← Back
CWE-79

46,994 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (46,994)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Zabbix
1Frontend
Jun 17, 2026
Jul 13, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Stored or persistent cross-site scripting (XSS) is a type of XSS where the attacker first sends the payload to the web application, then the application saves the payload (e.g., in a database or server-side text files),...Show more
Stored or persistent cross-site scripting (XSS) is a type of XSS where the attacker first sends the payload to the web application, then the application saves the payload (e.g., in a database or server-side text files), and finally, the application unintentionally executes the payload for every victim visiting its web pages.Show less
1Zabbix
1Zabbix
Jun 17, 2026
Jul 13, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Currently, geomap configuration (Administration -> General -> Geographical maps) allows using HTML in the field “Attribution text” when selected “Other” Tile provider.
1Idisplay
1Platplay Ds
Jun 17, 2026
Jul 13, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in iDisplay PlatPlay DS allows Stored XSS. This issue affects PlatPlay DS: before 3.14.
1Gitlab
1Gitlab
Jun 17, 2026
Jul 13, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
An issue has been discovered in GitLab CE/EE affecting all versions starting from 7.14 before 15.11.10, all versions starting from 16.0 before 16.0.6, all versions starting from 16.1 before 16.1.1, which allows an attack...Show more
An issue has been discovered in GitLab CE/EE affecting all versions starting from 7.14 before 15.11.10, all versions starting from 16.0 before 16.0.6, all versions starting from 16.1 before 16.1.1, which allows an attacker to inject HTML in an email address field.Show less
1Elecom
2Wrh 300wh H Firmware
Wtc 300hwh Firmware
Jun 17, 2026
Jul 13, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Cross-site scripting vulnerability in WRH-300WH-H v2.12 and earlier, and WTC-300HWH v1.09 and earlier allows a remote unauthenticated attacker to inject an arbitrary script.
1Gzscripts
1Vacation Rental Website
Jun 17, 2026
Jul 12, 2023
N/A· v4
6.1 MEDIUM· v3
5.0 MEDIUM· v2
A vulnerability was found in GZ Scripts Vacation Rental Website 1.8 and classified as problematic. Affected by this issue is some unknown functionality of the file /VacationRentalWebsite/property/8/ad-has-principes/ of t...Show more
A vulnerability was found in GZ Scripts Vacation Rental Website 1.8 and classified as problematic. Affected by this issue is some unknown functionality of the file /VacationRentalWebsite/property/8/ad-has-principes/ of the component HTTP POST Request Handler. The manipulation of the argument username/title/comment leads to cross site scripting. The attack may be launched remotely. The identifier of this vulnerability is VDB-233888.Show less
1Nodcms
1Nodcms
Jun 17, 2026
Jul 12, 2023
N/A· v4
6.1 MEDIUM· v3
5.0 MEDIUM· v2
A vulnerability has been found in khodakhah NodCMS 3.4.1 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /en/blog-comment-4 of the component POST Request Handler. The...Show more
A vulnerability has been found in khodakhah NodCMS 3.4.1 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /en/blog-comment-4 of the component POST Request Handler. The manipulation of the argument comment_name/comment_content leads to cross site scripting. The attack can be launched remotely. The associated identifier of this vulnerability is VDB-233887.Show less
1Simple Online Piggery Management System Project
1Simple Online Piggery Management System
Jun 17, 2026
Jul 12, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Online Piggery Management System 1.0 is vulnerable to Cross Site Scripting (XSS). An unauthenticated user can POST JavaScript code to "manage-breed.php" resulting in Persistent XSS.
1Jetbrains
1Teamcity
Jun 17, 2026
Jul 12, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2023.05.1 reflected XSS via the Referer header was possible during artifact downloads
1Jetbrains
1Teamcity
Jun 17, 2026
Jul 12, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2023.05.1 stored XSS while viewing the build log was possible
1Jetbrains
1Teamcity
Jun 17, 2026
Jul 12, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2023.05.1 stored XSS while running custom builds was possible
1Jetbrains
1Teamcity
Jun 17, 2026
Jul 12, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2023.05.1 stored XSS when using a custom theme was possible
1Wpmaniax
1About Me 3000
Jun 17, 2026
Jul 12, 2023
N/A· v4
4.8 MEDIUM· v3
N/A· v2
The About Me 3000 widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 2.2.6 due to insufficient input sanitization and output escaping. This makes...Show more
The About Me 3000 widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 2.2.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.Show less
1Wp Reroute Email Project
1Wp Reroute Email
Jun 17, 2026
Jul 12, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
The WP Reroute Email plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an email subject in versions up to, and including, 1.4.9 due to insufficient input sanitization and output escaping. This makes i...Show more
The WP Reroute Email plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an email subject in versions up to, and including, 1.4.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.Show less
1Webdesignmunich
1Mail Queue
Jun 17, 2026
Jul 12, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
The Mail Queue plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an email subject in versions up to, and including, 1.1 due to insufficient input sanitization and output escaping. This makes it possib...Show more
The Mail Queue plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an email subject in versions up to, and including, 1.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.Show less
1Lanacodes
1Lana Email Logger
Jun 17, 2026
Jul 12, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
The Lana Email Logger plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an email subject in versions up to, and including, Lana Email Logger due to insufficient input sanitization and output escaping....Show more
The Lana Email Logger plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an email subject in versions up to, and including, Lana Email Logger due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.Show less
1Instareza
1Mail Control
Jun 17, 2026
Jul 12, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
The Mail Control plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an email subject in versions up to, and including, 0.2.8 due to insufficient input sanitization and output escaping. This makes it po...Show more
The Mail Control plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an email subject in versions up to, and including, 0.2.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.Show less
1Oacstudio
1Mailtree Log Mail
Jun 17, 2026
Jul 12, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
The Mailtree Log Mail plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an email subject in versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping. This makes...Show more
The Mailtree Log Mail plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an email subject in versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.Show less
1Dev4press
1Gd Mail Queue
Jun 17, 2026
Jul 12, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
The GD Mail Queue plugin for WordPress is vulnerable to Stored Cross-Site Scripting via email contents in versions up to, and including, 3.9.3 due to insufficient input sanitization and output escaping. This makes it pos...Show more
The GD Mail Queue plugin for WordPress is vulnerable to Stored Cross-Site Scripting via email contents in versions up to, and including, 3.9.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.Show less
1Yaycommerce
1Yaysmtp
Jun 17, 2026
Jul 12, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
The YaySMTP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via email contents in versions up to, and including, 2.4.5 due to insufficient input sanitization and output escaping. This makes it possible...Show more
The YaySMTP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via email contents in versions up to, and including, 2.4.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.Show less