CWE-79
46,566 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (46,566)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
TpMeCMS 1.3.3.2 is vulnerable to Cross Site Scripting (XSS) in /h.php/page?ref=addtabs via the "Title," "Images," and "Content" fields. |
Seacms v13 is vulnerable to Cross Site Scripting (XSS) via admin-video.php. |
ShopXO 6.2 is vulnerable to Cross Site Scripting (XSS) in the backend that allows attackers to execute code by changing POST parameters. |
svelte performance oriented web framework. A potential mXSS vulnerability exists in Svelte for versions up to but not including 4.2.19. Svelte improperly escapes HTML on server-side rendering. The assumption is that attr...Show more |
A cross-site scripting (XSS) vulnerability in the component admin_datarelate.php of SeaCMS v12.9 allows attackers to execute arbitrary web scripts or HTML via a crafted payload. |
1Remyandrade 1Contact Manager With Export To Vcf Jun 17, 2026 Aug 30, 2024 5.3 MEDIUM· v4 5.4 MEDIUM· v3 4.0 MEDIUM· v2 A vulnerability, which was classified as problematic, has been found in SourceCodester Contact Manager with Export to VCF 1.0. Affected by this issue is some unknown functionality of the file index.html. The manipulation...Show more |
1Wpbookingcalendar 1Wp Booking Calendar Jun 17, 2026 Aug 30, 2024 N/A· v4 6.1 MEDIUM· v3 N/A· v2 The WP Booking Calendar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via several parameters from 'timeline_obj' in all versions up to, and including, 10.5 due to insufficient input sanitization an...Show more |
1Webtechstreet 1Elementor Addon Elements Jun 17, 2026 Aug 30, 2024 N/A· v4 5.4 MEDIUM· v3 N/A· v2 The Elementor Addon Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widgets in all versions up to, and including, 1.13.6 due to insufficient input sanitization and output escaping...Show more |
1Elecom 2Wab I1750 Ps Firmware Wab S1167 Ps FirmwareJun 17, 2026 Aug 30, 2024 N/A· v4 6.1 MEDIUM· v3 N/A· v2 Cross-site scripting vulnerability exists in ELECOM wireless access points due to improper processing of input values in menu.cgi. If a user views a malicious web page while logged in to the product, an arbitrary script...Show more |
1Elecom 3Wrc X3000gs2 B Firmware Wrc X3000gs2 W FirmwareWrc X3000gs2a B FirmwareJun 17, 2026 Aug 30, 2024 N/A· v4 6.1 MEDIUM· v3 N/A· v2 Cross-site scripting vulnerability exists in WRC-X3000GS2-B, WRC-X3000GS2-W, WRC-X3000GS2A-B and WRC-X3000GST2-B due to improper processing of input values in easysetup.cgi. If a user views a malicious web page while log...Show more |
The HubSpot – CRM, Email Marketing, Live Chat, Forms & Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'url' attribute of the HubSpot Meeting Widget in all versions up to, and includin...Show more |
The Betheme theme for WordPress is vulnerable to Stored Cross-Site Scripting via several of the plugin's shortcodes in all versions up to, and including, 27.5.6 due to insufficient input sanitization and output escaping...Show more |
The Enfold - Responsive Multi-Purpose Theme theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘wrapper_class’ and 'class' parameters in all versions up to, and including, 6.0.3 due to insufficient...Show more |
The Memberpress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'mepr_screenname' and 'mepr_key' parameter in all versions up to, and including, 1.11.29 due to insufficient input sanitization...Show more |
1Webtechstreet 1Elementor Addon Elements Jun 17, 2026 Aug 30, 2024 N/A· v4 5.4 MEDIUM· v3 N/A· v2 The Elementor Addon Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ and 'eae_slider_animation' parameters in all versions up to, and including, 1.13.5 due to insufficient input san...Show more |
1Easy Test Online Learning And Testing Platform Project 1Easy Test Online Learning And Testing Platform Jun 17, 2026 Aug 30, 2024 N/A· v4 5.4 MEDIUM· v3 N/A· v2 Easy test Online Learning and Testing Platform from HWA JIUH DIGITAL TECHNOLOGY does not properly validate a specific page parameter, allowing remote attackers with regular privilege to inject arbitrary JavaScript code a...Show more |
unmark 1.9.2 is vulnerable to Cross Site Scripting (XSS) via application/views/marks/add_by_url.php. |
Organizr v1.90 is vulnerable to Cross Site Scripting (XSS) via api.php. |
phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via app\admin\import-export\import-load-data.php. |
bjyadmin commit a560fd5 is vulnerable to Cross Site Scripting (XSS) via Public/statics/umeditor1_2_3/php/getContent.php |