CWE-79
46,977 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (46,977)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Icopydoc 1Xml For Google Merchant Center Jun 17, 2026 Aug 17, 2023 N/A· v4 6.1 MEDIUM· v3 N/A· v2 Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Maxim Glazunov XML for Google Merchant Center plugin <= 3.0.1 versions. |
1Davidmichaelross 1Dave's Wordpress Live Search Jun 17, 2026 Aug 17, 2023 N/A· v4 4.8 MEDIUM· v3 N/A· v2 Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Dave Ross Dave's WordPress Live Search plugin <= 4.8.1 versions. |
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Steve Curtis, St. Pete Design Gps Plotter plugin <= 5.1.4 versions. |
1Tridenttechnolabs 1Easy Slider Revolution Jun 17, 2026 Aug 17, 2023 N/A· v4 5.4 MEDIUM· v3 N/A· v2 Auth. (author+) Stored Cross-Site Scripting (XSS) vulnerability in Trident Technolabs Easy Slider Revolution plugin <= 1.0.0 versions. |
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in M Williams Cab Grid plugin <= 1.5.15 versions. |
EC-CUBE 2.11.0 to 2.17.2-p1 contain a cross-site scripting vulnerability in "mail/template" and "products/product" of Management page. If this vulnerability is exploited, an arbitrary script may be executed on the web b...Show more |
Cross-site Scripting (XSS) - Stored in GitHub repository cockpit-hq/cockpit prior to 2.6.4. |
1Cisco 2Evolved Programmable Network Manager Prime InfrastructureJun 17, 2026 Aug 16, 2023 N/A· v4 6.1 MEDIUM· v3 N/A· v2 A vulnerability in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager (EPNM) could allow an unauthenticated, remote attacker to conduct a cross-site scripting...Show more |
1Cisco 2Evolved Programmable Network Manager Prime InfrastructureJun 17, 2026 Aug 16, 2023 N/A· v4 5.4 MEDIUM· v3 N/A· v2 Multiple vulnerabilities in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager (EPNM) could allow an authenticated, remote attacker to conduct a stored cross-s...Show more |
1Cisco 2Evolved Programmable Network Manager Prime InfrastructureJun 17, 2026 Aug 16, 2023 N/A· v4 5.4 MEDIUM· v3 N/A· v2 Multiple vulnerabilities in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager (EPNM) could allow an authenticated, remote attacker to conduct a stored cross-s...Show more |
1Cisco 2Evolved Programmable Network Manager Prime InfrastructureJun 17, 2026 Aug 16, 2023 N/A· v4 5.4 MEDIUM· v3 N/A· v2 Multiple vulnerabilities in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager (EPNM) could allow an authenticated, remote attacker to conduct a stored cross-s...Show more |
1Cisco 2Unified Communications Manager Unified Communications Manager Im And Presence ServiceJun 17, 2026 Aug 16, 2023 N/A· v4 6.1 MEDIUM· v3 N/A· v2 A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM), Cisco Unified CM Session Management Edition (Unified CM SME), and Cisco Unified Communications Manager IM &...Show more |
1Cisco 6Encs 5100 Firmware Encs 5400 FirmwareUcs E1120d M3 Firmware+3 moreJun 17, 2026 Aug 16, 2023 N/A· v4 6.1 MEDIUM· v3 N/A· v2 A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the i...Show more |
A vulnerability, which was classified as problematic, has been found in tdevs Hyip Rio 2.1. Affected by this issue is some unknown functionality of the file /user/settings of the component Profile Settings. The manipulat...Show more |
Jenkins Docker Swarm Plugin 1.11 and earlier does not escape values returned from Docker before inserting them into the Docker Swarm Dashboard view, resulting in a stored cross-site scripting (XSS) vulnerability exploita...Show more |
Jenkins Shortcut Job Plugin 0.4 and earlier does not escape the shortcut redirection URL, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to configure shortcut jobs. |
Jenkins Flaky Test Handler Plugin 1.2.2 and earlier does not escape JUnit test contents when showing them on the Jenkins UI, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to...Show more |
A Cross Site Scripting (XSS) vulnerability in Netlify CMS v.2.10.192 allows a remote attacker to execute arbitrary code via a crafted payload to the body parameter of the new post function. |
The Ko-fi Button WordPress plugin before 1.3.3 does not properly some of its settings, which could allow high-privilege users to perform Stored Cross-Site Scripting (XSS) attacks even when the unfiltered_html capability...Show more |
The URL Params WordPress plugin before 2.5 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contribut...Show more |