← Back
CWE-79

46,964 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (46,964)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Startrinity
1Softswitch
Jun 17, 2026
Sep 3, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
StarTrinity Softswitch version 2023-02-16 - Persistent XSS (CWE-79)
1Startrinity
1Softswitch
Jun 17, 2026
Sep 3, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
StarTrinity Softswitch version 2023-02-16 - Multiple Reflected XSS (CWE-79)
1Farsight
1Provide Server
Jun 17, 2026
Sep 3, 2023
N/A· v4
4.8 MEDIUM· v3
N/A· v2
Farsight Tech Nordic AB ProVide version 14.5 - Multiple XSS vulnerabilities (CWE-79) can be exploited by a user with administrator privilege.
17 Twenty
1Bot
Jun 17, 2026
Sep 3, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
7Twenty BOT - CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').
1Kristarella
1Exifography
Jun 17, 2026
Sep 3, 2023
N/A· v4
4.8 MEDIUM· v3
N/A· v2
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Exifography plugin <= 1.3.1 versions.
1Visualmodo
1Borderless
Jun 17, 2026
Sep 3, 2023
N/A· v4
4.8 MEDIUM· v3
N/A· v2
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Visualmodo Borderless plugin <= 1.4.8 versions.
1Realwebcare
1Wrc Pricing Tables
Jun 17, 2026
Sep 3, 2023
N/A· v4
4.8 MEDIUM· v3
N/A· v2
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Realwebcare WRC Pricing Tables plugin <= 2.3.7 versions.
1Essentialplugin
1Audio Player With Playlist Ultimate
Jun 17, 2026
Sep 3, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in WP OnlineSupport, Essential Plugin Audio Player with Playlist Ultimate plugin <= 1.2.2 versions.
1Qualityunit
1Post Affiliate Pro
Jun 17, 2026
Sep 3, 2023
N/A· v4
4.8 MEDIUM· v3
N/A· v2
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in QualityUnit Post Affiliate Pro plugin <= 1.25.0 versions.
1Suitedash
1Client Portal \
Jun 17, 2026
Sep 3, 2023
N/A· v4
4.8 MEDIUM· v3
N/A· v2
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in SuiteDash :: ONE Dashboard® Client Portal : SuiteDash Direct Login plugin <= 1.7.6 versions.
1Elasticemail
1Elastic Email Sender
Jun 17, 2026
Sep 3, 2023
N/A· v4
4.8 MEDIUM· v3
N/A· v2
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Elastic Email Sender plugin <= 1.2.6 versions.
1Newnine
1Font Awesome 4 Menus
Jun 17, 2026
Sep 2, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
The Font Awesome 4 Menus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'fa' and 'fa-stack' shortcodes in versions up to, and including, 4.7.0 due to insufficient input sanitization and output...Show more
The Font Awesome 4 Menus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'fa' and 'fa-stack' shortcodes in versions up to, and including, 4.7.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.Show less
1Totvs
1Rm
Jun 17, 2026
Sep 1, 2023
N/A· v4
6.1 MEDIUM· v3
5.0 MEDIUM· v2
A vulnerability classified as problematic was found in TOTVS RM 12.1. Affected by this vulnerability is an unknown functionality of the component Portal. The manipulation of the argument d leads to cross site scripting....Show more
A vulnerability classified as problematic was found in TOTVS RM 12.1. Affected by this vulnerability is an unknown functionality of the component Portal. The manipulation of the argument d leads to cross site scripting. The attack can be launched remotely. The identifier VDB-238573 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.Show less
1Decentraland
1Single Sign On Client
Jun 17, 2026
Sep 1, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
@dcl/single-sign-on-client is an open source npm library which deals with single sign on authentication flows. Improper input validation in the `init` function allows arbitrary javascript to be executed using the `javas...Show more
@dcl/single-sign-on-client is an open source npm library which deals with single sign on authentication flows. Improper input validation in the `init` function allows arbitrary javascript to be executed using the `javascript:` prefix. This vulnerability has been patched on version `0.1.0`. Users are advised to upgrade. Users unable to upgrade should limit untrusted user input to the `init` function.Show less
1Totvs
1Rm
Jun 17, 2026
Sep 1, 2023
2.3 LOW· v4
6.1 MEDIUM· v3
2.6 LOW· v2
A vulnerability classified as problematic has been found in TOTVS RM 12.1. Affected is an unknown function of the file Login.aspx of the component Portal. The manipulation of the argument VIEWSTATE leads to cross site sc...Show more
A vulnerability classified as problematic has been found in TOTVS RM 12.1. Affected is an unknown function of the file Login.aspx of the component Portal. The manipulation of the argument VIEWSTATE leads to cross site scripting. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. It is possible to mitigate the problem by applying the configuration setting <pages validateRequest="true" [...] viewStateEncryptionMode="Always" />. It is recommended to change the configuration settings. The vendor was initially contacted early about this disclosure but did not respond in any way. In a later statement he explains, that "the behavior described [...] is related to specific configurations that are not part of the default application setup. In standard production environments, the relevant feature (VIEWSTATE) is disabled by default, which effectively mitigates the risk of exploitation."Show less
1Infosoftbd
1Clcknshop
Jun 17, 2026
Sep 1, 2023
N/A· v4
6.1 MEDIUM· v3
4.0 MEDIUM· v2
A vulnerability was found in Infosoftbd Clcknshop 1.0.0. It has been declared as problematic. This vulnerability affects unknown code of the file /collection/all. The manipulation of the argument q leads to cross site sc...Show more
A vulnerability was found in Infosoftbd Clcknshop 1.0.0. It has been declared as problematic. This vulnerability affects unknown code of the file /collection/all. The manipulation of the argument q leads to cross site scripting. The attack can be initiated remotely. VDB-238570 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.Show less
1Free And Open Source Inventory Management System Project
1Free And Open Source Inventory Management System
Jun 17, 2026
Sep 1, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Multiple cross-site scripting (XSS) vulnerabilities in Free and Open Source Inventory Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Name, Addres...Show more
Multiple cross-site scripting (XSS) vulnerabilities in Free and Open Source Inventory Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Name, Address, and Company parameters under the Add New Member section.Show less
1Free And Open Source Inventory Management System Project
1Free And Open Source Inventory Management System
Jun 17, 2026
Sep 1, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Multiple cross-site scripting (XSS) vulnerabilities in Free and Open Source Inventory Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Name, Addres...Show more
Multiple cross-site scripting (XSS) vulnerabilities in Free and Open Source Inventory Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Name, Address, and Company parameters under the Add Customer section.Show less
1Typora
1Typora
Jun 17, 2026
Sep 1, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
A cross site scripting (XSS) vulnerability in the Markdown Editor component of Typora v1.6.7 allows attackers to execute arbitrary code via uploading a crafted Markdown file.
1General Solutions
1Contwise Case2
Jun 17, 2026
Sep 1, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
A cross-site scripting (XSS) vulnerability in General Solutions Steiner GmbH CASE 3 Taskmanagement V 3.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the name parameter.