← Back
CWE-79

45,887 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (45,887)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Cisco
1Email Security Appliance
May 6, 2026
Oct 28, 2016
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A vulnerability in the display of email messages in the Messages in Quarantine (MIQ) view in Cisco AsyncOS for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to cause a user to click...Show more
A vulnerability in the display of email messages in the Messages in Quarantine (MIQ) view in Cisco AsyncOS for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to cause a user to click a malicious link in the MIQ view. The malicious link could be used to facilitate a cross-site scripting (XSS) or HTML injection attack. More Information: CSCuz02235. Known Affected Releases: 8.0.2-069. Known Fixed Releases: 9.1.1-038 9.7.2-047.Show less
1Huge It
1Slider
May 6, 2026
Oct 27, 2016
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
XSS and SQLi in Huge IT Joomla Slider v1.0.9 extension
1Novell
2Identity Manager
Identity Manager Identity Applications
May 6, 2026
Oct 27, 2016
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
XSS in NetIQ IDM 4.5 Identity Applications before 4.5.4 allows attackers able to change their username to inject arbitrary HTML code into the Role Assignment administrator HTML pages.
1Netiq
1Identity Manager
May 6, 2026
Oct 27, 2016
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
XSS in NetIQ Designer for Identity Manager before 4.5.3 allows remote attackers to inject arbitrary HTML code via the nrfEntitlementReport.do CGI.
1Netiq
1Identity Manager
May 6, 2026
Oct 27, 2016
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
XSS in NetIQ Designer for Identity Manager before 4.5.3 allows remote attackers to inject arbitrary HTML code via the accessMgrDN value of the forgotUser.do CGI.
1Yandex
1Yandex Browser
May 6, 2026
Oct 26, 2016
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
XSS in Yandex Browser Translator in Yandex browser for desktop for versions from 15.12 to 16.2 could be used by remote attacker for evaluation arbitrary javascript code.
1Yandex
1Yandex.browser
May 6, 2026
Oct 26, 2016
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
XSS in Yandex Browser BookReader in Yandex browser for desktop for versions before 16.6. could be used by remote attacker for evaluation arbitrary javascript code.
1Oracle
1Agile Product Lifecycle Management
May 6, 2026
Oct 25, 2016
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Unspecified vulnerability in the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9.3.4 and 9.3.5 allows remote attackers to affect confidentiality and integrity via unknown vectors, a different vulnerabi...Show more
Unspecified vulnerability in the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9.3.4 and 9.3.5 allows remote attackers to affect confidentiality and integrity via unknown vectors, a different vulnerability than CVE-2016-5521.Show less
1Ibm
1Security Guardium
May 6, 2026
Oct 22, 2016
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in IBM Security Guardium 8.2 before p310, 9.x through 9.5 before p700, and 10.x through 10.1 before p100 allows remote attackers to inject arbitrary web script or HTML via a craft...Show more
Cross-site scripting (XSS) vulnerability in IBM Security Guardium 8.2 before p310, 9.x through 9.5 before p700, and 10.x through 10.1 before p100 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.Show less
1Huge It
1Catalog
May 6, 2026
Oct 21, 2016
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
SQLi and XSS in Huge IT catalog extension v1.0.4 for Joomla
1Huge It
1Slideshow
May 6, 2026
Oct 21, 2016
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
XSS & SQLi in HugeIT slideshow v1.0.4
1Huge It
1Slideshow
May 6, 2026
Oct 21, 2016
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
XSS & SQLi in HugeIT slideshow v1.0.4
1Huge It
1Portfolio Gallery Manager
May 6, 2026
Oct 21, 2016
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
Huge-IT Portfolio Gallery manager v1.1.0 SQL Injection and XSS
1Huge It
1Portfolio Gallery Manager
May 6, 2026
Oct 21, 2016
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
Huge-IT Portfolio Gallery manager v1.1.0 SQL Injection and XSS
1Ibm
1Business Process Manager
May 6, 2026
Oct 14, 2016
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-site scripting (XSS) vulnerability in Business Space in IBM Business Process Manager 7.5 through 7.5.1.2, 8.0 through 8.0.1.3, and 8.5 before 8.5.7.0 CF2016.09 allows remote authenticated users to inject arbitrary...Show more
Cross-site scripting (XSS) vulnerability in Business Space in IBM Business Process Manager 7.5 through 7.5.1.2, 8.0 through 8.0.1.3, and 8.5 before 8.5.7.0 CF2016.09 allows remote authenticated users to inject arbitrary web script or HTML via crafted content.Show less
1Wpsolr
1Wpsolr Search Engine
May 6, 2026
Oct 10, 2016
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Reflected XSS in wordpress plugin wpsolr-search-engine v7.6
1Browserweb
1Whizz
May 6, 2026
Oct 10, 2016
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Reflected XSS in wordpress plugin whizz v1.0.7
1Tidio Gallery Project
1Tidio Gallery
May 6, 2026
Oct 10, 2016
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Reflected XSS in wordpress plugin tidio-gallery v1.1
1Tidio Form Project
1Tidio Form
May 6, 2026
Oct 10, 2016
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Reflected XSS in wordpress plugin tidio-form v1.0
1Tera Charts Project
1Tera Charts
May 6, 2026
Oct 10, 2016
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Reflected XSS in wordpress plugin tera-charts v1.0