← Back
CWE-79

45,863 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (45,863)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Apache
1Ofbiz
Jun 17, 2026
Nov 12, 2025
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Reflected cross-site scripting vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.03. Users are recommended to upgrade to version 24.09.03, which fixes the issue.
-
-
Jun 17, 2026
Nov 12, 2025
N/A· v4
7.3 HIGH· v3
N/A· v2
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in DivvyDrive Information Technologies Inc. Digital Corporate Warehouse allows Stored XSS. This issue affects Dig...Show more
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in DivvyDrive Information Technologies Inc. Digital Corporate Warehouse allows Stored XSS. This issue affects Digital Corporate Warehouse: before v.4.8.2.22.Show less
-
-
Jun 17, 2026
Nov 12, 2025
5.1 MEDIUM· v4
5.4 MEDIUM· v3
N/A· v2
The a+HRD and a+HCM developed by aEnrich has a Stored Cross-Site Scripting vulnerability, allowing authenticated remote attackers to upload files containing malicious JavaScript code, which will execute on the client sid...Show more
The a+HRD and a+HCM developed by aEnrich has a Stored Cross-Site Scripting vulnerability, allowing authenticated remote attackers to upload files containing malicious JavaScript code, which will execute on the client side when a user is tricked into visiting a specific URL.Show less
1Aenrich
1A+hrd
Jun 17, 2026
Nov 12, 2025
4.8 MEDIUM· v4
4.8 MEDIUM· v3
N/A· v2
The a+HRD developed by aEnrich has a Stored Cross-Site Scripting vulnerability, allowing remote attackers with administrator privileges to inject persistent JavaScript codes that are executed in users' browsers upon page...Show more
The a+HRD developed by aEnrich has a Stored Cross-Site Scripting vulnerability, allowing remote attackers with administrator privileges to inject persistent JavaScript codes that are executed in users' browsers upon page load.Show less
-
-
Jun 17, 2026
Nov 12, 2025
N/A· v4
4.4 MEDIUM· v3
N/A· v2
The MembershipWorks – Membership, Events & Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 6.14 due to insufficient input sanitization...Show more
The MembershipWorks – Membership, Events & Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 6.14 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.Show less
1Microsoft
1Dynamics 365
Jun 17, 2026
Nov 11, 2025
N/A· v4
8.7 HIGH· v3
N/A· v2
Improper neutralization of input during web page generation ('cross-site scripting') in Dynamics 365 Field Service (online) allows an authorized attacker to perform spoofing over a network.
1Microsoft
1Dynamics 365
Jun 17, 2026
Nov 11, 2025
N/A· v4
8.7 HIGH· v3
N/A· v2
Improper neutralization of input during web page generation ('cross-site scripting') in Dynamics 365 Field Service (online) allows an authorized attacker to perform spoofing over a network.
-
-
Jun 17, 2026
Nov 11, 2025
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Zohocorp ManageEngine OpManager versions 128609 and below are vulnerable to Stored XSS Vulnerability in the SNMP trap processor.
