← Back
CWE-79

45,915 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (45,915)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Zammad
1Zammad
May 13, 2026
Mar 13, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An XSS issue was discovered in Zammad before 1.0.4, 1.1.x before 1.1.3, and 1.2.x before 1.2.1. Attachments are opened in a new tab instead of getting downloaded. This creates an attack vector of executing code in the do...Show more
An XSS issue was discovered in Zammad before 1.0.4, 1.1.x before 1.1.3, and 1.2.x before 1.2.1. Attachments are opened in a new tab instead of getting downloaded. This creates an attack vector of executing code in the domain of the application.Show less
1Roundcube
1Webmail
May 13, 2026
Mar 12, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
rcube_utils.php in Roundcube before 1.1.8 and 1.2.x before 1.2.4 is susceptible to a cross-site scripting vulnerability via a crafted Cascading Style Sheets (CSS) token sequence within an SVG element.
1Wordpress
1Wordpress
May 13, 2026
Mar 12, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In WordPress before 4.7.3 (wp-admin/js/tags-box.js), there is cross-site scripting (XSS) via taxonomy term names.
2Debian
Wordpress
2Debian Linux
Wordpress
May 13, 2026
Mar 12, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
In WordPress before 4.7.3 (wp-includes/embed.php), there is authenticated Cross-Site Scripting (XSS) in YouTube URL Embeds.
2Debian
Wordpress
2Debian Linux
Wordpress
May 13, 2026
Mar 12, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
In WordPress before 4.7.3, there is authenticated Cross-Site Scripting (XSS) via Media File Metadata. This is demonstrated by both (1) mishandling of the playlist shortcode in the wp_playlist_shortcode function in wp-inc...Show more
In WordPress before 4.7.3, there is authenticated Cross-Site Scripting (XSS) via Media File Metadata. This is demonstrated by both (1) mishandling of the playlist shortcode in the wp_playlist_shortcode function in wp-includes/media.php and (2) mishandling of meta information in the renderTracks function in wp-includes/js/mediaelement/wp-playlist.js.Show less
1Mangoswebv4 Project
1Mangoswebv4
May 13, 2026
Mar 11, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
paintballrefjosh/MaNGOSWebV4 4.0.8 is vulnerable to a reflected XSS in inc/admin/template_files/admin.vote.php (id parameter).
1Mangoswebv4 Project
1Mangoswebv4
May 13, 2026
Mar 11, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
paintballrefjosh/MaNGOSWebV4 4.0.8 is vulnerable to a reflected XSS in inc/admin/template_files/admin.shop.php (id parameter).
1Mangoswebv4 Project
1Mangoswebv4
May 13, 2026
Mar 11, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
paintballrefjosh/MaNGOSWebV4 4.0.8 is vulnerable to a reflected XSS in inc/admin/template_files/admin.fplinks.php (linkid parameter).
1Mangoswebv4 Project
1Mangoswebv4
May 13, 2026
Mar 11, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
paintballrefjosh/MaNGOSWebV4 4.0.8 is vulnerable to a reflected XSS in inc/admin/template_files/admin.donate.php (id parameter).
1Mangoswebv4 Project
1Mangoswebv4
May 13, 2026
Mar 11, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
paintballrefjosh/MaNGOSWebV4 4.0.8 is vulnerable to a reflected XSS in inc/admin/template_files/admin.faq.php (id parameter).
1Mantisbt
1Mantisbt
May 13, 2026
Mar 10, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A cross-site scripting (XSS) vulnerability in view_filters_page.php in MantisBT before 2.2.1 allows remote attackers to inject arbitrary JavaScript via the 'view_type' parameter.
1Mantisbt
1Mantisbt
May 13, 2026
Mar 10, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A cross-site scripting (XSS) vulnerability in bug_change_status_page.php in MantisBT before 1.3.7 and 2.x before 2.2.1 allows remote attackers to inject arbitrary JavaScript via the 'action_type' parameter.
1Django Epiceditor Project
1Django Epiceditor
May 13, 2026
Mar 9, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
There is a cross-site scripting vulnerability in django-epiceditor 0.2.3 via crafted content in a form field.
1Epiceditor Project
1Epiceditor
May 13, 2026
Mar 9, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
EpicEditor through 0.2.3 has Cross-Site Scripting because of an insecure default marked.js configuration. An example attack vector is a crafted IMG element in an HTML document.
1Agora Project
1Agora Project
May 13, 2026
Mar 9, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
XSS in Agora-Project 3.2.2 exists with an index.php?ctrl=file&targetObjId=fileFolder-2&targetObjIdChild=[XSS] attack.
1Agora Project
1Agora Project
May 13, 2026
Mar 9, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
XSS in Agora-Project 3.2.2 exists with an index.php?ctrl=object&action=[XSS] attack.
1Agora Project
1Agora Project
May 13, 2026
Mar 9, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
XSS in Agora-Project 3.2.2 exists with an index.php?ctrl=misc&action=[XSS]&editObjId=[XSS] attack.
1Agora Project
1Agora Project
May 13, 2026
Mar 9, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
XSS in Agora-Project 3.2.2 exists with an index.php?disconnect=1&msgNotif[]=[XSS] attack.
1Cmsmadesimple
1Cms Made Simple
May 13, 2026
Mar 9, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-site scripting (XSS) vulnerability in CMS Made Simple (CMSMS) 2.1.6 allows remote authenticated users to inject arbitrary web script or HTML via the "adminpage > sitesetting > General Settings > globalmetadata" fie...Show more
Cross-site scripting (XSS) vulnerability in CMS Made Simple (CMSMS) 2.1.6 allows remote authenticated users to inject arbitrary web script or HTML via the "adminpage > sitesetting > General Settings > globalmetadata" field.Show less
1Cmsmadesimple
1Cms Made Simple
May 13, 2026
Mar 9, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-site scripting (XSS) vulnerability in /admin/moduleinterface.php in CMS Made Simple 2.1.6 allows remote authenticated users to inject arbitrary web script or HTML via the m1_description parameter (aka "Design Manag...Show more
Cross-site scripting (XSS) vulnerability in /admin/moduleinterface.php in CMS Made Simple 2.1.6 allows remote authenticated users to inject arbitrary web script or HTML via the m1_description parameter (aka "Design Manager > Categories > Category Description").Show less