CWE-79
46,934 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (46,934)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Castos Seriously Simple Stats plugin <= 1.5.1 versions. |
1Pluginus 1Wolf Wordpress Posts Bulk Editor And Products Manager Professional Jun 17, 2026 Oct 17, 2023 N/A· v4 4.8 MEDIUM· v3 N/A· v2 Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in realmag777 WOLF – WordPress Posts Bulk Editor and Manager Professional plugin <= 1.0.7.1 versions. |
1Liferay 2Digital Experience Platform Liferay PortalJun 17, 2026 Oct 17, 2023 N/A· v4 6.1 MEDIUM· v3 N/A· v2 Multiple reflected cross-site scripting (XSS) vulnerabilities in the Plugin for OAuth 2.0 module's OAuth2ProviderApplicationRedirect class in Liferay Portal 7.4.3.41 through 7.4.3.89, and Liferay DXP 7.4 update 41 throug...Show more |
1Liferay 2Digital Experience Platform Liferay PortalJun 17, 2026 Oct 17, 2023 N/A· v4 5.4 MEDIUM· v3 N/A· v2 Stored cross-site scripting (XSS) vulnerability in Page Tree menu Liferay Portal 7.3.6 through 7.4.3.78, and Liferay DXP 7.3 fix pack 1 through update 23, and 7.4 before update 79 allows remote attackers to inject arbitr...Show more |
1Liferay 2Digital Experience Platform Liferay PortalJun 17, 2026 Oct 17, 2023 N/A· v4 5.4 MEDIUM· v3 N/A· v2 Multiple stored cross-site scripting (XSS) vulnerabilities in the fragment components in Liferay Portal 7.4.2 through 7.4.3.53, and Liferay DXP 7.4 before update 54 allow remote attackers to inject arbitrary web script o...Show more |
1Liferay 2Digital Experience Platform Liferay PortalJun 17, 2026 Oct 17, 2023 N/A· v4 5.4 MEDIUM· v3 N/A· v2 Stored cross-site scripting (XSS) vulnerability in the manage vocabulary page in Liferay Portal 7.4.2 through 7.4.3.87, and Liferay DXP 7.4 before update 88 allows remote attackers to inject arbitrary web script or HTML...Show more |
1Davidlingren 1Media Library Assistant Jun 17, 2026 Oct 17, 2023 N/A· v4 4.8 MEDIUM· v3 N/A· v2 Auth. (author+) Stored Cross-Site Scripting (XSS) vulnerability in David Lingren Media Library Assistant plugin <= 3.11 versions. |
1Liferay 2Digital Experience Platform Liferay PortalJun 17, 2026 Oct 17, 2023 N/A· v4 6.1 MEDIUM· v3 N/A· v2 Reflected cross-site scripting (XSS) vulnerability on the Export for Translation page in Liferay Portal 7.4.3.4 through 7.4.3.85, and Liferay DXP 7.4 before update 86 allows remote attackers to inject arbitrary web scrip...Show more |
Archer Platform 6.x before 6.13 P2 HF2 (6.13.0.2.2) contains a stored cross-site scripting (XSS) vulnerability. A remote authenticated malicious Archer user could potentially exploit this vulnerability to store malicious...Show more |
Discourse is an open source platform for community discussion. Improper escaping of user input allowed for Cross-site Scripting attacks via the digest email preview UI. This issue only affects sites with CSP disabled. Th...Show more |
dicourse-calendar is a plugin for the Discourse messaging platform which adds the ability to create a dynamic calendar in the first post of a topic. Improper escaping of event titles could lead to Cross-site Scripting (X...Show more |
Cross Site Scripting vulnerability in mooSocial 3.1.8 allows a remote attacker to obtain sensitive information via a crafted script to the q parameter in the Search function. |
com.xwiki.identity-oauth:identity-oauth-ui is a package to aid in building identity and service providers based on OAuth authorizations. When a user logs in via the OAuth method, the identityOAuth parameters sent in the...Show more |
1User Registration & Login And User Management System With Admin Panel Project 1User Registration & Login And User Management System With Admin Panel Jun 17, 2026 Oct 16, 2023 N/A· v4 5.4 MEDIUM· v3 N/A· v2 Cross Site Scripting (XSS) vulnerability in Phpgurukul User Registration & Login and User Management System With admin panel 3.0 allows attackers to run arbitrary code via fname, lname, email, and contact fields of the u...Show more |
github.com/crewjam/saml is a saml library for the go language. In affected versions the package does not validate the ACS Location URI according to the SAML binding being parsed. If abused, this flaw allows attackers to...Show more |
1Codedraft 1Mediabay Wordpress Media Library Folders Jun 17, 2026 Oct 16, 2023 N/A· v4 5.4 MEDIUM· v3 N/A· v2 Auth. (editor+) Stored Cross-Site Scripting (XSS) vulnerability in Codedrafty Mediabay – Media Library Folders plugin <= 1.6 versions. |
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Timely - Appointment software Timely Booking Button plugin <= 2.0.2 versions. |
1Tychesoftwares 1Abandoned Cart Lite For Woocommerce Jun 17, 2026 Oct 16, 2023 N/A· v4 4.8 MEDIUM· v3 N/A· v2 Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Tyche Softwares Abandoned Cart Lite for WooCommerce plugin <= 5.15.2 versions. |
Auth. (contributo+) Stored Cross-Site Scripting (XSS) vulnerability in Cytech BuddyMeet plugin <= 2.2.0 versions. |
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Robin Wilson bbp style pack plugin <= 5.6.7 versions. |