← Back
CWE-79

47,152 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (47,152)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Zohocorp
1Manageengine Servicedesk Plus
Jun 17, 2026
Feb 1, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Cross site scripting (XSS) vulnerability in Zoho ManageEngine ServiceDesk Plus 14 via embedding videos in the language component.
1Zohocorp
1Manageengine Servicedesk Plus
Jun 17, 2026
Feb 1, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Cross site scripting (XSS) vulnerability in Zoho ManageEngine ServiceDesk Plus 14 via PO in the purchase component.
1Keking
1Kkfileview
Jun 17, 2026
Feb 1, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
kkFileView v4.1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the url parameter at /controller/OnlinePreviewController.java.
1Ibm
1Infosphere Information Server
Jun 17, 2026
Feb 1, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading...Show more
IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 243161.Show less
1Microweber
1Microweber
Jun 17, 2026
Feb 1, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Cross-site Scripting (XSS) - DOM in GitHub repository microweber/microweber prior to 1.3.2.
1Projectsend
1Projectsend
Jun 17, 2026
Feb 1, 2023
N/A· v4
4.8 MEDIUM· v3
N/A· v2
Cross-site Scripting (XSS) - Stored in GitHub repository projectsend/projectsend prior to r1606.
1Eta.js
1Eta
Jun 17, 2026
Feb 1, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Eta is an embedded JS templating engine that works inside Node, Deno, and the browser. XSS attack - anyone using the Express API is impacted. The problem has been resolved. Users should upgrade to version 2.0.0. As a wor...Show more
Eta is an embedded JS templating engine that works inside Node, Deno, and the browser. XSS attack - anyone using the Express API is impacted. The problem has been resolved. Users should upgrade to version 2.0.0. As a workaround, don't pass user supplied things directly to `res.render`. Show less
1Ampache
1Ampache
Jun 17, 2026
Feb 1, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Cross-site Scripting (XSS) - Reflected in GitHub repository ampache/ampache prior to 5.5.7.
1Comfast Project
1Cf Wr623n Firmware
Jun 17, 2026
Jan 31, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
COMFAST (Shenzhen Sihai Zhonglian Network Technology Co., Ltd) CF-WR623N Router firmware V2.3.0.1 is vulnerable to Cross Site Scripting (XSS).
1Comfast Project
1Cf Wr623n Firmware
Jun 17, 2026
Jan 31, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
COMFAST (Shenzhen Sihai Zhonglian Network Technology Co., Ltd) CF-WR623N Router firmware V2.3.0.1 is vulnerable to Cross Site Scripting (XSS) via the URL filtering feature in the router.
1Joplin Project
1Joplin
Jun 17, 2026
Jan 31, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Cross Site Scripting vulnerability in Joplin Desktop App before v2.9.17 allows attacker to execute arbitrary code via improper santization.
1Jsuites
1Jsuites
Jun 17, 2026
Jan 31, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Versions of the package jsuites before 5.0.1 are vulnerable to Cross-site Scripting (XSS) due to improper user-input sanitization in the Editor() function.
1Octopus
1Octopus Server
Jun 17, 2026
Jan 31, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
In affected versions of Octopus Server the help sidebar can be customized to include a Cross-Site Scripting payload in the support link. This was initially resolved in advisory 2022-07 however it was identified that the...Show more
In affected versions of Octopus Server the help sidebar can be customized to include a Cross-Site Scripting payload in the support link. This was initially resolved in advisory 2022-07 however it was identified that the fix could be bypassed in certain circumstances. A different approach was taken to prevent the possibility of the support link being susceptible to XSSShow less
1Apollotheme
1Ap Pagebuilder
Jul 9, 2026
Jan 31, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
A cross-site scripting (XSS) vulnerability in ApolloTheme AP PageBuilder component through 2.4.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the show_number parameter.
1Shapedplugin
1Smart Post Show
Jun 17, 2026
Jan 30, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
The Post Grid, Post Carousel, & List Category Posts WordPress plugin before 2.4.19 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could a...Show more
The Post Grid, Post Carousel, & List Category Posts WordPress plugin before 2.4.19 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.Show less
1Machothemes
1Cpo Companion
Jun 17, 2026
Jan 30, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
The CPO Companion WordPress plugin before 1.1.0 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform...Show more
The CPO Companion WordPress plugin before 1.1.0 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.Show less
1Solwininfotech
1Blog Designer
Jun 17, 2026
Jan 30, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
The Blog Designer WordPress plugin before 2.4.1 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.
1Themify
1Shortcodes
Jun 17, 2026
Jan 30, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Themify Shortcodes WordPress plugin before 2.0.8 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.
1Pwrplugins
1Portfolio For Elementor
Jun 17, 2026
Jan 30, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
The Portfolio for Elementor WordPress plugin before 2.3.1 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor t...Show more
The Portfolio for Elementor WordPress plugin before 2.3.1 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.Show less
1Infornweb
1Posts List Designer
Jun 17, 2026
Jan 30, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
The Posts List Designer by Category WordPress plugin before 3.2 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contrib...Show more
The Posts List Designer by Category WordPress plugin before 3.2 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.Show less