← Back
CWE-79

46,618 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (46,618)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Wpbean
1Wpb Elementor Addons
Jun 17, 2026
May 30, 2024
N/A· v4
5.4 MEDIUM· v3
N/A· v2
The WPB Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the output of 'tags' added to widgets in all versions up to, and including, 1.0.9 due to insufficient input sanitization and...Show more
The WPB Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the output of 'tags' added to widgets in all versions up to, and including, 1.0.9 due to insufficient input sanitization and output escaping on user supplied tag attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.Show less
-
-
Jun 17, 2026
May 30, 2024
N/A· v4
6.4 MEDIUM· v3
N/A· v2
The Testimonial Carousel For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via URL values the plugin's carousel widgets in all versions up to, and including, 10.2.2 due to insufficient input...Show more
The Testimonial Carousel For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via URL values the plugin's carousel widgets in all versions up to, and including, 10.2.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.Show less
-
-
Jun 17, 2026
May 30, 2024
N/A· v4
6.4 MEDIUM· v3
N/A· v2
The Login Logout Register Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'llrmloginlogout' shortcode in all versions up to, and including, 2.0 due to insufficient input sanitizati...Show more
The Login Logout Register Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'llrmloginlogout' shortcode in all versions up to, and including, 2.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.Show less
1Mitel
1Micontact Center Business
Jun 17, 2026
May 29, 2024
N/A· v4
5.4 MEDIUM· v3
N/A· v2
A vulnerability in the legacy chat component of Mitel MiContact Center Business through 10.0.0.4 could allow an unauthenticated attacker to conduct a reflected cross-site scripting (XSS) attack due to insufficient input...Show more
A vulnerability in the legacy chat component of Mitel MiContact Center Business through 10.0.0.4 could allow an unauthenticated attacker to conduct a reflected cross-site scripting (XSS) attack due to insufficient input validation.Show less
1Mitel
1Micontact Center Business
Jun 17, 2026
May 29, 2024
N/A· v4
6.1 MEDIUM· v3
N/A· v2
A vulnerability in the Ignite component of Mitel MiContact Center Business through 10.0.0.4 could allow an unauthenticated attacker to conduct a stored cross-site scripting (XSS) attack due to insufficient input validati...Show more
A vulnerability in the Ignite component of Mitel MiContact Center Business through 10.0.0.4 could allow an unauthenticated attacker to conduct a stored cross-site scripting (XSS) attack due to insufficient input validation.Show less
1Jetbrains
1Teamcity
Jun 17, 2026
May 29, 2024
N/A· v4
5.4 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2024.03.2 stored XSS via build step settings was possible
1Jetbrains
1Teamcity
Jun 17, 2026
May 29, 2024
N/A· v4
5.4 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2024.03.2 several stored XSS in untrusted builds settings were possible
1Jetbrains
1Teamcity
Jun 17, 2026
May 29, 2024
N/A· v4
6.1 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2023.05.6 reflected XSS on the subscriptions page was possible
1Jetbrains
1Teamcity
Jun 17, 2026
May 29, 2024
N/A· v4
5.4 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2023.05.6, 2023.11.5 stored XSS in Commit status publisher was possible
1Jetbrains
1Teamcity
Jun 17, 2026
May 29, 2024
N/A· v4
5.4 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 stored XSS via OAuth connection settings was possible
1Jetbrains
1Teamcity
Jun 17, 2026
May 29, 2024
N/A· v4
5.4 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 stored XSS via issue tracker integration was possible
1Jetbrains
1Teamcity
Jun 17, 2026
May 29, 2024
N/A· v4
5.4 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 reflected XSS via OAuth provider configuration was possible
1Jetbrains
1Teamcity
Jun 17, 2026
May 29, 2024
N/A· v4
6.1 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 stored XSS via third-party reports was possible
1Jetbrains
1Teamcity
Jun 17, 2026
May 29, 2024
N/A· v4
6.1 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 an XSS could be executed via certain report grouping and filtering operations
1Jetbrains
1Teamcity
Jun 17, 2026
May 29, 2024
N/A· v4
5.4 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 several Stored XSS in code inspection reports were possible
1Pluginus
1Husky Products Filter Professional For Woocommerce
Jun 17, 2026
May 29, 2024
N/A· v4
6.4 MEDIUM· v3
N/A· v2
The HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 1.3.5.3 due to insufficient i...Show more
The HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 1.3.5.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.Show less
-
-
Jun 17, 2026
May 29, 2024
N/A· v4
6.1 MEDIUM· v3
N/A· v2
When LDAP authentication is activated in the configuration it is possible to obtain reflected XSS execution by creating a custom URL that the victim only needs to open in order to execute arbitrary JavaScript code in the...Show more
When LDAP authentication is activated in the configuration it is possible to obtain reflected XSS execution by creating a custom URL that the victim only needs to open in order to execute arbitrary JavaScript code in the victim's browser. This is due to a fault in the file login.php where the content of "$_SERVER['PHP_SELF']" is reflected into the HTML of the website. Hence the attacker does not need a valid account in order to exploit this issue.Show less
1Zohocorp
1Manageengine Pam360
Jun 17, 2026
May 29, 2024
N/A· v4
4.6 MEDIUM· v3
N/A· v2
Zoho ManageEngine PAM360 is vulnerable to Stored XSS vulnerability. This vulnerability is applicable only in the version 6610.
1Wpdeveloper
1Essential Addons For Elementor
Jun 17, 2026
May 29, 2024
N/A· v4
5.4 MEDIUM· v3
N/A· v2
The Essential Addons for Elementor PRO – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Team Member Carousel widget in al...Show more
The Essential Addons for Elementor PRO – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Team Member Carousel widget in all Pro versions up to, and including, 5.8.14 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.Show less
1Pjaudiomv
1Fetch Jft
Jun 17, 2026
May 29, 2024
N/A· v4
4.0 MEDIUM· v3
N/A· v2
The Fetch JFT plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.8.3 due to insufficient input sanitization and output escaping. This makes it pos...Show more
The Fetch JFT plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.8.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.Show less