← Back
CWE-79

47,365 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (47,365)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Gavazziautomation
2Cpy Car Park Server
Uwp 3.0 Monitoring Gateway And Controller Firmware
Jun 17, 2026
Sep 28, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 the Sentilo Proxy is prone to reflected XSS which only affects the Sentilo service.
1Cowell Enterprise Travel Management System Project
1Cowell Enterprise Travel Management System
Jun 17, 2026
Sep 28, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Cowell enterprise travel management system has insufficient filtering for special characters within web URL. An unauthenticated remote attacker can inject JavaScript and perform XSS (Reflected Cross-Site Scripting) attac...Show more
Cowell enterprise travel management system has insufficient filtering for special characters within web URL. An unauthenticated remote attacker can inject JavaScript and perform XSS (Reflected Cross-Site Scripting) attack.Show less
1Heimavista
1Dark Horse Rpage
Jun 17, 2026
Sep 28, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Heimavista Rpage has insufficient filtering for platform web URL. An unauthenticated remote attacker can inject JavaScript and perform XSS (Reflected Cross-Site Scripting) attack.
1Lcnet
1Smart Evision
Jun 17, 2026
Sep 28, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Smart eVision has insufficient filtering for special characters in the POST Data parameter in the specific function. An unauthenticated remote attacker can inject JavaScript to perform XSS (Stored Cross-Site Scripting) a...Show more
Smart eVision has insufficient filtering for special characters in the POST Data parameter in the specific function. An unauthenticated remote attacker can inject JavaScript to perform XSS (Stored Cross-Site Scripting) attack.Show less
1Ec Cube
1Ec Cube
Jun 17, 2026
Sep 27, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
DOM-based cross-site scripting vulnerability in EC-CUBE 4 series (EC-CUBE 4.0.0 to 4.1.2) allows a remote attacker to inject an arbitrary script by having an administrative user of the product to visit a specially crafte...Show more
DOM-based cross-site scripting vulnerability in EC-CUBE 4 series (EC-CUBE 4.0.0 to 4.1.2) allows a remote attacker to inject an arbitrary script by having an administrative user of the product to visit a specially crafted page.Show less
1Vtiger
1Vtiger Crm
Jun 17, 2026
Sep 27, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Vtiger CRM v7.4.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the e-mail template modules.
1Iris
1Isams
Jun 17, 2026
Sep 27, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
ISAMS 22.2.3.2 is prone to stored Cross-site Scripting (XSS) attack on the title field for groups, allowing an attacker to store a JavaScript payload that will be executed when another user uses the application.
1Online Market Place Site Project
1Online Market Place Site
Jun 17, 2026
Sep 26, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Sourcecodester Online Market Place Site 1.0 is vulnerable to Cross Site Scripting (XSS), allowing attackers to register as a Seller then create new products containing XSS payloads in the 'Product Title' and 'Short Descr...Show more
Sourcecodester Online Market Place Site 1.0 is vulnerable to Cross Site Scripting (XSS), allowing attackers to register as a Seller then create new products containing XSS payloads in the 'Product Title' and 'Short Description' fields.Show less
1Centreon
1Centreon
Jun 17, 2026
Sep 26, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Centreon v20.10.18 was discovered to contain a cross-site scripting (XSS) vulnerability via the esc_name (Escalation Name) parameter at Configuration/Notifications/Escalations. This vulnerability allows attackers to exec...Show more
Centreon v20.10.18 was discovered to contain a cross-site scripting (XSS) vulnerability via the esc_name (Escalation Name) parameter at Configuration/Notifications/Escalations. This vulnerability allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload.Show less
2Fedoraproject
Google
2Chrome
Fedora
Jun 17, 2026
Sep 26, 2022
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Inappropriate implementation in Extensions API in Google Chrome prior to 104.0.5112.101 allowed an attacker who convinced a user to install a malicious extension to inject arbitrary scripts into WebUI via a crafted HTML...Show more
Inappropriate implementation in Extensions API in Google Chrome prior to 104.0.5112.101 allowed an attacker who convinced a user to install a malicious extension to inject arbitrary scripts into WebUI via a crafted HTML page.Show less
1Seo Smart Links Project
1Seo Smart Links
Jun 17, 2026
Sep 26, 2022
N/A· v4
4.8 MEDIUM· v3
N/A· v2
The SEO Smart Links WordPress plugin through 3.0.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfi...Show more
The SEO Smart Links WordPress plugin through 3.0.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)Show less
1Quantumcloud
1Slider Hero
Jun 17, 2026
Sep 26, 2022
N/A· v4
4.8 MEDIUM· v3
N/A· v2
The Slider Hero WordPress plugin before 8.4.4 does not escape the slider Name, which could allow high-privileged users to perform Cross-Site Scripting attacks.
1Zealousweb
1Generate Pdf Using Contact Form 7
Jun 17, 2026
Sep 26, 2022
N/A· v4
4.8 MEDIUM· v3
N/A· v2
The Generate PDF WordPress plugin before 3.6 does not sanitise and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disa...Show more
The Generate PDF WordPress plugin before 3.6 does not sanitise and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.Show less
1Wordlift
1Wordlift
Jun 17, 2026
Sep 26, 2022
N/A· v4
4.8 MEDIUM· v3
N/A· v2
The WordLift WordPress plugin before 3.37.2 does not sanitise and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disal...Show more
The WordLift WordPress plugin before 3.37.2 does not sanitise and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.Show less
1Simplefilelist
1Simple File List
Jun 17, 2026
Sep 26, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
The Simple File List WordPress plugin before 4.4.12 does not escape parameters before outputting them back in attributes, leading to Reflected Cross-Site Scripting
1Bitcoin/altcoin Faucet Project
1Bitcoin/altcoin Faucet
Jun 17, 2026
Sep 26, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
The Bitcoin / Altcoin Faucet WordPress plugin through 1.6.0 does not have any CSRF check when saving its settings, allowing attacker to make a logged in admin change them via a CSRF attack. Furthermore, due to the lack o...Show more
The Bitcoin / Altcoin Faucet WordPress plugin through 1.6.0 does not have any CSRF check when saving its settings, allowing attacker to make a logged in admin change them via a CSRF attack. Furthermore, due to the lack of sanitisation and escaping, it could also lead to Stored Cross-Site Scripting issuesShow less
1Themehunk
1Wp Popup Builder
Jun 17, 2026
Sep 26, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
The WP Popup Builder WordPress plugin before 1.2.9 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting
1Benbodhi
1Svg Support
Jun 17, 2026
Sep 26, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
The SVG Support WordPress plugin before 2.5 does not properly handle SVG added via an URL, which could allow users with a role as low as author to perform Cross-Site Scripting attacks
1Creativeitem
1Academy Learning Management System
Jul 9, 2026
Sep 26, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Academy Learning Management System before v5.9.1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the Search parameter.
1Xdsoft
1Jodit Editor
Jun 17, 2026
Sep 24, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Jodit Editor is a WYSIWYG editor written in pure TypeScript without the use of additional libraries. Jodit Editor is vulnerable to XSS attacks when pasting specially constructed input. This issue has not been fully patch...Show more
Jodit Editor is a WYSIWYG editor written in pure TypeScript without the use of additional libraries. Jodit Editor is vulnerable to XSS attacks when pasting specially constructed input. This issue has not been fully patched. There are no known workarounds.Show less