CWE-79
46,595 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (46,595)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Wisdmlabs 1Product Enquiry For Woocommerce Jun 17, 2026 Jul 13, 2024 N/A· v4 5.9 MEDIUM· v3 N/A· v2 The Product Enquiry for WooCommerce WordPress plugin before 3.1.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks eve...Show more |
The Giveaways and Contests by RafflePress WordPress plugin before 1.12.14 does not sanitise and escape some parameters, which could allow users with a role as low as editor to perform Cross-Site Scripting attacks |
1Arnesonium 1Openpgp Form Encryption Jun 17, 2026 Jul 13, 2024 N/A· v4 4.6 MEDIUM· v3 N/A· v2 The OpenPGP Form Encryption for WordPress plugin before 1.5.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users...Show more |
The Hostel WordPress plugin before 1.1.5.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such...Show more |
1Castos 1Seriously Simple Podcasting Jun 17, 2026 Jul 13, 2024 N/A· v4 4.8 MEDIUM· v3 N/A· v2 The Seriously Simple Podcasting WordPress plugin before 3.3.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even wh...Show more |
1Wpchill 1Image Photo Gallery Final Tiles Grid Jun 17, 2026 Jul 13, 2024 N/A· v4 6.8 MEDIUM· v3 N/A· v2 The Image Photo Gallery Final Tiles Grid WordPress plugin before 3.6.0 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as...Show more |
The WordPress Button Plugin MaxButtons WordPress plugin before 9.7.8 does not sanitise and escape some parameters, which could allow users with a role as low as editor to perform Cross-Site Scripting attacks |
The socialdriver-framework WordPress plugin before 2024.04.30 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high p...Show more |
The User Feedback – Create Interactive Feedback Form, User Surveys, and Polls in Seconds plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the name parameter in all versions up to, and including, 1.0....Show more |
1Ibm 1Infosphere Information Server Jun 17, 2026 Jul 12, 2024 N/A· v4 5.4 MEDIUM· v3 N/A· v2 IBM InfoSphere Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially lead...Show more |
1Leap13 1Premium Addons For Elementor Jun 17, 2026 Jul 12, 2024 N/A· v4 5.4 MEDIUM· v3 N/A· v2 The Premium Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Animated Text widget in all versions up to, and including, 4.10.36 due to insufficient input sanitizatio...Show more |
The WP Total Branding – Complete branding solution for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.2 due to insufficient input sa...Show more |
The PowerPress Podcasting plugin by Blubrry plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘media_url’ parameter in all versions up to, and including, 11.9.10 due to insufficient input sanit...Show more |
1Quantumcloud 1Simple Video Directory Jun 17, 2026 Jul 12, 2024 N/A· v4 5.4 MEDIUM· v3 N/A· v2 The Simple Video Directory WordPress plugin before 1.4.4 does not sanitise and escape some of its settings, which could allow contributors and higher to perform Stored Cross-Site Scripting attacks even when the unfiltere...Show more |
The Inline Related Posts WordPress plugin before 3.7.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privileg...Show more |
The WP Secure Maintenance WordPress plugin before 1.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the u...Show more |
The socialdriver-framework WordPress plugin before 2024.04.30 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even wh...Show more |
The Watu Quiz WordPress plugin before 3.4.1.2 does not sanitise and escape some of its settings, which could allow users such as authors (if they've been authorized by admins) to perform Stored Cross-Site Scripting attac...Show more |
1Matteoenna 1Website Content In Page Or Post Jun 17, 2026 Jul 12, 2024 N/A· v4 5.4 MEDIUM· v3 N/A· v2 The Website Content in Page or Post WordPress plugin before 2024.04.09 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could al...Show more |
1Bmwebproperties 1Social Media Widget Jun 17, 2026 Jul 12, 2024 N/A· v4 4.8 MEDIUM· v3 N/A· v2 The Social Media Widget WordPress plugin before 4.0.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the u...Show more |