← Back
CWE-79

47,142 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (47,142)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Fullworksplugins
1Quick Event Manager
Jun 17, 2026
Mar 28, 2023
N/A· v4
4.8 MEDIUM· v3
N/A· v2
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Fullworks Quick Event Manager plugin <= 9.6.4 versions.
1Wpdarko
1Responsive Pricing Table
Jun 17, 2026
Mar 28, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in WP Darko Responsive Pricing Table plugin <= 5.1.6 versions.
1Themeisle
1Visualizer
Jun 17, 2026
Mar 28, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Themeisle Visualizer: Tables and Charts Manager for WordPress plugin <= 3.9.1 versions.
1Oxilab
1Image Hover Effects For Elementor With Lightbox And Flipbox
Jun 17, 2026
Mar 28, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in biplob018 Image Hover Effects for Elementor with Lightbox and Flipbox plugin <= 2.8 versions.
1Liquidweb
1Wpcomplete
Jun 17, 2026
Mar 28, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in iThemes WPComplete plugin <= 2.9.2 versions.
1Thoughtworks
1Gocd
Jun 17, 2026
Mar 27, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
GoCD is an open source continuous delivery server. GoCD versions before 23.1.0 are vulnerable to a stored XSS vulnerability, where pipeline configuration with a malicious pipeline label configuration can affect browser d...Show more
GoCD is an open source continuous delivery server. GoCD versions before 23.1.0 are vulnerable to a stored XSS vulnerability, where pipeline configuration with a malicious pipeline label configuration can affect browser display of pipeline runs generated from that configuration. An attacker that has permissions to configure GoCD pipelines could include JavaScript elements within the label template, causing a XSS vulnerability to be triggered for any users viewing the Value Stream Map or Job Details for runs of the affected pipeline, potentially allowing them to perform arbitrary actions within the victim's browser context rather than their own. This issue has been fixed in GoCD 23.1.0. Users are advised to upgrade. There are no known workarounds for this vulnerability.Show less
1Adobe
2Commerce
Magento Open Source
Jun 17, 2026
Mar 27, 2023
N/A· v4
4.8 MEDIUM· v3
N/A· v2
Adobe Commerce versions 2.4.4-p2 (and earlier) and 2.4.5-p1 (and earlier) are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to inject malicious scripts i...Show more
Adobe Commerce versions 2.4.4-p2 (and earlier) and 2.4.5-p1 (and earlier) are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.Show less
1Sauter Controls
1Ey As525f001 Firmware
Jun 17, 2026
Mar 27, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
A malicious user could leverage this vulnerability to escalate privileges or perform unauthorized actions in the context of the targeted privileged users.
1Sauter Controls
1Ey As525f001 Firmware
Jun 17, 2026
Mar 27, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
An unauthenticated remote attacker could provide a malicious link and trick an unsuspecting user into clicking on it. If clicked, the attacker could execute the malicious JavaScript (JS) payload in the target’s security...Show more
An unauthenticated remote attacker could provide a malicious link and trick an unsuspecting user into clicking on it. If clicked, the attacker could execute the malicious JavaScript (JS) payload in the target’s security context.Show less
1Sauter Controls
1Ey As525f001 Firmware
Jun 17, 2026
Mar 27, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
An unauthenticated remote attacker could force all authenticated users, such as administrative users, to perform unauthorized actions by viewing the logs. This action would also grant the attacker privilege escalation.
1File Management System Project
1File Management System
Jun 17, 2026
Mar 27, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
A cross-site scripting (XSS) vulnerability in File Management Project 1.0.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field under the Edit User module.
1Water Billing System Project
1Water Billing System
Jun 17, 2026
Mar 27, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
SourceCodester Water Billing System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the lastname text box under the Add Client module.
1Jetbrains
1Teamcity
Jun 17, 2026
Mar 27, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2022.10.3 stored XSS on the SSH keys page was possible
1Jetbrains
1Teamcity
Jun 17, 2026
Mar 27, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2022.10.3 stored XSS on “Pending changes” and “Changes” tabs was possible
1Simplefilelist
1Simple File List
Jun 17, 2026
Mar 27, 2023
N/A· v4
4.8 MEDIUM· v3
N/A· v2
The Simple File List WordPress plugin before 6.0.10 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unf...Show more
The Simple File List WordPress plugin before 6.0.10 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).Show less
1Jetbrains
1Hub
Jun 17, 2026
Mar 27, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
In JetBrains Hub before 2022.3.15573, 2022.2.15572, 2022.1.15583 reflected XSS in dashboards was possible
1Jetbrains
1Teamcity
Jun 17, 2026
Mar 27, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2022.10.3 stored XSS in Perforce connection settings was possible
1Wpsoul
1Greenshift
Jun 17, 2026
Mar 27, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Auth. (author+) Cross-Site Scripting (XSS) vulnerability in Wpsoul Greenshift – animation and page builder blocks plugin <= 4.9.9 versions.
1Contempothemes
1Real Estate 7
Jun 17, 2026
Mar 27, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Contempoinc Real Estate 7 WordPress theme <= 3.3.1 versions.
1Phpgurukul
1Park Ticketing Management System
Jun 17, 2026
Mar 27, 2023
N/A· v4
4.8 MEDIUM· v3
N/A· v2
Phpgurukul Park Ticketing Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via the Admin Name parameter.