CWE-79
47,150 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (47,150)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The Hueman Addons WordPress plugin through 2.3.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the con...Show more |
1Bootstrap Shortcodes Project 1Bootstrap Shortcodes Jun 17, 2026 Feb 21, 2023 N/A· v4 5.4 MEDIUM· v3 N/A· v2 The Bootstrap Shortcodes WordPress plugin through 3.4.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with...Show more |
1Easy Social Box Project 1Easy Social Box Jun 17, 2026 Feb 21, 2023 N/A· v4 5.4 MEDIUM· v3 N/A· v2 The Easy Social Box / Page Plugin WordPress plugin through 4.1.2 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow us...Show more |
1Opening Hours Project 1Opening Hours Jun 17, 2026 Feb 21, 2023 N/A· v4 5.4 MEDIUM· v3 N/A· v2 The Opening Hours WordPress plugin through 2.3.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the con...Show more |
2Blueastral Livecomposerplugin2Page Builder\ Page Builder\Jun 17, 2026 Feb 21, 2023 N/A· v4 5.4 MEDIUM· v3 N/A· v2 The Page Builder: Live Composer WordPress plugin before 1.5.23 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow user...Show more |
The Spectra WordPress plugin before 1.15.0 does not sanitize user input as it reaches its style HTML attribute, allowing contributors to conduct stored XSS attacks via the plugin's Gutenberg blocks. |
1Cention Chatserver Project 1Cention Chatserver Nov 21, 2024 Feb 21, 2023 N/A· v4 6.1 MEDIUM· v3 4.0 MEDIUM· v2 A vulnerability was found in cention-chatserver 3.8.0-rc1. It has been declared as problematic. Affected by this vulnerability is the function _formatBody of the file lib/InternalChatProtocol.fe. The manipulation of the...Show more |
JD-GUI 1.6.6 allows XSS via util/net/InterProcessCommunicationUtil.java. |
Erxes, an experience operating system (XOS) with a set of plugins, is vulnerable to cross-site scripting in versions 0.22.3 and prior. This results in client-side code execution. The victim must follow a malicious link o...Show more |
Countly, a product analytics solution, is vulnerable to cross-site scripting prior to version 21.11 of the community edition. The victim must follow a malicious link or be redirected there from malicious web site. The at...Show more |
Mind-elixir is a free, open source mind map core. Prior to version 0.18.1, mind-elixir is prone to cross-site scripting when handling untrusted menus. This issue is patched in version 0.18.1 |
1Jquery Minicolors Project 1Jquery Minicolors Jun 17, 2026 Feb 20, 2023 N/A· v4 6.1 MEDIUM· v3 N/A· v2 jQuery MiniColors is a color picker built on jQuery. Prior to version 2.3.6, jQuery MiniColors is prone to cross-site scripting when handling untrusted color names. This issue is patched in version 2.3.6. |
1Metaphorcreations 1Post Duplicator Nov 21, 2024 Feb 20, 2023 N/A· v4 6.1 MEDIUM· v3 4.0 MEDIUM· v2 A vulnerability was found in meta4creations Post Duplicator Plugin 2.18 on WordPress. It has been classified as problematic. Affected is the function mtphr_post_duplicator_notice of the file includes/notices.php. The man...Show more |
1Generator Hottowel Project 1Generator Hottowel Nov 21, 2024 Feb 20, 2023 N/A· v4 6.1 MEDIUM· v3 4.0 MEDIUM· v2 A vulnerability, which was classified as problematic, was found in generator-hottowel 0.0.11. Affected is an unknown function of the file app/templates/src/server/_app.js of the component 404 Error Handler. The manipulat...Show more |
A vulnerability was found in NREL api-umbrella-web 0.7.1. It has been classified as problematic. This affects an unknown part of the component Admin Data Table Handler. The manipulation leads to cross site scripting. It...Show more |
A vulnerability was found in qt-users-jp silk 0.0.1. It has been declared as problematic. This vulnerability affects unknown code of the file contents/root/examples/header.qml. The manipulation of the argument model.key/...Show more |
1Buddystream Project 1Buddystream Nov 21, 2024 Feb 19, 2023 N/A· v4 6.1 MEDIUM· v3 4.0 MEDIUM· v2 A vulnerability was found in madgicweb BuddyStream Plugin up to 3.2.7 on WordPress. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file ShareBox.php. The manipulati...Show more |
1Simple Food Ordering System Project 1Simple Food Ordering System Jun 17, 2026 Feb 18, 2023 N/A· v4 5.4 MEDIUM· v3 4.0 MEDIUM· v2 A vulnerability was found in SourceCodester Simple Food Ordering System 1.0. It has been classified as problematic. This affects an unknown part of the file process_order.php. The manipulation of the argument order leads...Show more |
1Intern Record System Project 1Intern Record System Jun 17, 2026 Feb 18, 2023 N/A· v4 5.4 MEDIUM· v3 N/A· v2 Cross Site Scripting (XSS) vulnerability in Intern Record System version 1.0 in /intern/controller.php in 'name' and 'email' parameters, allows attackers to execute arbitrary code. |
2Changedetection Webtechnologies2Changedetection ChangedetectionJun 17, 2026 Feb 17, 2023 N/A· v4 5.4 MEDIUM· v3 N/A· v2 Changedetection.io before v0.40.1.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the main page. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted...Show more |