← Back
CWE-79

45,916 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (45,916)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Openeclass
1Openeclass
May 13, 2026
Apr 1, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Multiple Cross-Site Scripting (XSS) were discovered in 'openeclass Release_3.5.4'. The vulnerabilities exist due to insufficient filtration of user-supplied data (meeting_id, user) passed to the 'openeclass-master/module...Show more
Multiple Cross-Site Scripting (XSS) were discovered in 'openeclass Release_3.5.4'. The vulnerabilities exist due to insufficient filtration of user-supplied data (meeting_id, user) passed to the 'openeclass-master/modules/tc/webconf/webconf.php' URL. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website.Show less
1Wallaceit
1Wallacepos
May 13, 2026
Apr 1, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A Cross-Site Scripting (XSS) was discovered in 'wallacepos v1.4.1'. The vulnerability exists due to insufficient filtration of user-supplied data (token) passed to the 'wallacepos-master/myaccount/resetpassword.php' URL....Show more
A Cross-Site Scripting (XSS) was discovered in 'wallacepos v1.4.1'. The vulnerability exists due to insufficient filtration of user-supplied data (token) passed to the 'wallacepos-master/myaccount/resetpassword.php' URL. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website.Show less
1Helpmewatchwho Project
1Helpmewatchwho
May 13, 2026
Apr 1, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
TheFirstQuestion/HelpMeWatchWho before 2017-03-28 is vulnerable to a reflected XSS in HelpMeWatchWho-master/unaired.php (episodeID parameter).
1Symetrie Project
1Symetrie
May 13, 2026
Apr 1, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
citymont/symetrie v.0.9.6 is vulnerable to a reflected XSS in symetrie-master/app/commands/page.php (model parameter).
1Ibm
1Inotes
May 13, 2026
Mar 31, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
IBM iNotes 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials d...Show more
IBM iNotes 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM Reference #: 1998824.Show less
1Ibm
1Kenexa Lms
May 13, 2026
Mar 31, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM Kenexa LMS on Cloud 13.1, 13.2, 13.2.2, 13.2.3, 13.2.4 and 14.0.0 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended fu...Show more
IBM Kenexa LMS on Cloud 13.1, 13.2, 13.2.2, 13.2.3, 13.2.4 and 14.0.0 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM Reference #: 1999483.Show less
1Ibm
1Rational Quality Manager
May 13, 2026
Mar 31, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM Rational Quality Manager (RQM) 4.0, 5.0, and 6.0 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality poten...Show more
IBM Rational Quality Manager (RQM) 4.0, 5.0, and 6.0 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM Reference #: 2000784.Show less
1Ibm
1Rational Quality Manager
May 13, 2026
Mar 31, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM Rational Quality Manager 4.0, 5.0, and 6.0 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially...Show more
IBM Rational Quality Manager 4.0, 5.0, and 6.0 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM Reference #: 2000784.Show less
1Ibm
1Rational Quality Manager
May 13, 2026
Mar 31, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM Quality Manager (RQM) 4.0, 5.0, and 6.0 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially le...Show more
IBM Quality Manager (RQM) 4.0, 5.0, and 6.0 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM Reference #: 2000784.Show less
1Nagios
1Nagios
May 13, 2026
Mar 31, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in Nagios.
1Lucidcrew
1Pixie
May 13, 2026
Mar 31, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Pixie 1.0.4 allows an admin/index.php s=publish&m=module&x= XSS attack.
1Lucidcrew
1Pixie
May 13, 2026
Mar 31, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Pixie 1.0.4 allows an admin/index.php s=publish&m=dynamic&x= XSS attack.
1Lucidcrew
1Pixie
May 13, 2026
Mar 31, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Pixie 1.0.4 allows an admin/index.php s=publish&m=static&x= XSS attack.
1Lucidcrew
1Pixie
May 13, 2026
Mar 31, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Pixie 1.0.4 allows an admin/index.php s=settings&x= XSS attack.
1Lucidcrew
1Pixie
May 13, 2026
Mar 31, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Pixie 1.0.4 allows an admin/index.php s=login&m= XSS attack.
1Mantisbt
1Mantisbt
May 13, 2026
Mar 31, 2017
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
A cross-site scripting (XSS) vulnerability in the MantisBT Configuration Report page (adm_config_report.php) allows remote attackers to inject arbitrary code (if CSP settings permit it) through a crafted 'config_option'...Show more
A cross-site scripting (XSS) vulnerability in the MantisBT Configuration Report page (adm_config_report.php) allows remote attackers to inject arbitrary code (if CSP settings permit it) through a crafted 'config_option' parameter. This is fixed in 1.3.9, 2.1.3, and 2.2.3.Show less
1Mantisbt
1Mantisbt
May 13, 2026
Mar 31, 2017
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
A cross-site scripting (XSS) vulnerability in the MantisBT Move Attachments page (move_attachments_page.php, part of admin tools) allows remote attackers to inject arbitrary code through a crafted 'type' parameter, if Co...Show more
A cross-site scripting (XSS) vulnerability in the MantisBT Move Attachments page (move_attachments_page.php, part of admin tools) allows remote attackers to inject arbitrary code through a crafted 'type' parameter, if Content Security Protection (CSP) settings allows it. This is fixed in 1.3.9, 2.1.3, and 2.2.3. Note that this vulnerability is not exploitable if the admin tools directory is removed, as recommended in the "Post-installation and upgrade tasks" of the MantisBT Admin Guide. A reminder to do so is also displayed on the login page.Show less
1Mantisbt
1Mantisbt
May 13, 2026
Mar 31, 2017
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
A cross-site scripting (XSS) vulnerability in the MantisBT Configuration Report page (adm_config_report.php) allows remote attackers to inject arbitrary code through a crafted 'action' parameter. This is fixed in 1.3.8,...Show more
A cross-site scripting (XSS) vulnerability in the MantisBT Configuration Report page (adm_config_report.php) allows remote attackers to inject arbitrary code through a crafted 'action' parameter. This is fixed in 1.3.8, 2.1.2, and 2.2.2.Show less
1Modx
1Modx Revolution
May 13, 2026
Mar 30, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
setup/controllers/language.php in MODX Revolution 2.5.4-pl and earlier does not properly constrain the language parameter, which allows remote attackers to conduct Cookie-Bombing attacks and cause a denial of service (co...Show more
setup/controllers/language.php in MODX Revolution 2.5.4-pl and earlier does not properly constrain the language parameter, which allows remote attackers to conduct Cookie-Bombing attacks and cause a denial of service (cookie quota exhaustion), or conduct HTTP Response Splitting attacks with resultant XSS, via an invalid parameter value.Show less
1Netcomm
1Nb16wv 02 Firmware
May 13, 2026
Mar 29, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-site scripting (XSS) vulnerability in the NetComm NB16WV-02 router with firmware NB16WV_R0.09 allows remote authenticated users to inject arbitrary web script or HTML via the S801F0334 parameter to hdd.htm.