← Back
CWE-79

45,863 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (45,863)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Apple
6Ipados
Iphone OsSafari+3 more
Jun 17, 2026
Nov 4, 2025
N/A· v4
6.5 MEDIUM· v3
N/A· v2
This issue was addressed with improved checks. This issue is fixed in Safari 26.1, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS 26.1. Processing maliciously crafted web content may lead t...Show more
This issue was addressed with improved checks. This issue is fixed in Safari 26.1, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS 26.1. Processing maliciously crafted web content may lead to an unexpected process crash.Show less
1Apple
3Ipados
Iphone OsMacos
Jun 17, 2026
Nov 4, 2025
N/A· v4
7.1 HIGH· v3
N/A· v2
An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 26 and iPadOS 26, macOS Sonoma 14.8.2, macOS Sonoma 14.8.4, macOS Tahoe 26. Processing a maliciously crafted media fil...Show more
An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 26 and iPadOS 26, macOS Sonoma 14.8.2, macOS Sonoma 14.8.4, macOS Tahoe 26. Processing a maliciously crafted media file may lead to unexpected app termination or corrupt process memory.Show less
1Ibm
1Cloud Pak For Business Automation
Jun 17, 2026
Nov 3, 2025
N/A· v4
5.4 MEDIUM· v3
N/A· v2
IBM Cloud Pak for Business Automation 25.0.0 through 25.0.0 Interim Fix 001, 24.0.1 through 24.0.1 Interim Fix 004, 24.0.0 through 24.0.0 Interim Fix 006, and earlier unsupported releases IBM Business Automation Workflow...Show more
IBM Cloud Pak for Business Automation 25.0.0 through 25.0.0 Interim Fix 001, 24.0.1 through 24.0.1 Interim Fix 004, 24.0.0 through 24.0.0 Interim Fix 006, and earlier unsupported releases IBM Business Automation Workflow is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.Show less
1Nagios
1Nagios Xi
Jun 17, 2026
Nov 3, 2025
5.1 MEDIUM· v4
5.4 MEDIUM· v3
N/A· v2
Nagios XI versions prior to 5.8.7 using embedded Nagios Core are vulnerable to cross-site scripting (XSS) via the Core UI’s Views URL handling (escape_string()). Insufficient validation or escaping of user-supplied input...Show more
Nagios XI versions prior to 5.8.7 using embedded Nagios Core are vulnerable to cross-site scripting (XSS) via the Core UI’s Views URL handling (escape_string()). Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the context of a victim's browser.Show less
1Getgrav
1Grav
Jun 17, 2026
Nov 3, 2025
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Grav CMS1.7.49.5 is vulnerable to Cross Site Scripting (XSS).
1Opensource Socialnetwork
1Open Source Social Network
Jun 17, 2026
Nov 3, 2025
N/A· v4
7.3 HIGH· v3
N/A· v2
Open Source Social Network (OSSN) 8.6 is vulnerable to Cross Site Scripting (XSS) via the parameter param` at endpoint u/administrator/friends.
1Phpgurukul
1Maid Hiring Management System
Jun 17, 2026
Nov 3, 2025
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Phpgurukul Maid Hiring Management System 1.0 is vulnerable to Cross Site Scripting (XSS) in /maid-hiring.php va the name field.
1Sailpoint
1Identityiq
Jun 17, 2026
Nov 3, 2025
N/A· v4
6.1 MEDIUM· v3
N/A· v2
IdentityIQ 8.5, IdentityIQ 8.4 and all 8.4 patch levels prior to 8.4p4, IdentityIQ 8.3 and all 8.3 patch levels including 8.3p5, and all prior versions allows some IdentityIQ web services that provide non-HTML content to...Show more
IdentityIQ 8.5, IdentityIQ 8.4 and all 8.4 patch levels prior to 8.4p4, IdentityIQ 8.3 and all 8.3 patch levels including 8.3p5, and all prior versions allows some IdentityIQ web services that provide non-HTML content to be accessed via a URL path that will set the Content-Type to HTML allowing a requesting browser to interpret content not properly escaped to prevent Cross-Site Scripting (XSS).Show less
1Car Booking System Php Project
1Car Booking System Php
Jun 17, 2026
Nov 3, 2025
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Car-Booking-System-PHP v.1.0 is vulnerable to Cross Site Scripting (XSS) in /carlux/booking.php.
