CWE-79
45,863 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (45,863)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Reflected cross-site scripting vulnerability in Apache OFBiz.
This issue affects Apache OFBiz: before 24.09.03.
Users are recommended to upgrade to version 24.09.03, which fixes the issue. |
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in DivvyDrive Information Technologies Inc. Digital Corporate Warehouse allows Stored XSS. This issue affects Dig...Show more |
The a+HRD and a+HCM developed by aEnrich has a Stored Cross-Site Scripting vulnerability, allowing authenticated remote attackers to upload files containing malicious JavaScript code, which will execute on the client sid...Show more |
The a+HRD developed by aEnrich has a Stored Cross-Site Scripting vulnerability, allowing remote attackers with administrator privileges to inject persistent JavaScript codes that are executed in users' browsers upon page...Show more |
The MembershipWorks – Membership, Events & Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 6.14 due to insufficient input sanitization...Show more |
Improper neutralization of input during web page generation ('cross-site scripting') in Dynamics 365 Field Service (online) allows an authorized attacker to perform spoofing over a network. |
Improper neutralization of input during web page generation ('cross-site scripting') in Dynamics 365 Field Service (online) allows an authorized attacker to perform spoofing over a network. |
Zohocorp ManageEngine OpManager versions 128609 and below are vulnerable to Stored XSS Vulnerability in the SNMP trap processor. |
Cross-Site Scripting (XSS) in NetScaler ADC and NetScaler Gateway when the appliance is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server |
1Fairsketch 1Rise Ultimate Project Manager Jun 17, 2026 Nov 11, 2025 5.1 MEDIUM· v4 5.4 MEDIUM· v3 N/A· v2 HTML injection vulnerability found in Fairsketch's RISE CRM Framework v3.8.1, which consist of an HTML code injection due to lack of proper validation of user inputs by sending a POST request in parameter 'first_name' in...Show more |
1Fairsketch 1Rise Ultimate Project Manager Jun 17, 2026 Nov 11, 2025 5.1 MEDIUM· v4 5.4 MEDIUM· v3 N/A· v2 HTML injection vulnerability found in Fairsketch's RISE CRM Framework v3.8.1, which consist of an HTML code injection due to lack of proper validation of user inputs by sending a POST request in parameter 'title' in '/ti...Show more |
1Fairsketch 1Rise Ultimate Project Manager Jun 17, 2026 Nov 11, 2025 5.1 MEDIUM· v4 5.4 MEDIUM· v3 N/A· v2 HTML injection vulnerability found in Fairsketch's RISE CRM Framework v3.8.1, which consist of an HTML code injection due to lack of proper validation of user inputs by sending a POST request in parameter 'custom_field_1...Show more |
1Fairsketch 1Rise Ultimate Project Manager Jun 17, 2026 Nov 11, 2025 5.1 MEDIUM· v4 5.4 MEDIUM· v3 N/A· v2 HTML injection vulnerability found in Fairsketch's RISE CRM Framework v3.8.1, which consist of an HTML code injection due to lack of proper validation of user inputs by sending a POST request in parameter 'reply_message'...Show more |
1Fairsketch 1Rise Ultimate Project Manager Jun 17, 2026 Nov 11, 2025 5.1 MEDIUM· v4 5.4 MEDIUM· v3 N/A· v2 HTML injection vulnerability found in Fairsketch's RISE CRM Framework v3.8.1, which consist of an HTML code injection due to lack of proper validation of user inputs by sending a POST request in parameter 'title' in '/ev...Show more |
1Fairsketch 1Rise Ultimate Project Manager Jun 17, 2026 Nov 11, 2025 5.1 MEDIUM· v4 5.4 MEDIUM· v3 N/A· v2 HTML injection vulnerability found in Fairsketch's RISE CRM Framework v3.8.1, which consist of an HTML code injection due to lack of proper validation of user inputs by sending a POST request in parameter 'title' in'/pro...Show more |
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Aryom Software High Technology Systems Inc. KVKNET allows Reflected XSS. This issue affects KVKNET: before 2.1...Show more |
1Zohocorp 1Manageengine Exchange Reporter Plus Jun 17, 2026 Nov 11, 2025 N/A· v4 6.1 MEDIUM· v3 N/A· v2 Zohocorp ManageEngine Exchange Reporter Plus versions 5723 and below are vulnerable to the Stored XSS Vulnerability in the Custom report. |
1Zohocorp 1Manageengine Exchange Reporter Plus Jun 17, 2026 Nov 11, 2025 N/A· v4 5.4 MEDIUM· v3 N/A· v2 Zohocorp ManageEngine Exchange Reporter Plus versions 5723 and below are vulnerable to the Stored XSS Vulnerability in the Public Folders report. |
1Zohocorp 1Manageengine Exchange Reporter Plus Jun 17, 2026 Nov 11, 2025 N/A· v4 5.4 MEDIUM· v3 N/A· v2 Zohocorp ManageEngine Exchange Reporter Plus versions 5723 and below are vulnerable to the Stored XSS Vulnerability in the Folder Message Count and Size report. |
1Zohocorp 1Manageengine Exchange Reporter Plus Jun 17, 2026 Nov 11, 2025 N/A· v4 5.4 MEDIUM· v3 N/A· v2 Zohocorp ManageEngine Exchange Reporter Plus versions 5723 and below are vulnerable to the Stored XSS Vulnerability in the Mails Deleted or Moved report. |