← Back
CWE-79

45,916 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (45,916)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1F5
1Big Ip Access Policy Manager
May 13, 2026
May 9, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In F5 BIG-IP APM 12.0.0 through 12.1.2, non-authenticated users may be able to inject JavaScript into a request that will then be rendered and executed in the context of the Administrative user when the Administrative us...Show more
In F5 BIG-IP APM 12.0.0 through 12.1.2, non-authenticated users may be able to inject JavaScript into a request that will then be rendered and executed in the context of the Administrative user when the Administrative user is viewing the Access System Logs, allowing the non-authenticated user to carry out a Cross Site Scripting (XSS) attack against the Administrative user.Show less
1Nextcloud
1Nextcloud Server
May 13, 2026
May 8, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Nextcloud Server before 9.0.58 and 10.0.5 and 11.0.3 are shipping a vulnerable JavaScript library for sanitizing untrusted user-input which suffered from a XSS vulnerability caused by a behaviour change in Safari 10.1 an...Show more
Nextcloud Server before 9.0.58 and 10.0.5 and 11.0.3 are shipping a vulnerable JavaScript library for sanitizing untrusted user-input which suffered from a XSS vulnerability caused by a behaviour change in Safari 10.1 and 10.2. Note that Nextcloud employs a strict Content-Security-Policy preventing exploitation of this XSS issue on modern web browsers.Show less
1Nextcloud
1Nextcloud Server
May 13, 2026
May 8, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Nextcloud Server before 9.0.58 and 10.0.5 and 11.0.3 are vulnerable to an inadequate escaping of error messages leading to XSS vulnerabilities in multiple components.
1Nextcloud
1Nextcloud Server
May 13, 2026
May 8, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Nextcloud Server before 11.0.3 is vulnerable to an inadequate escaping leading to a XSS vulnerability in the search module. To be exploitable a user has to write or paste malicious content into the search dialogue.
1Zen Cart
1Zen Cart
May 13, 2026
May 8, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Zen Cart 1.6.0 has XSS in the main_page parameter to index.php. NOTE: 1.6.0 is not an official release but the vendor's README.md file offers a link to v160.zip with a description of "Download latest in-development versi...Show more
Zen Cart 1.6.0 has XSS in the main_page parameter to index.php. NOTE: 1.6.0 is not an official release but the vendor's README.md file offers a link to v160.zip with a description of "Download latest in-development version from github."Show less
1Allen Disk Project
1Allen Disk
May 13, 2026
May 8, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Allen Disk 1.6 has XSS in the id parameter to downfile.php.
1Certec Edv Gmbh
1Atvise Scada
May 13, 2026
May 6, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A Cross-Site Scripting issue was discovered in Certec EDV GmbH atvise scada prior to Version 3.0. This may allow remote code execution.
1Trendmicro
1Officescan
May 13, 2026
May 5, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Trend Micro OfficeScan 11.0 before SP1 CP 6325 (with Agent Module Build before 6152) and XG before CP 1352 has XSS via a crafted URI using a blocked website.
1Ibm
1Marketing Platform
May 13, 2026
May 5, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
IBM Marketing Platform 9.1 and 10.0 is vulnerable to stored cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability to inject malicious script into a...Show more
IBM Marketing Platform 9.1 and 10.0 is vulnerable to stored cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability to inject malicious script into a Web page which would be executed in a victim's Web browser within the security context of the hosting Web site, once the page is viewed. An attacker could use this vulnerability to steal the victim's cookie-based authentication credentials. IBM X-Force ID: 110564.Show less
1Accellion
1File Transfer Appliance
May 13, 2026
May 5, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered on Accellion FTA devices before FTA_9_12_180. There is XSS in home/seos/courier/smtpg_add.html with the param parameter.
1Accellion
1File Transfer Appliance
May 13, 2026
May 5, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered on Accellion FTA devices before FTA_9_12_180. There is XSS in home/seos/courier/user_add.html with the param parameter.
1Accellion
1File Transfer Appliance
May 13, 2026
May 5, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered on Accellion FTA devices before FTA_9_12_180. There is XSS in courier/1000@/index.html with the auth_params parameter. The device tries to use internal WAF filters to stop specific XSS Vulnerabili...Show more
An issue was discovered on Accellion FTA devices before FTA_9_12_180. There is XSS in courier/1000@/index.html with the auth_params parameter. The device tries to use internal WAF filters to stop specific XSS Vulnerabilities. However, these can be bypassed by using some modifications to the payloads, e.g., URL encoding.Show less
1Accellion
1File Transfer Appliance
May 13, 2026
May 5, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered on Accellion FTA devices before FTA_9_12_180. courier/1000@/oauth/playground/callback.html allows XSS with a crafted URI.
1Gitlab
1Gitlab
May 13, 2026
May 4, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
GitLab before 8.14.9, 8.15.x before 8.15.6, and 8.16.x before 8.16.5 has XSS via a SCRIPT element in an issue attachment or avatar that is an SVG document.
1Genixcms
1Genixcms
May 13, 2026
May 4, 2017
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
GeniXCMS 1.0.2 has XSS triggered by a comment that is mishandled during a publish operation by an administrator, as demonstrated by a malformed P element.
1Telaxius
1Epesi
May 13, 2026
May 4, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in modules/Base/Box/check_for_new_version.php in EPESI in Telaxus/EPESI 1.8.2 and earlier allows remote attackers to inject arbitrary web script or HTML via a crafted URI that lac...Show more
Cross-site scripting (XSS) vulnerability in modules/Base/Box/check_for_new_version.php in EPESI in Telaxus/EPESI 1.8.2 and earlier allows remote attackers to inject arbitrary web script or HTML via a crafted URI that lacks the cid parameter.Show less
1Genixcms
1Genixcms
May 13, 2026
May 3, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
GeniXCMS 1.0.2 has XSS triggered by an authenticated user who submits a page, as demonstrated by a crafted oncut attribute in a B element.
1Proxmox
1Proxmox Mail Gateway
May 13, 2026
May 3, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Multiple cross-site scripting (XSS) vulnerabilities in Proxmox Mail Gateway prior to hotfix 4.0-8-097d26a9 allow remote attackers to inject arbitrary web script or HTML via multiple parameters, related to /users/index.ht...Show more
Multiple cross-site scripting (XSS) vulnerabilities in Proxmox Mail Gateway prior to hotfix 4.0-8-097d26a9 allow remote attackers to inject arbitrary web script or HTML via multiple parameters, related to /users/index.htm, /quarantine/spam/manage.htm, /quarantine/spam/whitelist.htm, /queues/mail/index/, /system/ssh.htm, /queues/mail/?domain=, and /quarantine/virus/manage.htm.Show less
2Netiq
Novell
2Imanager
Imanager
May 13, 2026
May 3, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Novell iManager 2.7.x before 2.7 SP7 Patch 10 HF1 and NetIQ iManager 3.x before 3.0.3.1 have a persistent XSS vulnerability in Framework.
1Genixcms
1Genixcms
May 13, 2026
May 1, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
GeniXCMS 1.0.2 has XSS triggered by an authenticated comment that is mishandled during a mouse operation by an administrator.