CWE-79
47,294 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (47,294)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Abpressoptimizer 1Ab Press Optimizer Jun 17, 2026 Oct 17, 2022 N/A· v4 4.8 MEDIUM· v3 N/A· v2 Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Mammothology AB Press Optimizer plugin <= 1.1.1 on WordPress. |
A cross-site scripting issue has been discovered in GitLab CE/EE affecting all versions before 15.1.6, 15.2 to 15.2.4 and 15.3 prior to 15.3.2. It was possible to exploit a vulnerability in setting the labels colour feat...Show more |
An issue in Incident Timelines has been discovered in GitLab CE/EE affecting all versions starting from 14.9 before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2.whi...Show more |
A crafted tag in the Jupyter Notebook viewer in GitLab EE/CE affecting all versions before 15.1.6, 15.2 to 15.2.4, and 15.3 to 15.3.2 allows an attacker to issue arbitrary HTTP requests |
74cmsSE v3.12.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /apiadmin/notice/add. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payl...Show more |
1Oretnom23 1Simple Cold Storage Management System Jun 17, 2026 Oct 17, 2022 N/A· v4 4.8 MEDIUM· v3 N/A· v2 A vulnerability was found in SourceCodester Simple Cold Storage Management System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the component Add New Storage Handler. The manipulati...Show more |
1Simple Cold Storage Management System Project 1Simple Cold Storage Management System Jun 17, 2026 Oct 17, 2022 N/A· v4 4.8 MEDIUM· v3 N/A· v2 A vulnerability was found in SourceCodester Simple Cold Storage Management System 1.0. It has been classified as problematic. This affects an unknown part of the file /csms/admin/?page=system_info of the component Settin...Show more |
1Oretnom23 1Simple Cold Storage Management System Jun 17, 2026 Oct 17, 2022 N/A· v4 4.8 MEDIUM· v3 N/A· v2 A vulnerability was found in SourceCodester Simple Cold Storage Management System 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /csms/admin/?page=user/list of the com...Show more |
1Wp Custom Cursors Project 1Wp Custom Cursors Jun 17, 2026 Oct 17, 2022 N/A· v4 6.1 MEDIUM· v3 N/A· v2 The WP Custom Cursors WordPress plugin before 3.0.1 does not have CSRF check in place when creating and editing cursors, which could allow attackers to made a logged in admin perform such actions via CSRF attacks. Furthe...Show more |
The We’re Open! WordPress plugin before 1.42 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered...Show more |
The Meks Easy Social Share WordPress plugin before 1.2.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when th...Show more |
The Tutor LMS WordPress plugin before 2.0.10 does not escape some course parameters, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capab...Show more |
1Adobe 2Commerce Magento Open SourceJun 17, 2026 Oct 14, 2022 N/A· v4 5.4 MEDIUM· v3 N/A· v2 Adobe Commerce versions 2.4.4-p1 (and earlier) and 2.4.5 (and earlier) are affected by a Stored Cross-site Scripting vulnerability. Exploitation of this issue does not require user interaction and could result in a post-...Show more |
1Oretnom23 1Online Birth Certificate Management System Jun 17, 2026 Oct 14, 2022 N/A· v4 6.1 MEDIUM· v3 N/A· v2 Online Birth Certificate Management System version 1.0 suffers from a Cross Site Scripting (XSS) Vulnerability. |
1Oretnom23 1Online Birth Certificate Management System Jun 17, 2026 Oct 14, 2022 N/A· v4 5.4 MEDIUM· v3 N/A· v2 Online Birth Certificate Management System version 1.0 suffers from a persistent Cross Site Scripting (XSS) vulnerability. |
1Projectworlds 1Online Examination System Jun 17, 2026 Oct 14, 2022 N/A· v4 6.1 MEDIUM· v3 N/A· v2 Online Examination System version 1.0 suffers from a cross site scripting vulnerability via index.php. |
Cross-site Scripting (XSS) - Stored in GitHub repository barrykooij/related-posts-for-wp prior to 2.1.3. |
1Sanitization Management System Project 1Sanitization Management System Jun 17, 2026 Oct 14, 2022 N/A· v4 5.4 MEDIUM· v3 N/A· v2 A vulnerability was found in SourceCodester Sanitization Management System. It has been classified as problematic. Affected is an unknown function of the file /php-sms/admin/. The manipulation of the argument page leads...Show more |
1Oretnom23 1Human Resource Management System Jun 17, 2026 Oct 14, 2022 N/A· v4 5.4 MEDIUM· v3 N/A· v2 A vulnerability was found in Human Resource Management System 1.0. It has been classified as problematic. This affects an unknown part of the component Leave Handler. The manipulation of the argument Reason leads to cros...Show more |
1Oretnom23 1Human Resource Management System Jun 17, 2026 Oct 14, 2022 N/A· v4 5.4 MEDIUM· v3 N/A· v2 A vulnerability was found in SourceCodester Human Resource Management System 1.0. It has been classified as problematic. Affected is an unknown function of the component Master List. The manipulation of the argument city...Show more |