← Back
CWE-79

46,516 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (46,516)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ordat
1Ordat.erp
Jul 5, 2026
Sep 12, 2024
N/A· v4
6.1 MEDIUM· v3
N/A· v2
ORDAT FOSS-Online before version 2.24.01 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the login page.
1Docker
1Desktop
Jun 17, 2026
Sep 12, 2024
8.9 HIGH· v4
9.8 CRITICAL· v3
N/A· v2
A remote code execution (RCE) vulnerability via crafted extension publisher-url/additional-urls could be abused by a malicious extension in Docker Desktop before 4.34.2.
1Docker
1Desktop
Jun 17, 2026
Sep 12, 2024
9.0 CRITICAL· v4
9.8 CRITICAL· v3
N/A· v2
A remote code execution (RCE) vulnerability via crafted extension description/changelog could be abused by a malicious extension in Docker Desktop before 4.34.2.
1Kasdanet
1Kw5515 Firmware
Jun 17, 2026
Sep 12, 2024
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Cross Site Scripting (XSS) Vulnerability in Firewall menu in Control Panel in KASDA KW5515 version 4.3.1.0, allows attackers to execute arbitrary code and steal cookies via a crafted script
1Pega
1Infinity
Jun 17, 2026
Sep 12, 2024
N/A· v4
4.8 MEDIUM· v3
N/A· v2
Pega Platform versions 8.1 to Infinity 24.1.2 are affected by an HTML Injection issue with Stage.
1Pega
1Infinity
Jun 17, 2026
Sep 12, 2024
N/A· v4
4.8 MEDIUM· v3
N/A· v2
Pega Platform versions 8.1 to Infinity 24.1.2 are affected by an XSS issue with case type.
1Pega
1Infinity
Jun 17, 2026
Sep 12, 2024
N/A· v4
4.8 MEDIUM· v3
N/A· v2
Pega Platform versions 8.1 to Infinity 24.1.2 are affected by an XSS issue with App name.
1Mindsdb
1Mindsdb
Jun 17, 2026
Sep 12, 2024
N/A· v4
5.4 MEDIUM· v3
N/A· v2
A cross-site scripting (XSS) vulnerability exists in all versions of the MindsDB platform, enabling the execution of a JavaScript payload whenever a user enumerates an ML Engine, database, project, or dataset containing...Show more
A cross-site scripting (XSS) vulnerability exists in all versions of the MindsDB platform, enabling the execution of a JavaScript payload whenever a user enumerates an ML Engine, database, project, or dataset containing arbitrary JavaScript code within the web UI.Show less
1Microfocus
1Edirectory
Jun 17, 2026
Sep 12, 2024
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Possible Cross-Site Scripting (XSS) Vulnerability in eDirectory has been discovered in OpenText™ eDirectory 9.2.5.0000.
1Microfocus
1Edirectory
Jun 17, 2026
Sep 12, 2024
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Possible Improper Neutralization of Input During Web Page Generation Vulnerability in eDirectory has been discovered in OpenText™ eDirectory 9.2.3.0000.
1I Doit
1I Doit
Jun 17, 2026
Sep 12, 2024
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Cross-site Scripting (XSS) vulnerability in idoit pro version 28. This vulnerability allows an attacker to retrieve session details of an authenticated user due to lack of proper sanitization of the following parameters...Show more
Cross-site Scripting (XSS) vulnerability in idoit pro version 28. This vulnerability allows an attacker to retrieve session details of an authenticated user due to lack of proper sanitization of the following parameters (id,lang,mNavID,name,pID,treeNode,type,view).Show less
1Amcharts
1Amcharts\
Jun 17, 2026
Sep 12, 2024
N/A· v4
6.1 MEDIUM· v3
N/A· v2
The amCharts: Charts and Maps plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'amcharts_javascript' parameter in all versions up to, and including, 1.4.4 due to the ability to supply arbitrar...Show more
The amCharts: Charts and Maps plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'amcharts_javascript' parameter in all versions up to, and including, 1.4.4 due to the ability to supply arbitrary JavaScript a lack of nonce validation on the preview functionality. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.Show less
1Tebilisim
1V5
Jun 17, 2026
Sep 12, 2024
8.8 HIGH· v4
6.1 MEDIUM· v3
N/A· v2
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in TE Informatics V5 allows Reflected XSS. This issue affects V5: before 6.2.
1Mm Breaking News Project
1Mm Breaking News
Jun 17, 2026
Sep 12, 2024
N/A· v4
6.1 MEDIUM· v3
N/A· v2
The MM-Breaking News WordPress plugin through 0.7.9 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsers
1Mm Breaking News Project
1Mm Breaking News
Jun 17, 2026
Sep 12, 2024
N/A· v4
6.1 MEDIUM· v3
N/A· v2
The MM-Breaking News WordPress plugin through 0.7.9 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads vi...Show more
The MM-Breaking News WordPress plugin through 0.7.9 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.Show less
1Michalaugustyniak
1Misiek Paypal
Jun 17, 2026
Sep 12, 2024
N/A· v4
6.1 MEDIUM· v3
N/A· v2
The Misiek Paypal WordPress plugin through 1.1.20090324 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payload...Show more
The Misiek Paypal WordPress plugin through 1.1.20090324 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.Show less
1Outtolunchproductions
1Simple Headline Rotator
Jun 17, 2026
Sep 12, 2024
N/A· v4
6.1 MEDIUM· v3
N/A· v2
The Simple Headline Rotator WordPress plugin through 1.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloa...Show more
The Simple Headline Rotator WordPress plugin through 1.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.Show less
1Gwycon
1Quick Code
Jun 17, 2026
Sep 12, 2024
N/A· v4
6.1 MEDIUM· v3
N/A· v2
The Quick Code WordPress plugin through 1.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF...Show more
The Quick Code WordPress plugin through 1.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.Show less
1Michalaugustyniak
1Misiek Photo Album
Jun 17, 2026
Sep 12, 2024
N/A· v4
6.1 MEDIUM· v3
N/A· v2
The Misiek Photo Album WordPress plugin through 1.4.3 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads...Show more
The Misiek Photo Album WordPress plugin through 1.4.3 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.Show less
1Adeelraza
1Gixaw Chat
Jun 17, 2026
Sep 12, 2024
N/A· v4
6.1 MEDIUM· v3
N/A· v2
The Gixaw Chat WordPress plugin through 1.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF...Show more
The Gixaw Chat WordPress plugin through 1.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.Show less