← Back
CWE-79

45,916 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (45,916)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Setucocms Project
1Setucocms
May 13, 2026
Apr 12, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting vulnerability in SetsucoCMS all versions allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
1Mozilla
1Bugzilla
May 13, 2026
Apr 12, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in the dependency graphs in Bugzilla 2.16rc1 through 4.4.11, and 4.5.1 through 5.0.2 allows remote attackers to inject arbitrary web script or HTML.
1Appleple
1A Blog Cms
May 13, 2026
Apr 12, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in the standard template of the comment functionality in appleple a-blog cms 2.6.0.1 and earlier allows remote attackers to inject arbitrary web script or HTML.
1Teampass
1Teampass
May 13, 2026
Apr 12, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Multiple cross-site scripting (XSS) vulnerabilities in TeamPass 2.1.24 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) label value of an item or (2) name of a role.
1Moxa
1Awk 3131a Firmware
May 13, 2026
Apr 12, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An exploitable reflected Cross-Site Scripting vulnerability exists in the Web Application functionality of Moxa AWK-3131A Wireless Access Point running firmware 1.1. Specially crafted input, in multiple parameters, can c...Show more
An exploitable reflected Cross-Site Scripting vulnerability exists in the Web Application functionality of Moxa AWK-3131A Wireless Access Point running firmware 1.1. Specially crafted input, in multiple parameters, can cause a malicious scripts to be executed by a victim.Show less
1Fortinet
1Fortimail
May 13, 2026
Apr 12, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An unauthenticated XSS vulnerability with FortiMail 5.0.0 - 5.2.9 and 5.3.0 - 5.3.8 could allow an attacker to execute arbitrary scripts in the security context of the browser of a victim logged in FortiMail, assuming th...Show more
An unauthenticated XSS vulnerability with FortiMail 5.0.0 - 5.2.9 and 5.3.0 - 5.3.8 could allow an attacker to execute arbitrary scripts in the security context of the browser of a victim logged in FortiMail, assuming the victim is social engineered into clicking an URL crafted by the attacker.Show less
1Microsoft
5Excel Web App
Office Online ServerOffice Web Apps+2 more
May 13, 2026
Apr 12, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Microsoft Excel Services on Microsoft SharePoint Server 2010 SP1 and SP2, Microsoft Excel Web Apps 2010 SP2, Microsoft Office Web Apps 2010 SP2, Microsoft Office Web Apps Server 2013 SP1 and Office Online Server allows r...Show more
Microsoft Excel Services on Microsoft SharePoint Server 2010 SP1 and SP2, Microsoft Excel Web Apps 2010 SP2, Microsoft Office Web Apps 2010 SP2, Microsoft Office Web Apps Server 2013 SP1 and Office Online Server allows remote attackers to perform cross-site scripting and run script with local user privileges via a crafted request, aka "Microsoft Office XSS Elevation of Privilege Vulnerability."Show less
1Auromeera
1Emli
May 13, 2026
Apr 11, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross Site Scripting Vulnerability in core-eMLi in AuroMeera Technometrix Pvt. Ltd. eMLi V1.0 allows an Attacker to send malicious code, generally in the form of a browser-side script, to a different end user via the pag...Show more
Cross Site Scripting Vulnerability in core-eMLi in AuroMeera Technometrix Pvt. Ltd. eMLi V1.0 allows an Attacker to send malicious code, generally in the form of a browser-side script, to a different end user via the page parameter to code/student_portal/home.php. The affected versions are eMLi School Management 1.0, eMLi College Campus Management 1.0, and eMLi University Management 1.0.Show less
1Smartbear
1Swagger Ui
May 13, 2026
Apr 10, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Swagger-UI before 2.2.1 has XSS via the Default field in the Definitions section.
1Opmantek
1Network Management Information System
May 13, 2026
Apr 10, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Opmantek NMIS before 8.5.12G has XSS via SNMP.
1Paessler
1Prtg Network Monitor
May 13, 2026
Apr 10, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Paessler PRTG before 16.2.24.4045 has XSS via SNMP.
1Netikus
1Eventsentry
May 13, 2026
Apr 10, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Netikus EventSentry before 3.2.1.44 has XSS via SNMP.
1Cloudviewnms
1Cloudview Nms
May 13, 2026
Apr 10, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
CloudView NMS before 2.10a has XSS via a TELNET login.
1Cloudviewnms
1Cloudview Nms
May 13, 2026
Apr 10, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
CloudView NMS before 2.10a has XSS via SNMP.
1Osram
1Lightify Pro
May 13, 2026
Apr 10, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
OSRAM SYLVANIA Osram Lightify Pro before 2016-07-26 has XSS in the username field and Wireless Client Mode configuration page.
1Atlassian
1Jira
May 13, 2026
Apr 10, 2017
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Atlassian JIRA Server before 7.1.9 has XSS in project/ViewDefaultProjectRoleActors.jspa via a role name.
1Atlassian
1Confluence
May 13, 2026
Apr 10, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Atlassian Confluence Server before 5.9.11 has XSS on the viewmyprofile.action page.
1Dell
1Integrated Remote Access Controller Firmware
May 13, 2026
Apr 10, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Dell Integrated Remote Access Controller (iDRAC) 6 before 2.85 and 7/8 before 2.30.30.30 has XSS.
1Opsview
1Opsview
May 13, 2026
Apr 10, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Opsview before 2015-11-06 has XSS via SNMP.
1Castlerock
1Snmpc
May 13, 2026
Apr 10, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Castle Rock Computing SNMPc before 2015-12-17 has XSS via SNMP.