← Back
CWE-79

47,136 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (47,136)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1W3eden
1Download Manager
Jun 17, 2026
Apr 18, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in W3 Eden, Inc. Download Manager plugin <= 3.2.59 versions.
1Content Repeater Project
1Content Repeater
Jun 17, 2026
Apr 18, 2023
N/A· v4
4.8 MEDIUM· v3
N/A· v2
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Denis Buka Content Repeater – Custom Posts Simplified plugin <= 1.1.13 versions.
1Webhelpagency
1Wha Puzzle
Jun 17, 2026
Apr 18, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in WHA WHA Puzzle plugin <= 1.0.9 versions.
1Reputeinfosystems
1Arforms Form Builder
Jun 17, 2026
Apr 18, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Unauth. Stored Cross-Site Scripting (XSS) vulnerability in Repute InfoSystems ARForms Form Builder plugin <= 1.5.5 versions.
1Wp Clictracker Project
1Wp Clictracker
Jun 17, 2026
Apr 18, 2023
N/A· v4
4.8 MEDIUM· v3
N/A· v2
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Gus Sevilla WP Clictracker plugin <= 1.0.5 versions.
1Jbootfly Project
1Jbootfly
Jun 17, 2026
Apr 18, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Cross Site Scripting vulnerability found in Jbootfly allows attackers to obtain sensitive information via the username parameter.
1I13websolution
1Thumbnail Carousel Slider
Jun 17, 2026
Apr 18, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
The Thumbnail carousel slider plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the search_term parameter in versions up to, and including, 1.1.9 due to insufficient input sanitization and output e...Show more
The Thumbnail carousel slider plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the search_term parameter in versions up to, and including, 1.1.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.Show less
1I13websolution
1Responsive Filterable Portfolio
Jun 17, 2026
Apr 18, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
The Responsive Filterable Portfolio plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the search_term parameter in versions up to, and including, 1.0.19 due to insufficient input sanitization and o...Show more
The Responsive Filterable Portfolio plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the search_term parameter in versions up to, and including, 1.0.19 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.Show less
1Servicenow
1Servicenow
Jun 17, 2026
Apr 17, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
There exists a reflected XSS within the logout functionality of ServiceNow versions lower than Quebec Patch 10 Hotfix 11b, Rome Patch 10 Hotfix 3b, San Diego Patch 9, Tokyo Patch 4, and Utah GA. This enables an unauthent...Show more
There exists a reflected XSS within the logout functionality of ServiceNow versions lower than Quebec Patch 10 Hotfix 11b, Rome Patch 10 Hotfix 3b, San Diego Patch 9, Tokyo Patch 4, and Utah GA. This enables an unauthenticated remote attacker to execute arbitrary JavaScript code in the browser-based web console.Show less
1Yikesinc
1Easy Forms For Mailchimp
Jun 17, 2026
Apr 17, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
The Easy Forms for Mailchimp WordPress plugin before 6.8.7 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users wi...Show more
The Easy Forms for Mailchimp WordPress plugin before 6.8.7 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacksShow less
1W4 Post List Project
1W4 Post List
Jun 17, 2026
Apr 17, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
The W4 Post List WordPress plugin before 2.4.6 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role...Show more
The W4 Post List WordPress plugin before 2.4.6 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.Show less
1Timesheets For Jira
1Timesheet Tracking
Jun 17, 2026
Apr 17, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
The TouchDown Timesheet tracking component 4.1.4 for Jira allows XSS in the calendar view.
1Chatwoot
1Chatwoot
Jun 17, 2026
Apr 17, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Cross-site Scripting (XSS) - DOM in GitHub repository chatwoot/chatwoot prior to 2.14.0.
1Colorlib
1Activello Theme
Jun 17, 2026
Apr 16, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Auth. (subscriber+) Reflected Cross-Site Scripting (XSS) vulnerability in Silkalns Activello theme <= 1.4.4 versions.
1Bestwebsoft
1Car Rental
Jun 17, 2026
Apr 16, 2023
N/A· v4
4.8 MEDIUM· v3
N/A· v2
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in BestWebSoft Car Rental by BestWebSoft plugin <= 1.1.2 versions.
1Magneticlab
1Homepage Pop Up
Jun 17, 2026
Apr 16, 2023
N/A· v4
4.8 MEDIUM· v3
N/A· v2
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Magneticlab Sàrl Homepage Pop-up plugin <= 1.2.5 versions.
1Codetides
1Advanced Floating Content
Jun 17, 2026
Apr 16, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Auth. (contributor+) Cross-Site Scripting (XSS) vulnerability in Code Tides Advanced Floating Content plugin <= 1.2.1 versions.
1Xwiki
1Xwiki
Jun 17, 2026
Apr 16, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
XWiki Commons are technical libraries common to several other top level XWiki projects. A user without script rights can introduce a stored XSS by using the Live Data macro, if the last author of the content of the page...Show more
XWiki Commons are technical libraries common to several other top level XWiki projects. A user without script rights can introduce a stored XSS by using the Live Data macro, if the last author of the content of the page has script rights. This has been patched in XWiki 14.10, 14.4.7, and 13.10.11. Show less
1Xwiki
1Xwiki
Jun 17, 2026
Apr 16, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
XWiki Commons are technical libraries common to several other top level XWiki projects. It was possible to inject some code using the URL of authenticated endpoints. This problem has been patched on XWiki 13.10.11, 14.4....Show more
XWiki Commons are technical libraries common to several other top level XWiki projects. It was possible to inject some code using the URL of authenticated endpoints. This problem has been patched on XWiki 13.10.11, 14.4.7 and 14.10.Show less
1External Redirect Warning Project
1External Redirect Warning
Jun 17, 2026
Apr 16, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
In the External Redirect Warning Plugin 1.3 for MyBB, the redirect URL (aka external.php?url=) is vulnerable to XSS.