← Back
CWE-79

45,916 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (45,916)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Adobe
1Coldfusion
May 13, 2026
Apr 27, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Adobe ColdFusion 2016 Update 3 and earlier, ColdFusion 11 update 11 and earlier, ColdFusion 10 Update 22 and earlier have a reflected cross-site scripting vulnerability.
1Apache
1Hadoop
May 13, 2026
Apr 26, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The HDFS web UI in Apache Hadoop before 2.7.0 is vulnerable to a cross-site scripting (XSS) attack through an unescaped query parameter.
1Ibm
1Maximo Asset Management
May 13, 2026
Apr 26, 2017
N/A· v4
5.6 MEDIUM· v3
4.3 MEDIUM· v2
IBM Maximo Asset Management 7.1, 7.5 and 7.6 could allow a remote attacker to hijack a user's session, caused by the failure to invalidate an existing session identifier. An attacker could exploit this vulnerability to g...Show more
IBM Maximo Asset Management 7.1, 7.5 and 7.6 could allow a remote attacker to hijack a user's session, caused by the failure to invalidate an existing session identifier. An attacker could exploit this vulnerability to gain access to another user's session. IBM X-Force ID: 118537.Show less
1Joomla
1Joomla
May 13, 2026
Apr 25, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In Joomla! 3.2.0 through 3.6.5 (fixed in 3.7.0), inadequate escaping of file and folder names leads to XSS vulnerabilities in the template manager component.
1Joomla
1Joomla
May 13, 2026
Apr 25, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In Joomla! 1.5.0 through 3.6.5 (fixed in 3.7.0), inadequate filtering of specific HTML attributes leads to XSS vulnerabilities in various components.
1Joomla
1Joomla
May 13, 2026
Apr 25, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In Joomla! 1.5.0 through 3.6.5 (fixed in 3.7.0), inadequate filtering of multibyte characters leads to XSS vulnerabilities in various components.
1Joomla
1Joomla
May 13, 2026
Apr 25, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In Joomla! 3.2.0 through 3.6.5 (fixed in 3.7.0), inadequate filtering leads to XSS in the template manager component.
3Debian
GoogleRedhat
5Chrome
Debian LinuxEnterprise Linux Desktop+2 more
May 13, 2026
Apr 24, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
XSS Auditor in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android allowed detection of a blocked iframe load, which allowed a remote attacker to brute force JavaScript variables...Show more
XSS Auditor in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android allowed detection of a blocked iframe load, which allowed a remote attacker to brute force JavaScript variables via a crafted HTML page.Show less
1Oracle
1One To One Fulfillment
May 13, 2026
Apr 24, 2017
N/A· v4
7.1 HIGH· v3
7.8 HIGH· v2
Vulnerability in the Oracle One-to-One Fulfillment component of Oracle E-Business Suite (subcomponent: Print Server). Supported versions that are affected are 12.1.3, 12.2.3, 12.2.4, 12.2.5 and 12.2.6. Easily "exploitabl...Show more
Vulnerability in the Oracle One-to-One Fulfillment component of Oracle E-Business Suite (subcomponent: Print Server). Supported versions that are affected are 12.1.3, 12.2.3, 12.2.4, 12.2.5 and 12.2.6. Easily "exploitable" vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle One-to-One Fulfillment. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle One-to-One Fulfillment, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle One-to-One Fulfillment accessible data as well as unauthorized update, insert or delete access to some of Oracle One-to-One Fulfillment accessible data. CVSS 3.0 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).Show less
1Mybb
1Mybb
May 13, 2026
Apr 24, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In MyBB before 1.8.11, the Email MyCode component allows XSS, as demonstrated by an onmouseover event.
1S9y
1Serendipity
May 13, 2026
Apr 24, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Stored XSS in Serendipity v2.1-rc1 allows an attacker to steal an admin's cookie and other information by composing a new entry as an editor user. This is related to lack of the serendipity_event_xsstrust plugin and a se...Show more
Stored XSS in Serendipity v2.1-rc1 allows an attacker to steal an admin's cookie and other information by composing a new entry as an editor user. This is related to lack of the serendipity_event_xsstrust plugin and a set_config error in that plugin.Show less
1Wp Ecommerce
1Easy Wp Smtp
May 13, 2026
Apr 24, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
XSS exists in Easy WP SMTP (before 1.2.5), a WordPress Plugin, via the e-mail subject or body.
1Netiq
1Access Manager
May 13, 2026
Apr 24, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An XSS vulnerability on the /NAGErrors URI in NetIQ Access Manager 4.2 and 4.3 exists because Access Gateway Error pages do not validate the HTTP Referer header.
1Exponentcms
1Exponent Cms
May 13, 2026
Apr 24, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In Exponent CMS before 2.4.1 Patch #5, XSS in elFinder is possible in framework/modules/file/connector/elfinder.php.
1Xoops
1Xoops
May 13, 2026
Apr 24, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
XOOPS Core 2.5.8.1 has XSS due to unescaped HTML output of an Install DB failure error message in page_dbsettings.php.
1Craftcms
1Craft Cms
May 13, 2026
Apr 22, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Craft CMS before 2.6.2974 allows XSS attacks.
2Openstack
Redhat
2Manila
Openstack
May 13, 2026
Apr 21, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-site scripting (XSS) vulnerability in the "Shares" overview in Openstack Manila before 2.5.1 allows remote authenticated users to inject arbitrary web script or HTML via the Metadata field in the "Create Share" for...Show more
Cross-site scripting (XSS) vulnerability in the "Shares" overview in Openstack Manila before 2.5.1 allows remote authenticated users to inject arbitrary web script or HTML via the Metadata field in the "Create Share" form.Show less
1Heartland Payment Systems
1Heartland Php
May 13, 2026
Apr 21, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Heartland Payment Systems Payment Gateway PHP SDK hps/heartland-php v2.8.17 is vulnerable to a reflected XSS in examples/consumer-authentication/cruise.php via the URI, as demonstrated by the cavv parameter.
1Paloaltonetworks
1Pan Os
May 13, 2026
Apr 21, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Palo Alto Networks PAN-OS before 7.0.15 has XSS in the GlobalProtect external interface via crafted request parameters, aka PAN-SA-2017-0011 and PAN-70674.
1Cisco
1Integrated Management Controller Supervisor
May 13, 2026
Apr 20, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A vulnerability in the web-based GUI of Cisco Integrated Management Controller (IMC) 3.0(1c) could allow an authenticated, remote attacker to perform a cross-site scripting (XSS) attack. The vulnerability is due to insuf...Show more
A vulnerability in the web-based GUI of Cisco Integrated Management Controller (IMC) 3.0(1c) could allow an authenticated, remote attacker to perform a cross-site scripting (XSS) attack. The vulnerability is due to insufficient validation of user-supplied input by the affected software. An attacker could exploit this vulnerability by persuading an authenticated user of the web-based GUI on an affected system to follow a malicious link. A successful exploit could allow the attacker to execute arbitrary code in the context of the web-based GUI on the affected system. Cisco Bug IDs: CSCvd14587.Show less