← Back
CWE-79

46,995 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (46,995)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Yaycommerce
1Yaysmtp
Jun 17, 2026
Jul 12, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
The YaySMTP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via email contents in versions up to, and including, 2.4.5 due to insufficient input sanitization and output escaping. This makes it possible...Show more
The YaySMTP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via email contents in versions up to, and including, 2.4.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.Show less
1Photoboxone
1Smtp Mail
Jun 17, 2026
Jul 12, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
The SMTP Mail plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an email subject in versions up to, and including, 1.3.46 due to insufficient input sanitization and output escaping when the 'Save Data...Show more
The SMTP Mail plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an email subject in versions up to, and including, 1.3.46 due to insufficient input sanitization and output escaping when the 'Save Data SendMail' feature is enabled. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.Show less
1Wpvibes
1Wp Mail Log
Jun 17, 2026
Jul 12, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
The WP Mail Log plugin for WordPress is vulnerable to Stored Cross-Site Scripting via email contents in versions up to, and including, 1.1.1 due to insufficient input sanitization and output escaping. This makes it possi...Show more
The WP Mail Log plugin for WordPress is vulnerable to Stored Cross-Site Scripting via email contents in versions up to, and including, 1.1.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.Show less
1Wpmanageninja
1Fluentsmtp
Jun 17, 2026
Jul 12, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
The FluentSMTP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an email subject in versions up to, and including, 2.2.4 due to insufficient input sanitization and output escaping. This makes it poss...Show more
The FluentSMTP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an email subject in versions up to, and including, 2.2.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.Show less
1Wpexperts
1Post Smtp
Jun 17, 2026
Jul 12, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
The Post SMTP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via email contents in versions up to, and including, 2.5.7 due to insufficient input sanitization and output escaping. This makes it possibl...Show more
The Post SMTP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via email contents in versions up to, and including, 2.5.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.Show less
1Awesomemotive
1Wp Mail Logging
Jun 17, 2026
Jul 12, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
The WP Mail Logging plugin for WordPress is vulnerable to Stored Cross-Site Scripting via email contents in versions up to, and including, 1.11.1 due to insufficient input sanitization and output escaping. This makes it...Show more
The WP Mail Logging plugin for WordPress is vulnerable to Stored Cross-Site Scripting via email contents in versions up to, and including, 1.11.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Note: An incomplete fix was released in 1.11.1.Show less
1Jamesward
1Wp Mail Catcher
Jun 17, 2026
Jul 12, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
The WP Mail Catcher plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an email subject in versions up to, and including, 2.1.2 due to insufficient input sanitization and output escaping. This makes it...Show more
The WP Mail Catcher plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an email subject in versions up to, and including, 2.1.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.Show less
1Advcomsys
1Onevote!
Jun 17, 2026
Jul 11, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in advcomsys.com oneVote component for Joomla. It allows XSS Targeting Non-Script Elements.
1Pimcore
1Admin Classic Bundle
Jun 17, 2026
Jul 11, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Pimcore Admin Classic Bundle provides a Backend UI for Pimcore based on the ExtJS framework. An admin who has not setup two factor authentication before is vulnerable for this attack, without need for any form of privile...Show more
Pimcore Admin Classic Bundle provides a Backend UI for Pimcore based on the ExtJS framework. An admin who has not setup two factor authentication before is vulnerable for this attack, without need for any form of privilege, causing the application to execute arbitrary scripts/HTML content. This vulnerability has been patched in version 1.0.3.Show less
1Microsoft
1Dynamics 365
Jun 17, 2026
Jul 11, 2023
N/A· v4
8.2 HIGH· v3
N/A· v2
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
1Decidim
1Decidim
Jun 17, 2026
Jul 11, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Decidim is a participatory democracy framework, written in Ruby on Rails, originally developed for the Barcelona City government online and offline participation website. The processes filter feature is susceptible to Cr...Show more
Decidim is a participatory democracy framework, written in Ruby on Rails, originally developed for the Barcelona City government online and offline participation website. The processes filter feature is susceptible to Cross-site scripting. This allows a remote attacker to execute JavaScript code in the context of a currently logged-in user. An attacker could use this vulnerability to make other users endorse or support proposals they have no intention of supporting or endorsing. The problem was patched in version 0.27.3 and 0.26.7. Show less
1Microsoft
1Dynamics 365
Jun 17, 2026
Jul 11, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
1Microsoft
1Sharepoint Server
Jun 17, 2026
Jul 11, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
Microsoft SharePoint Server Spoofing Vulnerability
1Decidim
1Decidim
Jun 17, 2026
Jul 11, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Decidim is a participatory democracy framework, written in Ruby on Rails, originally developed for the Barcelona City government online and offline participation website. The external link feature is susceptible to cross...Show more
Decidim is a participatory democracy framework, written in Ruby on Rails, originally developed for the Barcelona City government online and offline participation website. The external link feature is susceptible to cross-site scripting. This allows a remote attacker to execute JavaScript code in the context of a currently logged-in user. An attacker could use this vulnerability to make other users endorse or support proposals they have no intention of supporting or endorsing. The problem was patched in versions 0.27.3 and 0.26.7.Show less
1Microsoft
1Windows Admin Center
Jun 17, 2026
Jul 11, 2023
N/A· v4
6.8 MEDIUM· v3
N/A· v2
Windows Admin Center Spoofing Vulnerability
1Tarteaucitron
1Tarteaucitron
Jun 17, 2026
Jul 11, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Cross-site Scripting (XSS) - Stored in GitHub repository amauric/tarteaucitron.js prior to v1.13.1.
1Fastposter
1Fast Poster
Jun 17, 2026
Jul 11, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
fast-poster v2.15.0 is vulnerable to Cross Site Scripting (XSS). File upload check binary of img, but without strictly check file suffix at /server/fast.py -> ApiUploadHandler.post causes stored XSS
1Lm21
1Twonav
Jun 17, 2026
Jul 11, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
TwoNav v2.0.28-20230624 is vulnerable to Cross Site Scripting (XSS).
1Buildagate Project
1Buildagate
Jun 17, 2026
Jul 11, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Cross Site Scripting vulnerability in IP-DOT BuildaGate v.BuildaGate5 allows a remote attacker to execute arbitrary code via a crafted script to the mc parameter of the URL.
1Rockwellautomation
1Powermonitor 1000 Firmware
Jun 17, 2026
Jul 11, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
The Rockwell Automation PowerMonitor 1000 contains stored cross-site scripting vulnerabilities within the web page of the product.  The vulnerable pages do not require privileges to access and can be injected with code b...Show more
The Rockwell Automation PowerMonitor 1000 contains stored cross-site scripting vulnerabilities within the web page of the product.  The vulnerable pages do not require privileges to access and can be injected with code by an attacker which could be used to leverage an attack on an authenticated user resulting in remote code execution and potentially the complete loss of confidentiality, integrity, and availability of the product. Show less