← Back
CWE-79

47,152 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (47,152)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Youtube Shortcode Project
1Youtube Shortcode
Jun 17, 2026
Jan 23, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Auth. Stored Cross-Site Scripting (XSS) vulnerability in Youtube shortcode <= 1.8.5 versions.
1Oi Yandex.maps Project
1Oi Yandex.maps
Jun 17, 2026
Jan 23, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Auth. Stored Cross-Site Scripting (XSS) in Oi Yandex.Maps for WordPress <= 3.2.7 versions.
1My Youtube Channel Project
1My Youtube Channel
Jun 17, 2026
Jan 23, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
The My YouTube Channel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via its settings parameters in versions up to, and including, 3.0.12.1 due to insufficient input sanitization and output escaping....Show more
The My YouTube Channel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via its settings parameters in versions up to, and including, 3.0.12.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.Show less
1Hasthemes
1Hashbar
Jun 17, 2026
Jan 23, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
The HashBar WordPress plugin before 1.3.6 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.
1Sevenspark
1Shiftnav
Jun 17, 2026
Jan 23, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
The ShiftNav WordPress plugin before 1.7.2 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Store...Show more
The ShiftNav WordPress plugin before 1.7.2 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.Show less
1Onlyoffice
1Server
Jun 17, 2026
Jan 23, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
ONLYOFFICE all versions as of 2021-11-08 is vulnerable to Cross Site Scripting (XSS). The "macros" feature of the document editor allows malicious cross site scripting payloads to be used.
1Misp Project
2Malware Information Sharing Platform
Misp
Jun 23, 2026
Jan 23, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
app/View/AuthKeys/authkey_display.ctp in MISP through 2.4.167 has an XSS in authkey add via a Referer field.
2Misp
Misp Project
2Misp
Misp
Jun 22, 2026
Jan 20, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
In MISP 2.4.167, app/webroot/js/action_table.js allows XSS via a network history name.
1Misp Project
1Misp
Jun 17, 2026
Jan 20, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
In MISP 2.4.167, app/webroot/js/event-graph.js has an XSS vulnerability via an event-graph preview payload.
1Fullworksplugins
1Quick Event Manager
Jun 17, 2026
Jan 20, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
The Quick Event Manager WordPress Plugin, version < 9.7.5, is affected by a reflected cross-site scripting vulnerability in the 'category' parameter of its 'qem_ajax_calendar' action.
1Book Store Management System Project
1Book Store Management System
Jun 17, 2026
Jan 20, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Book Store Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in /bsms_ci/index.php/book. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafte...Show more
Book Store Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in /bsms_ci/index.php/book. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the writer parameter.Show less
1Kalkun Project
1Kalkun
Jun 17, 2026
Jan 20, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Cross Site Scripting (XSS) vulnerability in Kalkun 0.8.0 via username input in file User_model.php.
1Inventory System Project
1Inventory System
Jun 17, 2026
Jan 20, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Cross Site Scripting (XSS) vulnerability in InventorySystem thru commit e08fbbe17902146313501ed0b5feba81d58f455c (on Apr 23, 2021) via edit_store_name and edit_active inputs in file InventorySystem.php.
1Classroombookings
1Classroombookings
Jun 17, 2026
Jan 20, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Cross Site Scripting (XSS) vulnerability in craigrodway classroombookings 2.6.4 allows attackers to execute arbitrary code or other unspecified impacts via the input bgcol in file Weeks.php.
1Ecommerce Codeigniter Bootstrap Project
1Ecommerce Codeigniter Bootstrap
Jun 17, 2026
Jan 20, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Cross Site Scripting (XSS) vulnerability in Ecommerce-CodeIgniter-Bootstrap thru commit d5904379ca55014c5df34c67deda982c73dc7fe5 (on Dec 27, 2022), allows attackers to execute arbitrary code via the languages and trans_l...Show more
Cross Site Scripting (XSS) vulnerability in Ecommerce-CodeIgniter-Bootstrap thru commit d5904379ca55014c5df34c67deda982c73dc7fe5 (on Dec 27, 2022), allows attackers to execute arbitrary code via the languages and trans_load parameters in file add_product.php.Show less
1Left Project
1Left
Jun 17, 2026
Jan 20, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Cross site scripting (XSS) vulnerability in Hundredrabbits Left 7.1.5 for MacOS allows attackers to execute arbitrary code via the meta tag.
1Left Project
1Left
Jun 17, 2026
Jan 20, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Cross site scripting (XSS) vulnerability in Hundredrabbits Left 7.1.5 for MacOS allows attackers to execute arbitrary code via file names.
1Eyoucms
1Eyoucms
Jun 17, 2026
Jan 20, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
EyouCMS <= 1.6.0 was discovered a reflected-XSS in the FileManager component in GET parameter "filename" when editing any file.
1Eyoucms
1Eyoucms
Jun 17, 2026
Jan 20, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
EyouCMS <= 1.6.0 was discovered a reflected-XSS in the article attribute editor component in POST value "value" if the value contains a non-integer char.
1Eyoucms
1Eyoucms
Jun 17, 2026
Jan 20, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
EyouCMS <= 1.6.0 was discovered a reflected-XSS in article type editor component in POST value "name" if the value contains a malformed UTF-8 char.