CWE-79
47,142 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (47,142)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Fullworksplugins 1Quick Event Manager Jun 17, 2026 Mar 28, 2023 N/A· v4 4.8 MEDIUM· v3 N/A· v2 Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Fullworks Quick Event Manager plugin <= 9.6.4 versions. |
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in WP Darko Responsive Pricing Table plugin <= 5.1.6 versions. |
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Themeisle Visualizer: Tables and Charts Manager for WordPress plugin <= 3.9.1 versions. |
1Oxilab 1Image Hover Effects For Elementor With Lightbox And Flipbox Jun 17, 2026 Mar 28, 2023 N/A· v4 6.1 MEDIUM· v3 N/A· v2 Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in biplob018 Image Hover Effects for Elementor with Lightbox and Flipbox plugin <= 2.8 versions. |
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in iThemes WPComplete plugin <= 2.9.2 versions. |
GoCD is an open source continuous delivery server. GoCD versions before 23.1.0 are vulnerable to a stored XSS vulnerability, where pipeline configuration with a malicious pipeline label configuration can affect browser d...Show more |
1Adobe 2Commerce Magento Open SourceJun 17, 2026 Mar 27, 2023 N/A· v4 4.8 MEDIUM· v3 N/A· v2 Adobe Commerce versions 2.4.4-p2 (and earlier) and 2.4.5-p1 (and earlier) are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to inject malicious scripts i...Show more |
1Sauter Controls 1Ey As525f001 Firmware Jun 17, 2026 Mar 27, 2023 N/A· v4 5.4 MEDIUM· v3 N/A· v2 A malicious user could leverage this vulnerability to escalate privileges or perform unauthorized actions in the context of the targeted privileged users. |
1Sauter Controls 1Ey As525f001 Firmware Jun 17, 2026 Mar 27, 2023 N/A· v4 6.1 MEDIUM· v3 N/A· v2 An unauthenticated remote attacker could provide a malicious link and trick an unsuspecting user into clicking on it. If clicked, the attacker could execute the malicious JavaScript (JS) payload in the target’s security...Show more |
1Sauter Controls 1Ey As525f001 Firmware Jun 17, 2026 Mar 27, 2023 N/A· v4 6.1 MEDIUM· v3 N/A· v2 An unauthenticated remote attacker could force all authenticated users, such as administrative users, to perform unauthorized actions by viewing the logs. This action would also grant the attacker privilege escalation. |
1File Management System Project 1File Management System Jun 17, 2026 Mar 27, 2023 N/A· v4 6.1 MEDIUM· v3 N/A· v2 A cross-site scripting (XSS) vulnerability in File Management Project 1.0.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field under the Edit User module. |
1Water Billing System Project 1Water Billing System Jun 17, 2026 Mar 27, 2023 N/A· v4 6.1 MEDIUM· v3 N/A· v2 SourceCodester Water Billing System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the lastname text box under the Add Client module. |
In JetBrains TeamCity before 2022.10.3 stored XSS on the SSH keys page was possible |
In JetBrains TeamCity before 2022.10.3 stored XSS on “Pending changes” and “Changes” tabs was possible |
The Simple File List WordPress plugin before 6.0.10 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unf...Show more |
In JetBrains Hub before 2022.3.15573, 2022.2.15572, 2022.1.15583 reflected XSS in dashboards was possible
|
In JetBrains TeamCity before 2022.10.3 stored XSS in Perforce connection settings was possible |
Auth. (author+) Cross-Site Scripting (XSS) vulnerability in Wpsoul Greenshift – animation and page builder blocks plugin <= 4.9.9 versions. |
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Contempoinc Real Estate 7 WordPress theme <= 3.3.1 versions. |
1Phpgurukul 1Park Ticketing Management System Jun 17, 2026 Mar 27, 2023 N/A· v4 4.8 MEDIUM· v3 N/A· v2 Phpgurukul Park Ticketing Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via the Admin Name parameter. |