CWE-79
45,916 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (45,916)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Open Xchange 4Documentconverter Api Office WebOpen Xchange Appsuite Backend+1 moreMay 13, 2026 Mar 29, 2017 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Cross-site scripting (XSS) vulnerability in Open-Xchange (OX) AppSuite backend before 7.6.2-rev59, 7.8.0 before 7.8.0-rev38, 7.8.2 before 7.8.2-rev8; AppSuite frontend before 7.6.2-rev47, 7.8.0 before 7.8.0-rev30, and 7....Show more |
In Moodle 3.2.2+, there is XSS in the Course summary filter of the "Add a new course" page, as demonstrated by a crafted attribute of an SVG element. |
The integrated web server in Siemens RUGGEDCOM ROX I (all versions) at port 10000/TCP could allow an authenticated user to perform stored Cross-Site Scripting attacks. |
Siemens RUGGEDCOM ROX I (all versions) contain a vulnerability in the integrated web server at port 10000/TCP which is prone to reflected Cross-Site Scripting attacks if an unsuspecting user is induced to click on a mali...Show more |
Brave Browser iOS before 1.2.18 and Brave Browser Android 1.9.56 and earlier suffer from Full Address Bar Spoofing, allowing attackers to trick a victim by displaying a malicious page for legitimate domain names. |
1Revive Adserver 1Revive Adserver May 13, 2026 Mar 28, 2017 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 Revive Adserver before 3.2.5 and 4.0.0 suffers from Reflected XSS. The Revive Adserver web installer scripts were vulnerable to a reflected XSS attack via the dbHost, dbUser, and possibly other parameters. It has to be n...Show more |
1Revive Adserver 1Revive Adserver May 13, 2026 Mar 28, 2017 N/A· v4 9.0 CRITICAL· v3 9.3 HIGH· v2 Revive Adserver before 3.2.5 and 4.0.0 suffers from Reflected File Download. `www/delivery/asyncspc.php` was vulnerable to the fairly new Reflected File Download (RFD) web attack vector that enables attackers to gain com...Show more |
2Nextcloud Owncloud2Nextcloud Server OwncloudMay 13, 2026 Mar 28, 2017 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Nextcloud Server before 10.0.1 & ownCloud Server before 9.0.6 and 9.1.2 suffer from Reflected XSS in the Gallery application. The gallery app was not properly sanitizing exception messages from the Nextcloud/ownCloud ser...Show more |
2Nextcloud Owncloud2Nextcloud Server OwncloudMay 13, 2026 Mar 28, 2017 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 Nextcloud Server before 10.0.1 & ownCloud Server before 9.0.6 and 9.1.2 suffer from Stored XSS in CardDAV image export. The CardDAV image export functionality as implemented in Nextcloud/ownCloud allows the download of i...Show more |
2Nextcloud Owncloud2Nextcloud Server OwncloudMay 13, 2026 Mar 28, 2017 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Nextcloud Server before 9.0.52 & ownCloud Server before 9.0.4 are vulnerable to a log pollution vulnerability potentially leading to a local XSS. The download log functionality in the admin screen is delivering the log i...Show more |
1Revive Adserver 1Revive Adserver May 13, 2026 Mar 28, 2017 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 Revive Adserver before 3.2.3 suffers from Reflected XSS. `www/admin/stats.php` is vulnerable to reflected XSS attacks via multiple parameters that are not properly sanitised or escaped when displayed, such as setPerPage,...Show more |
1Revive Adserver 1Revive Adserver May 13, 2026 Mar 28, 2017 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 Revive Adserver before 3.2.3 suffers from Persistent XSS. A vector for persistent XSS attacks via the Revive Adserver user interface exists, requiring a trusted (non-admin) account. The banner image URL for external bann...Show more |
1Revive Adserver 1Revive Adserver May 13, 2026 Mar 28, 2017 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 Revive Adserver before 3.2.3 suffers from Persistent XSS. A vector for persistent XSS attacks via the Revive Adserver user interface exists, requiring a trusted (non-admin) account. The website name wasn't properly escap...Show more |
1Revive Adserver 1Revive Adserver May 13, 2026 Mar 28, 2017 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 Revive Adserver before 3.2.3 suffers from reflected XSS. The affiliate-preview.php script in www/admin is vulnerable to a reflected XSS attack. This vulnerability could be used by an attacker to steal the session ID of a...Show more |
1Revive Adserver 1Revive Adserver May 13, 2026 Mar 28, 2017 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 Revive Adserver before 3.2.3 suffers from persistent XSS. Usernames are not properly escaped when displayed in the audit trail widget of the dashboard upon login, allowing persistent XSS attacks. An authenticated user wi...Show more |
IBM WebSphere Portal 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to cre...Show more |
1Ibm 1Tririga Application Platform May 13, 2026 Mar 27, 2017 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 IBM TRIRIGA 3.3, 3.4, and 3.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to creden...Show more |
IBM Call Center for Commerce 9.3 and 9.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leadin...Show more |
Reflected Cross-site scripting (XSS) vulnerability in Yii Framework before 2.0.11, when development mode is used, allows remote attackers to inject arbitrary web script or HTML via crafted request data that is mishandled...Show more |
3Icinga OpensuseOpensuse Project3Icinga LeapLeapMay 13, 2026 Mar 27, 2017 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Cross-site scripting (XSS) vulnerability in the Classic-UI with the CSV export link and pagination feature in Icinga before 1.14 allows remote attackers to inject arbitrary web script or HTML via the query string to cgi-...Show more |