← Back
CWE-79

46,267 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (46,267)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Minicoursegenerator
1Mini Course Generator
Jun 17, 2026
Feb 21, 2025
N/A· v4
5.4 MEDIUM· v3
N/A· v2
The Mini Course Generator | Embed mini-courses and interactive content plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'mcg' shortcode in all versions up to, and including, 1.0.5 due to...Show more
The Mini Course Generator | Embed mini-courses and interactive content plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'mcg' shortcode in all versions up to, and including, 1.0.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.Show less
1Tcoderbd
1Tcbd Tooltip
Jun 17, 2026
Feb 21, 2025
N/A· v4
5.4 MEDIUM· v3
N/A· v2
The TCBD Tooltip plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'tcbdtooltip_text' shortcode in all versions up to, and including, 1.0 due to insufficient input sanitization and output...Show more
The TCBD Tooltip plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'tcbdtooltip_text' shortcode in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.Show less
1Covertnine
1C9 Admin Dashboard
Jun 17, 2026
Feb 21, 2025
N/A· v4
5.4 MEDIUM· v3
N/A· v2
The C9 Admin Dashboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.3.5 due to insufficient input sanitization and output escaping. This m...Show more
The C9 Admin Dashboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.3.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.Show less
1Oxyno Zeta
1S3 Proxy
Jun 17, 2026
Feb 20, 2025
8.4 HIGH· v4
8.2 HIGH· v3
N/A· v2
oxyno-zeta/s3-proxy is an aws s3 proxy written in go. In affected versions a Reflected Cross-site Scripting (XSS) vulnerability enables attackers to create malicious URLs that, when visited, inject scripts into the web a...Show more
oxyno-zeta/s3-proxy is an aws s3 proxy written in go. In affected versions a Reflected Cross-site Scripting (XSS) vulnerability enables attackers to create malicious URLs that, when visited, inject scripts into the web application. This can lead to session hijacking or phishing attacks on a trusted domain, posing a moderate risk to all users. It's possible to inject html elements, including scripts through the folder-list template. The affected template allows users to interact with the URL path provided by the `Request.URL.Path` variable, which is then rendered directly into the HTML without proper sanitization or escaping. This can be abused by attackers who craft a malicious URL containing injected HTML or JavaScript. When users visit such a URL, the malicious script will be executed in the user's context. This issue has been addressed in version 4.18.1 and all users are advised to upgrade. There are no known workarounds for this vulnerability.Show less
1Xunruicms
1Xunruicms
Jun 17, 2026
Feb 20, 2025
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Cross Site Scripting vulnerabilities in Xunruicms v.4.6.3 and before allows a remote attacker to escalate privileges via a crafted script.
1Phpcms
1Phpcms
Jun 17, 2026
Feb 20, 2025
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Cross Site Scripting vulnerability in phpcmsv9 v.9.6.3 allows a remote attacker to escalate privileges via the menu interface of the member center of the background administrator.
1Phpcms
1Phpcms
Jun 17, 2026
Feb 20, 2025
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Cross Site Scripting vulnerabilities in phpcmsv9 v.9.6.3 allows a remote attacker to escalate privileges via a crafted script.
-
-
Jun 17, 2026
Feb 20, 2025
2.3 LOW· v4
N/A· v3
N/A· v2
CKEditor 5 is a modern JavaScript rich-text editor with an MVC architecture. During a recent internal audit, a Cross-Site Scripting (XSS) vulnerability was discovered in the CKEditor 5 real-time collaboration package. Th...Show more
CKEditor 5 is a modern JavaScript rich-text editor with an MVC architecture. During a recent internal audit, a Cross-Site Scripting (XSS) vulnerability was discovered in the CKEditor 5 real-time collaboration package. This vulnerability affects user markers, which represent users' positions within the document. It can lead to unauthorized JavaScript code execution, which might happen with a very specific editor and token endpoint configuration. This vulnerability affects only installations with Real-time collaborative editing enabled. The problem has been recognized and patched. The fix is available in version 44.2.1 (and above). Users are advised to upgrade. There are no known workarounds for this vulnerability.Show less
1Phpjabbers
1Meeting Room Booking System
Jun 17, 2026
Feb 20, 2025
N/A· v4
5.4 MEDIUM· v3
N/A· v2
PHPJabbers Meeting Room Booking System v1.0 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) in the "title, name" parameters of index.php page.
