CWE-79
47,088 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (47,088)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Artisanworkshop 1Japanized For Woocommerce Jun 17, 2026 May 8, 2023 N/A· v4 6.1 MEDIUM· v3 N/A· v2 The Japanized For WooCommerce WordPress plugin before 2.5.8 does not escape generated URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting |
1Blackbirdi 1Custom Post Type List Shortcode Jun 17, 2026 May 8, 2023 N/A· v4 5.4 MEDIUM· v3 N/A· v2 The Custom Post Type List Shortcode WordPress plugin through 1.4.4 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow...Show more |
1Membership Database Project 1Membership Database Jun 17, 2026 May 8, 2023 N/A· v4 6.1 MEDIUM· v3 N/A· v2 The Membership Database WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege...Show more |
1Topdigitaltrends 1Ultimate Carousel For Elementor Jun 17, 2026 May 8, 2023 N/A· v4 5.4 MEDIUM· v3 N/A· v2 The Ultimate Carousel For Elementor WordPress plugin through 2.1.7 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with...Show more |
Cross Site Scripting (XSS) pandao editor.md 1.5.0 allows attackers to execute arbitrary code via crafted linked url values. |
Cross-site scripting (XSS) vulnerability in NoneCms 1.3.0 allows remote attackers to inject arbitrary web script or HTML via feedback feature. |
Cross Site Scripting (XSS) vulnerability in MIPCMS 3.6.0 allows attackers to execute arbitrary code via the category name field to categoryEdit. |
1Easy Event Calendar Project 1Easy Event Calendar Jun 17, 2026 May 8, 2023 N/A· v4 4.8 MEDIUM· v3 N/A· v2 Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in CoreFortress Easy Event calendar plugin <= 1.0 versions. |
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Michael Pretty (prettyboymp) CMS Press plugin <= 0.2.3 versions. |
1Te St 1Yandex.news Feed By Teplitsa Jun 17, 2026 May 8, 2023 N/A· v4 4.8 MEDIUM· v3 N/A· v2 Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Teplitsa Yandex.News Feed by Teplitsa plugin <= 1.12.5 versions. |
Auth. (subscriber+) Stored Cross-Site Scripting (XSS) vulnerability in Martin Lees Exxp plugin <= 2.6.8 versions. |
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in FareHarbor FareHarbor for WordPress plugin <= 3.6.6 versions. |
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in GiveWP plugin <= 2.25.1 versions. |
1I13websolution 1Easy Testimonial Slider And Form Jun 17, 2026 May 8, 2023 N/A· v4 6.1 MEDIUM· v3 N/A· v2 Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in I Thirteen Web Solution Easy Testimonial Slider and Form plugin <= 1.0.15 versions. |
Task instance details page in the UI is vulnerable to a stored XSS.This issue affects Apache Airflow: before 2.6.0.
|
Cross-site Scripting (XSS) - Stored in GitHub repository openemr/openemr prior to 7.0.1. |
1Multi Language Hotel Management Software Project 1Multi Language Hotel Management Software Jun 17, 2026 May 7, 2023 N/A· v4 6.1 MEDIUM· v3 4.0 MEDIUM· v2 A vulnerability has been found in SourceCodester Multi Language Hotel Management Software 1.0 and classified as problematic. This vulnerability affects unknown code of the file ajax.php of the component POST Parameter Ha...Show more |
1Hu Manity 1Cookie Notice & Compliance For Gdpr / Ccpa Jun 17, 2026 May 7, 2023 N/A· v4 5.4 MEDIUM· v3 N/A· v2 Auth. (contributor+) Cross-Site Scripting (XSS) vulnerability in Hu-manity.Co Cookie Notice & Compliance for GDPR / CCPA plugin <= 2.4.6 versions. |
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Samuel Marshall JCH Optimize plugin <= 3.2.2 versions. |
1Newbinggogo Project 1Newbinggogo Jun 17, 2026 May 6, 2023 N/A· v4 6.1 MEDIUM· v3 4.0 MEDIUM· v2 A vulnerability was found in jja8 NewBingGoGo up to 2023.5.5.2. It has been rated as problematic. This issue affects some unknown processing. The manipulation leads to cross site scripting. The attack may be initiated re...Show more |