CWE-79
47,011 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (47,011)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in GalleryPlugins Video Contest plugin <= 3.2 versions. |
1Wp Copyprotect Project 1Wp Copyprotect Nov 21, 2024 Jun 12, 2023 N/A· v4 6.1 MEDIUM· v3 4.0 MEDIUM· v2 A vulnerability classified as problematic was found in cchetanonline WP-CopyProtect up to 3.0.0. This vulnerability affects the function CopyProtect_options_page of the file wp-copyprotect.php. The manipulation of the ar...Show more |
The Danfoss AK-EM100 web applications allow for Reflected Cross-Site Scripting in the title parameter. |
The Danfoss AK-EM100 web applications allow for Reflected Cross-Site Scripting. |
Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.9. |
Pega Platform versions 7.2 to 8.8.1 are affected by an XSS issue. |
A Cross Site Scripting (XSS) vulnerability in D-Link DI-7500G-CI-19.05.29A allows attackers to execute arbitrary code via uploading a crafted HTML file to the interface /auth_pic.cgi. |
Cross Site Scripting vulnerability found in Vade Secure Gateway allows a remote attacker to execute arbitrary code via the username, password, and language cookies parameter. |
Cross Site Scripting vulnerability found in Vade Secure Gateway allows a remote attacker to execute arbitrary code via a crafted payload to the GET request after the /css/ directory. |
@udecode/plate-link is the link handler for the udecode/plate rich-text editor plugin system for Slate & React. Affected versions of the link plugin and link UI component do not sanitize URLs to prevent use of the `javas...Show more |
Cross Site Scripting vulnerability found in Vade Secure Gateway allows a remote attacker to execute arbitrary code via a crafted payload to the X-Rewrite-URL parameter. |
Vault and Vault Enterprise's (Vault) key-value v2 (kv-v2) diff viewer allowed HTML injection into the Vault web UI through key values. This vulnerability, CVE-2023-2121, is fixed in Vault 1.14.0, 1.13.3, 1.12.7, and 1.11...Show more |
1Sales Tracker Management System Project 1Sales Tracker Management System Jun 17, 2026 Jun 9, 2023 N/A· v4 4.8 MEDIUM· v3 3.3 LOW· v2 A vulnerability was found in SourceCodester Sales Tracker Management System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /classes/Users.php?f=save. The manipulat...Show more |
1Performance Indicator System Project 1Performance Indicator System Jun 17, 2026 Jun 9, 2023 N/A· v4 5.4 MEDIUM· v3 4.0 MEDIUM· v2 A vulnerability was found in SourceCodester Performance Indicator System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /admin/addproduct.php. The manipul...Show more |
1Iptanus 2Wordpress File Upload Wordpress File Upload ProJun 17, 2026 Jun 9, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 The WordPress File Upload and WordPress File Upload Pro plugins for WordPress are vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 4.19.1 due to insufficient input sanitizati...Show more |
1I13websolution 1Team Circle Image Slider With Lightbox Jun 17, 2026 Jun 9, 2023 N/A· v4 6.1 MEDIUM· v3 N/A· v2 The Team Circle Image Slider With Lightbox plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘search_term’ parameter in versions up to, and including, 1.0.17 due to insufficient input sanitizat...Show more |
1Pixelyoursite 2Pixelyoursite Pixelyoursite ProJun 17, 2026 Jun 9, 2023 N/A· v4 4.8 MEDIUM· v3 N/A· v2 The PixelYourSite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 9.3.6 (9.6.1 in the Pro version) due to insufficient input sanitization and output...Show more |
1Pluginus 1Wordpress Currency Switcher Professional Jun 17, 2026 Jun 9, 2023 N/A· v4 5.4 MEDIUM· v3 N/A· v2 The WPCS – WordPress Currency Switcher Professional plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpcs_current_currency shortcode in versions up to, and including, 1.1.9 due to insuff...Show more |
1Advanced Woo Search 1Advanced Woo Search Jun 17, 2026 Jun 9, 2023 N/A· v4 4.4 MEDIUM· v3 N/A· v2 The Advanced Woo Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 2.77 due to insufficient input sanitization and output escaping. This makes...Show more |
1I13websolution 1Photo Gallery Slideshow & Masonry Tiled Gallery Jun 17, 2026 Jun 9, 2023 N/A· v4 6.1 MEDIUM· v3 N/A· v2 The Photo Gallery Slideshow & Masonry Tiled Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the search_term parameter in versions up to, and including, 1.0.13 due to insufficient input sa...Show more |