the currentHTMLURL parameter.
1Fortinet
1Fortios
May 13, 2026
Jun 1, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A Cross-Site Scripting vulnerability in Fortinet FortiGate 5.2.0 through 5.2.10 allows attacker to execute unauthorized code or commands via the srcintf parameter during Firewall Policy Creation.
1Markdown On Save Improved Project
1Markdown On Save Improved
May 13, 2026
Jun 1, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Markdown on Save Improved plugin 2.5 for WordPress has a stored XSS vulnerability in the content of a post.
1Wp Editor.md Project
1Wp Editor.md
May 13, 2026
Jun 1, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The WP Editor.MD plugin 1.6 for WordPress has a stored XSS vulnerability in the content of a post.
1Epesi
1Epesi
May 13, 2026
Jun 1, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The Agenda component in Telaxus EPESI 1.8.2 and earlier has a Stored Cross-site Scripting (XSS) vulnerability in modules/Utils/RecordBrowser/RecordBrowserCommon_0.php, which allows remote attackers to inject arbitrary we...Show more
The Agenda component in Telaxus EPESI 1.8.2 and earlier has a Stored Cross-site Scripting (XSS) vulnerability in modules/Utils/RecordBrowser/RecordBrowserCommon_0.php, which allows remote attackers to inject arbitrary web script or HTML via a crafted meeting description parameter.Show less
1Syspass
1Syspass
May 13, 2026
May 31, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
inc/SP/Html/Html.class.php in sysPass 2.1.9 allows remote attackers to bypass the XSS filter, as demonstrated by use of an "<svg/onload=" substring instead of an "<svg onload=" substring.
1Tiki
1Tikiwiki Cms/groupware
May 13, 2026
May 31, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
lib/core/TikiFilter/PreventXss.php in Tiki Wiki CMS Groupware 16.2 allows remote attackers to bypass the XSS filter via padded zero characters, as demonstrated by an attack on tiki-batch_send_newsletter.php.
1Juniper
1Junos Space
May 13, 2026
May 30, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A reflected cross site scripting vulnerability in the administrative interface of Juniper Networks Junos Space versions prior to 16.1R1 may allow remote attackers to steal sensitive information or perform certain adminis...Show more
A reflected cross site scripting vulnerability in the administrative interface of Juniper Networks Junos Space versions prior to 16.1R1 may allow remote attackers to steal sensitive information or perform certain administrative actions on Junos Space.Show less
1Otrs
1Otrs
May 13, 2026
May 29, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Open Ticket Request System (OTRS) 3.3.9 has XSS in index.pl?Action=AgentStats requests, as demonstrated by OrderBy=[XSS] and Direction=[XSS] attacks. NOTE: this CVE may have limited relevance because it represents a 2017...Show more
Open Ticket Request System (OTRS) 3.3.9 has XSS in index.pl?Action=AgentStats requests, as demonstrated by OrderBy=[XSS] and Direction=[XSS] attacks. NOTE: this CVE may have limited relevance because it represents a 2017 discovery of an issue in software from 2014. The 3.3.20 release, for example, is not affected.Show less
1Hitachi
1Device Manager
May 13, 2026
May 29, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-site scripting vulnerability in Hitachi Device Manager before 8.5.2-01 and Hitachi Replication Manager before 8.5.2-00 allows authenticated remote users to execute arbitrary JavaScript code.
1Lansweeper
1Lansweeper
May 13, 2026
May 29, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Lansweeper before 6.0.0.65 has XSS in an image retrieval URI, aka Bug 542782.
1Note Project
1Note
May 13, 2026
May 29, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Bram Korsten Note through 1.2.0 is vulnerable to a reflected XSS in note-source\ui\editor.php (edit parameter).
1Raygun
1Raygun4wp
May 13, 2026
May 29, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Raygun4WP plugin 1.8.0 for WordPress is vulnerable to a reflected XSS in sendtesterror.php (backurl parameter).
1Finecms Project
1Finecms
May 13, 2026
May 28, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
andrzuk/FineCMS through 2017-05-28 is vulnerable to a reflected XSS in the search page via the text-search parameter to index.php in a route=search action.
1Finecms Project
1Finecms
May 13, 2026
May 28, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
andrzuk/FineCMS through 2017-05-28 is vulnerable to a reflected XSS in the sitename parameter to admin.php.
1Allen Disk Project
1Allen Disk
May 13, 2026
May 28, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-site scripting (XSS) vulnerability in Allen Disk 1.6 allows remote authenticated users to inject arbitrary web script or HTML persistently by uploading a crafted HTML file. The attack vector is the content of this...Show more
Cross-site scripting (XSS) vulnerability in Allen Disk 1.6 allows remote authenticated users to inject arbitrary web script or HTML persistently by uploading a crafted HTML file. The attack vector is the content of this file, and the filename must be specified in the PATH_INFO to readfile.php.Show less