CWE-79

High likelihood

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Parent: CWE-74 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

45,502 vulnerabilities with CWE-79
CVE-2024-41240 MEDIUM
Kashipara Responsive School Management System v3.2.0 - Reflected Cross-Site Scripting via Teacher Login Error Parameter
CVSS 6.1
CVE-2024-20479 MEDIUM
Cisco Identity Services Engine - Authenticated Stored Cross-Site Scripting in Web Management Interface
CVSS 4.8
CVE-2024-20443 MEDIUM
Cisco Identity Services Engine - Authenticated Stored Cross-Site Scripting
CVSS 5.4
CVE-2024-7355 MEDIUM
Organization chart < 1.5.1 - Authenticated Stored Cross-Site Scripting via Title Input and Node Description Parameters
CVSS 4.9
CVE-2024-7353 MEDIUM
Accept Stripe Payments <2.0.86 - XSS
CVSS 5.4
CVE-2024-6494 MEDIUM
WordPress File Upload <4.24.8 - XSS
CVSS 6.1
CVE-2024-3973 MEDIUM
House Manager < 1.0.8.4 - Reflected Cross-Site Scripting via Unsanitized Parameter
CVSS 4.8
CVE-2024-38166 HIGH
Microsoft Dynamics 365 - Unauthenticated Cross-Site Scripting
CVSS 8.2
CVE-2024-28740 CRITICAL
Koha < 23.05.00 - Remote Code Execution via additonal-contents.pl
CVSS 9.6
CVE-2024-28739 HIGH
Koha < 23.05.00 - Remote Code Execution via Format Parameter
CVSS 7.2
CVE-2024-41677 MEDIUM
Qwik < 1.6.0 - Mutation Cross-Site Scripting via Server-Side Rendering
CVSS 6.3
CVE-2024-43113 MEDIUM
Firefox for iOS < 129 - Cross-Site Scripting via Link Contextual Menu
CVSS 6.1
CVE-2024-43112 MEDIUM
Firefox for iOS < 129 - Cross-Site Scripting via Download Link Long Press
CVSS 6.1
CVE-2024-43111 MEDIUM
Firefox for iOS < 129 - Cross-Site Scripting via Download Link Long Press
CVSS 6.1
CVE-2024-41333 MEDIUM
Phpgurukul Tourism Management System 2.0 - Reflected Cross-Site Scripting via uname Parameter
CVSS 6.1
CVE-2024-41911 MEDIUM
Poly Clariti Manager < 10.12.0.2_100 - Cross-Site Scripting
CVSS 5.4
CVE-2024-41910 MEDIUM
Poly Clariti Manager < 10.12.0.2_100 - Cross-Site Scripting in JavaScript
CVSS 6.1
CVE-2024-40101 MEDIUM
microweber < 2.0.16 - Unauthenticated Reflected Cross-Site Scripting via Search Keywords Parameter
CVSS 6.1
CVE-2024-7524 MEDIUM
Firefox < 129 and Firefox ESR < 115.14 - Cross-Site Scripting via DOM Clobbering Bypass
CVSS 6.1
CVE-2024-33994 HIGH
School Event Management System <1.0 - XSS
CVSS 7.1
CVE-2024-33993 HIGH
School Event Management System <1.0 - XSS
CVSS 7.1
CVE-2024-33992 HIGH
School Event Management System <1.0 - XSS
CVSS 7.1
CVE-2024-33991 HIGH
School Event Management System <1.0 - XSS
CVSS 7.1
CVE-2024-33990 HIGH
School Event Management System <1.0 - XSS
CVSS 7.1
CVE-2024-33989 HIGH
School Event Management System <1.0 - XSS
CVSS 7.1
Details
Vulnerabilities 45,502
Exploit Likelihood High