← Back
CWE-79

46,770 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (46,770)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Wpmet
1Elementskit
Jun 17, 2026
Apr 19, 2024
N/A· v4
5.4 MEDIUM· v3
N/A· v2
The ElementsKit Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Creative Button widget in all versions up to, and including, 3.6.0 due to insufficient input sanitization and output...Show more
The ElementsKit Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Creative Button widget in all versions up to, and including, 3.6.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.Show less
1Thimpress
1Learnpress
Jun 17, 2026
Apr 19, 2024
N/A· v4
5.4 MEDIUM· v3
N/A· v2
The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the _id value in all versions up to, and including, 4.2.6.4 due to insufficient input sanitization and output es...Show more
The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the _id value in all versions up to, and including, 4.2.6.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.Show less
1Derbynet
1Derbynet
Jun 17, 2026
Apr 18, 2024
N/A· v4
8.0 HIGH· v3
N/A· v2
Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows attackers to execute arbitrary code via the 'back' Parameter in playlist.php
1Derbynet
1Derbynet
Jun 17, 2026
Apr 18, 2024
N/A· v4
6.3 MEDIUM· v3
N/A· v2
Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows attackers to execute arbitrary code via the racer-results.php component.
1Derbynet
1Derbynet
Jun 17, 2026
Apr 18, 2024
N/A· v4
4.6 MEDIUM· v3
N/A· v2
Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows attackers to execute arbitrary code via the ./inc/kiosks.inc component.
1Derbynet
1Derbynet
Jun 17, 2026
Apr 18, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows attackers to execute arbitrary code via the photo-thumbs.php component.
1Derbynet
1Derbynet
Jun 17, 2026
Apr 18, 2024
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows a remote attacker to execute arbitrary code via the photo.php component.
1Derbynet
1Derbynet
Jun 17, 2026
Apr 18, 2024
N/A· v4
7.4 HIGH· v3
N/A· v2
Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows a remote attacker to execute arbitrary code via the render-document.php component.
1Totolink
1N300rt Firmware
Jun 17, 2026
Apr 18, 2024
N/A· v4
5.4 MEDIUM· v3
N/A· v2
TOTOLINK N300RT V2.1.8-B20201030.1539 contains a Store Cross-site scripting (XSS) vulnerability in Access Control under the Wireless Page.
1Totolink
1N300rt Firmware
Jun 17, 2026
Apr 18, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
TOTOLINK N300RT V2.1.8-B20201030.1539 contains a Store Cross-site scripting (XSS) vulnerability in IP/Port Filtering under the Firewall Page.
1Totolink
1N300rt Firmware
Jun 17, 2026
Apr 18, 2024
N/A· v4
4.3 MEDIUM· v3
N/A· v2
TOTOLINK N300RT V2.1.8-B20201030.1539 contains a Store Cross-site scripting (XSS) vulnerability in MAC Filtering under the Firewall Page.
1Totolink
1N300rt Firmware
Jun 17, 2026
Apr 18, 2024
N/A· v4
6.1 MEDIUM· v3
N/A· v2
TOTOLINK N300RT V2.1.8-B20201030.1539 contains a Store Cross-site scripting (XSS) vulnerability in WDS Settings under the Wireless Page.
1Totolink
1N300rt Firmware
Jun 17, 2026
Apr 18, 2024
N/A· v4
5.5 MEDIUM· v3
N/A· v2
TOTOLINK N300RT V2.1.8-B20201030.1539 contains a Store Cross-site scripting (XSS) vulnerability in Port Forwarding under the Firewall Page.
1Totolink
1Ex200 Firmware
Jun 17, 2026
Apr 18, 2024
N/A· v4
6.8 MEDIUM· v3
N/A· v2
TOTOLINK EX200 V4.0.3c.7646_B20201211 contains a Cross-site scripting (XSS) vulnerability through the key parameter in the setWiFiExtenderConfig function.
1Totolink
1Ex200 Firmware
Jun 17, 2026
Apr 18, 2024
N/A· v4
2.4 LOW· v3
N/A· v2
TOTOLINK EX200 V4.0.3c.7646_B20201211 contains a Cross-site scripting (XSS) vulnerability through the ssid parameter in the setWiFiExtenderConfig function.
2Aiohttp
Fedoraproject
2Aiohttp
Fedora
Jun 17, 2026
Apr 18, 2024
N/A· v4
6.1 MEDIUM· v3
N/A· v2
aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. A XSS vulnerability exists on index pages for static file handling. This vulnerability is fixed in 3.9.4. We have always recommended using a...Show more
aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. A XSS vulnerability exists on index pages for static file handling. This vulnerability is fixed in 3.9.4. We have always recommended using a reverse proxy server (e.g. nginx) for serving static files. Users following the recommendation are unaffected. Other users can disable `show_index` if unable to upgrade.Show less
-
-
Jun 17, 2026
Apr 18, 2024
N/A· v4
7.1 HIGH· v3
N/A· v2
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in looks_awesome Superfly Menu superfly-menu.This issue affects Superfly Menu: from n/a through <= 5.0.25.
-
-
Jun 17, 2026
Apr 18, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tagbox Taggbox allows Stored XSS.This issue affects Taggbox: from n/a through 3.2.
-
-
Jun 17, 2026
Apr 18, 2024
N/A· v4
5.9 MEDIUM· v3
N/A· v2
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jeroen Peters Navigation menu as Dropdown Widget navigation-menu-as-dropdown-widget.This issue affects Navigation menu...Show more
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jeroen Peters Navigation menu as Dropdown Widget navigation-menu-as-dropdown-widget.This issue affects Navigation menu as Dropdown Widget: from n/a through <= 1.3.4.Show less
1Wpfactory
1Ean For Woocommerce
Jun 17, 2026
Apr 18, 2024
N/A· v4
5.4 MEDIUM· v3
N/A· v2
The EAN for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'alg_wc_ean_product_meta' shortcode in all versions up to, and including, 4.8.7 due to insufficient input sanitiz...Show more
The EAN for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'alg_wc_ean_product_meta' shortcode in all versions up to, and including, 4.8.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.Show less