CWE-79
47,036 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (47,036)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Janobe 1Life Insurance Management System Jun 17, 2026 Jun 8, 2023 N/A· v4 6.1 MEDIUM· v3 4.0 MEDIUM· v2 A vulnerability was found in SourceCodester Life Insurance Management System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file insertNominee.php of the compo...Show more |
1Ibm 1Sterling Partner Engagement Manager Jun 17, 2026 Jun 8, 2023 N/A· v4 5.4 MEDIUM· v3 N/A· v2 IBM Sterling Partner Engagement Manager 6.1, 6.2, and 6.2.1 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functi...Show more |
1Ibm 1Sterling Partner Engagement Manager Jun 17, 2026 Jun 8, 2023 N/A· v4 5.4 MEDIUM· v3 N/A· v2 IBM Sterling Partner Engagement Manager 6.1, 6.2, and 6.2.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality...Show more |
1Ibm 2Cics Tx Txseries For MultiplatformJun 17, 2026 Jun 8, 2023 N/A· v4 5.4 MEDIUM· v3 N/A· v2 IBM TXSeries for Multiplatforms 8.1, 8.2, 9.1, CICS TX Standard, 11.1, CICS TX Advanced 10.1, and 11.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web...Show more |
Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability |
An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.8 before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. A reflected XSS was p...Show more |
An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. A specially crafted merge request could lead to a stored XSS on the c...Show more |
1Razormist 1Online Discussion Forum Site Jun 17, 2026 Jun 7, 2023 N/A· v4 5.4 MEDIUM· v3 4.0 MEDIUM· v2 A vulnerability classified as problematic was found in SourceCodester Online Discussion Forum Site 1.0. Affected by this vulnerability is an unknown functionality of the file admin\posts\manage_post.php. The manipulation...Show more |
1Razormist 1Online Discussion Forum Site Jun 17, 2026 Jun 7, 2023 N/A· v4 5.4 MEDIUM· v3 4.0 MEDIUM· v2 A vulnerability classified as problematic has been found in SourceCodester Online Discussion Forum Site 1.0. Affected is an unknown function of the file admin\posts\manage_post.php. The manipulation of the argument conte...Show more |
Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 2.0. |
The 10Web Photo Gallery plugin through 1.5.69 for WordPress allows XSS via theme_id for bwg_frontend_data. NOTE: other parameters are covered by CVE-2021-24291, CVE-2021-25041, and CVE-2021-31693. |
1Webdevocean 1Wp Quick Frontend Editor Jun 17, 2026 Jun 7, 2023 N/A· v4 5.4 MEDIUM· v3 N/A· v2 The WP Quick FrontEnd Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.5 due to insufficient input sanitization and output escaping. This makes it possible for...Show more |
1Rightpress 1Woocommerce Dynamic Pricing And Discounts Jun 17, 2026 Jun 7, 2023 N/A· v4 6.1 MEDIUM· v3 N/A· v2 The WooCommerce Dynamic Pricing and Discounts plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.4.1. This is due to missing sanitization on the settings imported via th...Show more |
The Flo Forms – Easy Drag & Drop Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Options Change by using the flo_import_forms_options AJAX action in versions up to, and including, 1.0.3...Show more |
1Najeebmedia 1Frontend File Manager Plugin Jun 17, 2026 Jun 7, 2023 N/A· v4 6.1 MEDIUM· v3 N/A· v2 The Frontend File Manager plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting in versions up to, and including, 18.2. This is due to lacking authentication protections and santisation all on...Show more |
1Webdevocean 1Wp Quick Frontend Editor Jun 17, 2026 Jun 7, 2023 N/A· v4 6.1 MEDIUM· v3 N/A· v2 The WP Quick FrontEnd Editor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 5.5 due to insufficient input sanitization and output escaping on the 'save_content_fron...Show more |
The WP DSGVO Tools (GDPR) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an unknown parameter in versions up to, and including, 3.1.23 due to insufficient input sanitization and output escaping. Th...Show more |
1Wpdesk 2Flexible Checkout Fields Flexible Checkout Fields For WoocommerceJun 17, 2026 Jun 7, 2023 N/A· v4 6.1 MEDIUM· v3 N/A· v2 The Flexible Checkout Fields for WooCommerce plugin for WordPress is vulnerable to Unauthenticated Arbitrary Plugin Settings update, in addition to Stored Cross-Site Scripting in versions up to, and including, 2.3.1. Th...Show more |
1Visualcomposer 1Visual Composer Website Builder Jun 17, 2026 Jun 7, 2023 N/A· v4 4.8 MEDIUM· v3 N/A· v2 The Visual Composer plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 26.0 due to insufficient input sanitization and output escaping. This makes it possible for attackers to in...Show more |
The Avada theme for WordPress is vulnerable to Stored Cross-Site Scripting via the update_layout function in versions up to, and including, 6.2.3 due to insufficient input sanitization and output escaping. This makes it...Show more |