-
-
Jun 17, 2026
Nov 11, 2025
5.9 MEDIUM· v4
N/A· v3
N/A· v2
Cross-Site Scripting (XSS) in NetScaler ADC and NetScaler Gateway when the appliance is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server
1Fairsketch
1Rise Ultimate Project Manager
Jun 17, 2026
Nov 11, 2025
5.1 MEDIUM· v4
5.4 MEDIUM· v3
N/A· v2
HTML injection vulnerability found in Fairsketch's RISE CRM Framework v3.8.1, which consist of an HTML code injection due to lack of proper validation of user inputs by sending a POST request in parameter 'first_name' in...Show more
HTML injection vulnerability found in Fairsketch's RISE CRM Framework v3.8.1, which consist of an HTML code injection due to lack of proper validation of user inputs by sending a POST request in parameter 'first_name' in '/clients/save_contact/'.Show less
1Fairsketch
1Rise Ultimate Project Manager
Jun 17, 2026
Nov 11, 2025
5.1 MEDIUM· v4
5.4 MEDIUM· v3
N/A· v2
HTML injection vulnerability found in Fairsketch's RISE CRM Framework v3.8.1, which consist of an HTML code injection due to lack of proper validation of user inputs by sending a POST request in parameter 'title' in '/ti...Show more
HTML injection vulnerability found in Fairsketch's RISE CRM Framework v3.8.1, which consist of an HTML code injection due to lack of proper validation of user inputs by sending a POST request in parameter 'title' in '/tickets/save'.Show less
1Fairsketch
1Rise Ultimate Project Manager
Jun 17, 2026
Nov 11, 2025
5.1 MEDIUM· v4
5.4 MEDIUM· v3
N/A· v2
HTML injection vulnerability found in Fairsketch's RISE CRM Framework v3.8.1, which consist of an HTML code injection due to lack of proper validation of user inputs by sending a POST request in parameter 'custom_field_1...Show more
HTML injection vulnerability found in Fairsketch's RISE CRM Framework v3.8.1, which consist of an HTML code injection due to lack of proper validation of user inputs by sending a POST request in parameter 'custom_field_1' in '/estimate_requests/save_estimate_request'.Show less
1Fairsketch
1Rise Ultimate Project Manager
Jun 17, 2026
Nov 11, 2025
5.1 MEDIUM· v4
5.4 MEDIUM· v3
N/A· v2
HTML injection vulnerability found in Fairsketch's RISE CRM Framework v3.8.1, which consist of an HTML code injection due to lack of proper validation of user inputs by sending a POST request in parameter 'reply_message'...Show more
HTML injection vulnerability found in Fairsketch's RISE CRM Framework v3.8.1, which consist of an HTML code injection due to lack of proper validation of user inputs by sending a POST request in parameter 'reply_message' in '/messages/reply'.Show less
1Fairsketch
1Rise Ultimate Project Manager
Jun 17, 2026
Nov 11, 2025
5.1 MEDIUM· v4
5.4 MEDIUM· v3
N/A· v2
HTML injection vulnerability found in Fairsketch's RISE CRM Framework v3.8.1, which consist of an HTML code injection due to lack of proper validation of user inputs by sending a POST request in parameter 'title' in '/ev...Show more
HTML injection vulnerability found in Fairsketch's RISE CRM Framework v3.8.1, which consist of an HTML code injection due to lack of proper validation of user inputs by sending a POST request in parameter 'title' in '/events/save'.Show less
1Fairsketch
1Rise Ultimate Project Manager
Jun 17, 2026
Nov 11, 2025
5.1 MEDIUM· v4
5.4 MEDIUM· v3
N/A· v2
HTML injection vulnerability found in Fairsketch's RISE CRM Framework v3.8.1, which consist of an HTML code injection due to lack of proper validation of user inputs by sending a POST request in parameter 'title' in'/pro...Show more
HTML injection vulnerability found in Fairsketch's RISE CRM Framework v3.8.1, which consist of an HTML code injection due to lack of proper validation of user inputs by sending a POST request in parameter 'title' in'/projects/save'.Show less
-
-
Jun 17, 2026
Nov 11, 2025
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Aryom Software High Technology Systems Inc. KVKNET allows Reflected XSS. This issue affects KVKNET: before 2.1...Show more
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Aryom Software High Technology Systems Inc. KVKNET allows Reflected XSS. This issue affects KVKNET: before 2.1.8.Show less
1Zohocorp
1Manageengine Exchange Reporter Plus
Jun 17, 2026
Nov 11, 2025
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Zohocorp ManageEngine Exchange Reporter Plus versions 5723 and below are vulnerable to the Stored XSS Vulnerability in the Custom report.
1Zohocorp
1Manageengine Exchange Reporter Plus
Jun 17, 2026
Nov 11, 2025
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Zohocorp ManageEngine Exchange Reporter Plus versions 5723 and below are vulnerable to the Stored XSS Vulnerability in the Public Folders report.
1Zohocorp
1Manageengine Exchange Reporter Plus
Jun 17, 2026
Nov 11, 2025
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Zohocorp ManageEngine Exchange Reporter Plus versions 5723 and below are vulnerable to the Stored XSS Vulnerability in the Folder Message Count and Size report.
1Zohocorp
1Manageengine Exchange Reporter Plus
Jun 17, 2026
Nov 11, 2025
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Zohocorp ManageEngine Exchange Reporter Plus versions 5723 and below are vulnerable to the Stored XSS Vulnerability in the Mails Deleted or Moved report.