CWE-79
46,575 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (46,575)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Janobe 2School Attendence Monitoring System School Event Management SystemJun 17, 2026 Aug 6, 2024 N/A· v4 6.1 MEDIUM· v3 N/A· v2 Cross-Site Scripting (XSS) vulnerability in School Attendance Monitoring System and School Event Management System affecting version 1.0. An attacker could create a specially crafted URL and send it to a victim to obtain...Show more |
1Janobe 2School Attendence Monitoring System School Event Management SystemJun 17, 2026 Aug 6, 2024 N/A· v4 6.1 MEDIUM· v3 N/A· v2 Cross-Site Scripting (XSS) vulnerability in School Attendance Monitoring System and School Event Management System affecting version 1.0. An attacker could create a specially crafted URL and send it to a victim to obtain...Show more |
1Janobe 2School Attendence Monitoring System School Event Management SystemJun 17, 2026 Aug 6, 2024 N/A· v4 6.1 MEDIUM· v3 N/A· v2 Cross-Site Scripting (XSS) vulnerability in School Attendance Monitoring System and School Event Management System affecting version 1.0. An attacker could create a specially crafted URL and send it to a victim to obtain...Show more |
The Folders – Unlimited Folders to Organize Media Library Folder, Pages, Posts, File Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 3....Show more |
1Janobe 3Credit Card Debit Card PaymentPaypalJun 17, 2026 Aug 6, 2024 N/A· v4 6.1 MEDIUM· v3 N/A· v2 Cross-Site Scripting (XSS) vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could create a specially crafted URL and send it to a victim to obtain details of their session co...Show more |
1Janobe 3Credit Card Debit Card PaymentPaypalJun 17, 2026 Aug 6, 2024 N/A· v4 6.1 MEDIUM· v3 N/A· v2 Cross-Site Scripting (XSS) vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could create a specially crafted URL and send it to a victim to obtain details of their session co...Show more |
1Janobe 3Credit Card Debit Card PaymentPaypalJun 17, 2026 Aug 6, 2024 N/A· v4 6.1 MEDIUM· v3 N/A· v2 Cross-Site Scripting (XSS) vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could create a specially crafted URL and send it to a victim to obtain details of their session co...Show more |
1Janobe 1Young Entrepreneur E Negosyo System Jun 17, 2026 Aug 6, 2024 N/A· v4 6.1 MEDIUM· v3 N/A· v2 Cross-Site Scripting (XSS) vulnerability in E-Negosyo System affecting version 1.0. An attacker could create a specially crafted URL and send it to a victim to obtain their session cookie details via 'category' parameter...Show more |
1Janobe 1Young Entrepreneur E Negosyo System Jun 17, 2026 Aug 6, 2024 N/A· v4 6.1 MEDIUM· v3 N/A· v2 Cross-Site Scripting (XSS) vulnerability in E-Negosyo System affecting version 1.0. An attacker could create a specially crafted URL and send it to a victim to obtain their session cookie details via 'view' parameter in...Show more |
1Janobe 1Young Entrepreneur E Negosyo System Jun 17, 2026 Aug 6, 2024 N/A· v4 6.1 MEDIUM· v3 N/A· v2 Cross-Site Scripting (XSS) vulnerability in E-Negosyo System affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted JavaScript payload to an authenticated user and partially ta...Show more |
1Janobe 1Young Entrepreneur E Negosyo System Jun 17, 2026 Aug 6, 2024 N/A· v4 6.1 MEDIUM· v3 N/A· v2 Cross-Site Scripting (XSS) vulnerability in E-Negosyo System affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted JavaScript payload to an authenticated user and partially ta...Show more |
The Ajax Search Lite WordPress plugin before 4.12.1 does not sanitise and escape some parameters, which could allow users with a role as low as Admin+ to perform Cross-Site Scripting attacks. |
The Easy Table of Contents WordPress plugin before 2.0.68 does not sanitise and escape some parameters, which could allow users with a role as low as Editor to perform Cross-Site Scripting attacks. |
The shortcodes-ultimate-pro WordPress plugin before 7.2.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users wit...Show more |
The WordPress File Upload WordPress plugin before 4.24.8 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privil...Show more |
HaloITSM versions up to 2.146.1 are affected by a Stored Cross-Site Scripting (XSS) vulnerability. The injected JavaScript code can execute arbitrary action on behalf of the user accessing a ticket. HaloITSM versions pas...Show more |
The WPBakery Visual Composer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘link’ parameter in all versions up to, and including, 7.7 due to insufficient input sanitization and output escaping...Show more |
Unsanitized user-input in Calibre <= 7.15.0 allow attackers to perform reflected cross-site scripting. |
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Gitea Gitea Open Source Git Server allows Stored XSS.This issue affects Gitea Open Source Git Server: 1.22.0. |
The Traffic Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'page' parameter in the 'UserWebStat' AJAX function in all versions up to, and including, 1.4.5 due to insufficient input sani...Show more |