CWE-79
45,916 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (45,916)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Setucocms Project 1Setucocms May 13, 2026 Apr 12, 2017 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Cross-site scripting vulnerability in SetsucoCMS all versions allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. |
Cross-site scripting (XSS) vulnerability in the dependency graphs in Bugzilla 2.16rc1 through 4.4.11, and 4.5.1 through 5.0.2 allows remote attackers to inject arbitrary web script or HTML. |
Cross-site scripting (XSS) vulnerability in the standard template of the comment functionality in appleple a-blog cms 2.6.0.1 and earlier allows remote attackers to inject arbitrary web script or HTML. |
Multiple cross-site scripting (XSS) vulnerabilities in TeamPass 2.1.24 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) label value of an item or (2) name of a role. |
An exploitable reflected Cross-Site Scripting vulnerability exists in the Web Application functionality of Moxa AWK-3131A Wireless Access Point running firmware 1.1. Specially crafted input, in multiple parameters, can c...Show more |
An unauthenticated XSS vulnerability with FortiMail 5.0.0 - 5.2.9 and 5.3.0 - 5.3.8 could allow an attacker to execute arbitrary scripts in the security context of the browser of a victim logged in FortiMail, assuming th...Show more |
1Microsoft 5Excel Web App Office Online ServerOffice Web Apps+2 moreMay 13, 2026 Apr 12, 2017 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 Microsoft Excel Services on Microsoft SharePoint Server 2010 SP1 and SP2, Microsoft Excel Web Apps 2010 SP2, Microsoft Office Web Apps 2010 SP2, Microsoft Office Web Apps Server 2013 SP1 and Office Online Server allows r...Show more |
Cross Site Scripting Vulnerability in core-eMLi in AuroMeera Technometrix Pvt. Ltd. eMLi V1.0 allows an Attacker to send malicious code, generally in the form of a browser-side script, to a different end user via the pag...Show more |
Swagger-UI before 2.2.1 has XSS via the Default field in the Definitions section. |
1Opmantek 1Network Management Information System May 13, 2026 Apr 10, 2017 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 Opmantek NMIS before 8.5.12G has XSS via SNMP. |
1Paessler 1Prtg Network Monitor May 13, 2026 Apr 10, 2017 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Paessler PRTG before 16.2.24.4045 has XSS via SNMP. |
Netikus EventSentry before 3.2.1.44 has XSS via SNMP. |
CloudView NMS before 2.10a has XSS via a TELNET login. |
CloudView NMS before 2.10a has XSS via SNMP. |
OSRAM SYLVANIA Osram Lightify Pro before 2016-07-26 has XSS in the username field and Wireless Client Mode configuration page. |
Atlassian JIRA Server before 7.1.9 has XSS in project/ViewDefaultProjectRoleActors.jspa via a role name. |
Atlassian Confluence Server before 5.9.11 has XSS on the viewmyprofile.action page. |
1Dell 1Integrated Remote Access Controller Firmware May 13, 2026 Apr 10, 2017 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Dell Integrated Remote Access Controller (iDRAC) 6 before 2.85 and 7/8 before 2.30.30.30 has XSS. |
Opsview before 2015-11-06 has XSS via SNMP. |
Castle Rock Computing SNMPc before 2015-12-17 has XSS via SNMP. |