1Water Management System Project
1Water Management System
Jun 17, 2026
Nov 3, 2025
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Water Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in /orders.php.
1Water Management System Project
1Water Management System
Jun 17, 2026
Nov 3, 2025
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Water Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in /edit_product.php?id=1.
1Water Management System Project
1Water Management System
Jun 17, 2026
Nov 3, 2025
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Water Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in /add_customer.php.
1Water Management System Project
1Water Management System
Jun 17, 2026
Nov 3, 2025
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Water Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in /add_vendor.php.
1Ultimatefosters
1Ultimatepos
Jun 17, 2026
Nov 3, 2025
N/A· v4
8.7 HIGH· v3
N/A· v2
A cross-site scripting (XSS) vulnerability exists in the administrative interface of ultimatefosters UltimatePOS 4.8 where input submitted in the purchase functionality is reflected without proper escaping in the admin l...Show more
A cross-site scripting (XSS) vulnerability exists in the administrative interface of ultimatefosters UltimatePOS 4.8 where input submitted in the purchase functionality is reflected without proper escaping in the admin log panel page in the 'reference No.' field. This flaw allows an authenticated attacker to execute arbitrary JavaScript in the context of an administrator's browser session, which could lead to session hijacking or other malicious actions.Show less
1School Management System Php Project
1School Management System Php
Jun 17, 2026
Nov 3, 2025
N/A· v4
5.4 MEDIUM· v3
N/A· v2
School Management System PHP v1.0 is vulnerable to Cross Site Scripting (XSS) in /login.php via the password parameter.
1Nababur
1Simple User Management System
Jun 17, 2026
Nov 3, 2025
N/A· v4
4.6 MEDIUM· v3
N/A· v2
Simple User Management System with PHP-MySQL v1.0 is vulnerable to Cross-Site Scripting (XSS) via the Profile Section. The system fails to properly sanitize user input, allowing attackers to inject and execute arbitrary...Show more
Simple User Management System with PHP-MySQL v1.0 is vulnerable to Cross-Site Scripting (XSS) via the Profile Section. The system fails to properly sanitize user input, allowing attackers to inject and execute arbitrary JavaScript when the input is displayed in the browserShow less
-
-
Jun 17, 2026
Nov 1, 2025
N/A· v4
6.4 MEDIUM· v3
N/A· v2
The kallyas theme for WordPress is vulnerable to Stored Cross-Site Scripting via several of the plugin's shortcodes in all versions up to, and including, 4.23.0 due to insufficient input sanitization and output escaping...Show more
The kallyas theme for WordPress is vulnerable to Stored Cross-Site Scripting via several of the plugin's shortcodes in all versions up to, and including, 4.23.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.Show less
-
-
Jun 17, 2026
Nov 1, 2025
N/A· v4
6.4 MEDIUM· v3
N/A· v2
The Employee Spotlight – Team Member Showcase & Meet the Team Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Social URLs in all versions up to, and including, 5.1.2 due to insufficient input...Show more
The Employee Spotlight – Team Member Showcase & Meet the Team Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Social URLs in all versions up to, and including, 5.1.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.Show less
-
-
Jun 17, 2026
Nov 1, 2025
N/A· v4
6.4 MEDIUM· v3
N/A· v2
The Schema & Structured Data for WP & AMP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'saswp_tiny_multiple_faq' shortcode in all versions up to, and including, 1.51 due to insuffici...Show more
The Schema & Structured Data for WP & AMP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'saswp_tiny_multiple_faq' shortcode in all versions up to, and including, 1.51 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.Show less
-
-
Jun 17, 2026
Nov 1, 2025
N/A· v4
6.4 MEDIUM· v3
N/A· v2
The Schema Scalpel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the post title in all versions up to, and including, 1.6.1 due to insufficient input sanitization and output escaping when outputti...Show more
The Schema Scalpel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the post title in all versions up to, and including, 1.6.1 due to insufficient input sanitization and output escaping when outputting user-supplied data into JSON-LD schema markup. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.Show less