1Phpjabbers
1Event Ticketing System
Jun 17, 2026
Feb 20, 2025
N/A· v4
5.4 MEDIUM· v3
N/A· v2
PHPJabbers Event Ticketing System v1.0 is vulnerable to Reflected Cross-Site Scripting (XSS) in "lid" parameter in index.
1Yandaozi
1Ppress
Jun 17, 2026
Feb 20, 2025
N/A· v4
6.5 MEDIUM· v3
N/A· v2
A stored Cross Site Scripting vulnerability in the "related recommendations" feature in Ppress v.0.0.9 allows a remote attacker to execute arbitrary code via a crafted script to the article.title, article.category, and a...Show more
A stored Cross Site Scripting vulnerability in the "related recommendations" feature in Ppress v.0.0.9 allows a remote attacker to execute arbitrary code via a crafted script to the article.title, article.category, and article.tags parameters.Show less
1Nagios
1Nagios Xi
Jun 17, 2026
Feb 20, 2025
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Nagios XI 2024R1.2.2 is vulnerable to a Cross-Site Request Forgery (CSRF) attack through the Favorites component, enabling POST-based Cross-Site Scripting (XSS).
1Nagios
1Nagios Xi
Jun 17, 2026
Feb 20, 2025
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Nagios XI 2024R1.2.2 is susceptible to a stored Cross-Site Scripting (XSS) vulnerability in the Tools page. This flaw allows an attacker to inject malicious scripts into the Tools interface, which are then stored and exe...Show more
Nagios XI 2024R1.2.2 is susceptible to a stored Cross-Site Scripting (XSS) vulnerability in the Tools page. This flaw allows an attacker to inject malicious scripts into the Tools interface, which are then stored and executed in the context of other users accessing the page.Show less
1Phpjabbers
1Cinema Booking System
Jun 17, 2026
Feb 20, 2025
N/A· v4
6.5 MEDIUM· v3
N/A· v2
PHPJabbers Cinema Booking System v1.0 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) in the "title, name" parameters.
1Phpjabbers
1Cinema Booking System
Jun 17, 2026
Feb 20, 2025
N/A· v4
5.4 MEDIUM· v3
N/A· v2
PHPJabbers Cinema Booking System v1.0 is vulnerable to Reflected Cross-Site Scripting (XSS) in Now Showing menu "date" parameter.
1Phpjabbers
1Shared Asset Booking System
Jun 17, 2026
Feb 20, 2025
N/A· v4
5.4 MEDIUM· v3
N/A· v2
PHPJabbers Shared Asset Booking System v1.0 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) in the "title, name" parameters.
1Phpjabbers
1Bus Reservation System
Jun 17, 2026
Feb 20, 2025
N/A· v4
5.4 MEDIUM· v3
N/A· v2
PHPJabbers Bus Reservation System v1.1 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) in the "title, name" parameters.
1Phpjabbers
1Restaurant Booking System
Jun 17, 2026
Feb 20, 2025
N/A· v4
5.4 MEDIUM· v3
N/A· v2
PHPJabbers Restaurant Booking System v3.0 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) in the "seat_name, plugin_sms_api_key, plugin_sms_country_code, title, name" parameters.
1Phpjabbers
1Restaurant Booking System
Jun 17, 2026
Feb 20, 2025
N/A· v4
5.4 MEDIUM· v3
N/A· v2
PHPJabbers Restaurant Booking System v3.0 is vulnerable to Reflected Cross-Site Scripting (XSS) in Reservations menu, Schedule section date parameter.
1Phpjabbers
1Event Ticketing System
Jun 17, 2026
Feb 20, 2025
N/A· v4
5.4 MEDIUM· v3
N/A· v2
PHPJabbers Event Ticketing System v1.0 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) in the "name, title" parameters.