CWE-79
47,038 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (47,038)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The SEO by 10Web WordPress plugin before 1.2.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfilter...Show more |
The WP Multi Store Locator WordPress plugin through 2.4 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with...Show more |
DokuWiki before 2023-04-04a allows XSS via RSS titles. |
A vulnerability was found in Broken Link Checker Plugin up to 1.10.1 on WordPress. It has been declared as problematic. Affected by this vulnerability is the function options_page of the file core/core.php of the compone...Show more |
1Eelv Newsletter Project 1Eelv Newsletter Nov 21, 2024 Jun 4, 2023 N/A· v4 6.1 MEDIUM· v3 4.0 MEDIUM· v2 A vulnerability was found in EELV Newsletter Plugin 2.x on WordPress. It has been rated as problematic. Affected by this issue is the function style_newsletter of the file lettreinfo.php. The manipulation of the argument...Show more |
Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.9. |
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Kyle Maurer Don8 plugin <= 0.4 versions. |
A vulnerability, which was classified as problematic, has been found in X-WRT luci up to 22.10_b202303061504. This issue affects the function run_action of the file modules/luci-base/ucode/dispatcher.uc of the component...Show more |
Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.9. |
Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.9. |
1Vcita 2Event Registration Calendar By Vcita Online Payments Get Paid With Paypal, Square & StripeJun 17, 2026 Jun 3, 2023 N/A· v4 5.4 MEDIUM· v3 N/A· v2 The Event Registration Calendar By vcita plugin, versions up to and including 3.9.1, and Online Payments – Get Paid with PayPal, Square & Stripe plugin, for WordPress are vulnerable to Stored Cross-Site Scripting via the...Show more |
1Vcita 1Crm And Lead Management By Vcita Jun 17, 2026 Jun 3, 2023 N/A· v4 5.4 MEDIUM· v3 N/A· v2 The CRM and Lead Management by vcita plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'email' parameter in versions up to, and including, 2.6.2 due to insufficient input sanitization and output e...Show more |
1Vcita 1Contact Form And Calls To Action By Vcita Jun 17, 2026 Jun 3, 2023 N/A· v4 5.4 MEDIUM· v3 N/A· v2 The Contact Form and Calls To Action by vcita plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'email' parameter in versions up to, and including, 2.6.4 due to insufficient input sanitization and...Show more |
1Vcita 1Contact Form Builder By Vcita Jun 17, 2026 Jun 3, 2023 N/A· v4 5.4 MEDIUM· v3 N/A· v2 The Contact Form Builder by vcita plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'email' parameter in versions up to, and including, 4.9.1 due to insufficient input sanitization and output esca...Show more |
1Vcita 1Online Booking & Scheduling Calendar Jun 17, 2026 Jun 3, 2023 N/A· v4 6.1 MEDIUM· v3 N/A· v2 The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'business_id' parameter in versions up to, and including, 4.3.0 due to insufficien...Show more |
1Azexo 1Page Builder With Image Map By Azexo Jun 17, 2026 Jun 3, 2023 N/A· v4 5.4 MEDIUM· v3 N/A· v2 The Page Builder by AZEXO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'azh_post' shortcode in versions up to, and including, 1.27.133 due to insufficient input sanitization and output escaping....Show more |
eMedia Consulting simpleRedak up to v2.47.23.05 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /scheduler/index.php. |
eMedia Consulting simpleRedak up to v2.47.23.05 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /view/cb/format_642.php. |
Cross-site Scripting (XSS) - Stored in GitHub repository tsolucio/corebos prior to 8 via evvtgendoc. |
Cross-site Scripting (XSS) - Stored in GitHub repository tsolucio/corebos prior to 8. |