CWE-79
45,887 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (45,887)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Cisco 1Email Security Appliance May 6, 2026 Oct 28, 2016 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 A vulnerability in the display of email messages in the Messages in Quarantine (MIQ) view in Cisco AsyncOS for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to cause a user to click...Show more |
XSS and SQLi in Huge IT Joomla Slider v1.0.9 extension |
1Novell 2Identity Manager Identity Manager Identity ApplicationsMay 6, 2026 Oct 27, 2016 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 XSS in NetIQ IDM 4.5 Identity Applications before 4.5.4 allows attackers able to change their username to inject arbitrary HTML code into the Role Assignment administrator HTML pages. |
XSS in NetIQ Designer for Identity Manager before 4.5.3 allows remote attackers to inject arbitrary HTML code via the nrfEntitlementReport.do CGI. |
XSS in NetIQ Designer for Identity Manager before 4.5.3 allows remote attackers to inject arbitrary HTML code via the accessMgrDN value of the forgotUser.do CGI. |
XSS in Yandex Browser Translator in Yandex browser for desktop for versions from 15.12 to 16.2 could be used by remote attacker for evaluation arbitrary javascript code. |
XSS in Yandex Browser BookReader in Yandex browser for desktop for versions before 16.6. could be used by remote attacker for evaluation arbitrary javascript code. |
1Oracle 1Agile Product Lifecycle Management May 6, 2026 Oct 25, 2016 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Unspecified vulnerability in the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9.3.4 and 9.3.5 allows remote attackers to affect confidentiality and integrity via unknown vectors, a different vulnerabi...Show more |
Cross-site scripting (XSS) vulnerability in IBM Security Guardium 8.2 before p310, 9.x through 9.5 before p700, and 10.x through 10.1 before p100 allows remote attackers to inject arbitrary web script or HTML via a craft...Show more |
SQLi and XSS in Huge IT catalog extension v1.0.4 for Joomla |
XSS & SQLi in HugeIT slideshow v1.0.4 |
XSS & SQLi in HugeIT slideshow v1.0.4 |
1Huge It 1Portfolio Gallery Manager May 6, 2026 Oct 21, 2016 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 Huge-IT Portfolio Gallery manager v1.1.0 SQL Injection and XSS |
1Huge It 1Portfolio Gallery Manager May 6, 2026 Oct 21, 2016 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 Huge-IT Portfolio Gallery manager v1.1.0 SQL Injection and XSS |
Cross-site scripting (XSS) vulnerability in Business Space in IBM Business Process Manager 7.5 through 7.5.1.2, 8.0 through 8.0.1.3, and 8.5 before 8.5.7.0 CF2016.09 allows remote authenticated users to inject arbitrary...Show more |
1Wpsolr 1Wpsolr Search Engine May 6, 2026 Oct 10, 2016 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Reflected XSS in wordpress plugin wpsolr-search-engine v7.6 |
Reflected XSS in wordpress plugin whizz v1.0.7 |
1Tidio Gallery Project 1Tidio Gallery May 6, 2026 Oct 10, 2016 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Reflected XSS in wordpress plugin tidio-gallery v1.1 |
1Tidio Form Project 1Tidio Form May 6, 2026 Oct 10, 2016 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Reflected XSS in wordpress plugin tidio-form v1.0 |
1Tera Charts Project 1Tera Charts May 6, 2026 Oct 10, 2016 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Reflected XSS in wordpress plugin tera-charts v1.0 |