CWE-79
47,365 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (47,365)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Authenticated (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Fullworks Meet My Team plugin <= 2.0.5 at WordPress. |
1Blossomthemes 1Blossom Recipe Maker Jun 17, 2026 Sep 23, 2022 N/A· v4 5.4 MEDIUM· v3 N/A· v2 Multiple Authenticated (contributor+) Stored Cross-Site Scripting (XSS) vulnerabilities in Blossom Recipe Maker plugin <= 1.0.7 at WordPress. |
Authenticated (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in WHA Crossword plugin <= 1.1.10 at WordPress. |
1Oxilab 1Image Hover Effects Ultimate Jun 17, 2026 Sep 23, 2022 N/A· v4 5.4 MEDIUM· v3 N/A· v2 The Image Hover Effects Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Title & Description values that can be added to an Image Hover in versions up to, and including, 9.7.3 due to ins...Show more |
netlify-ipx is an on-Demand image optimization for Netlify using ipx. In versions prior to 1.2.3, an attacker can bypass the source image domain allowlist by sending specially crafted headers, causing the handler to load...Show more |
1Veritas 1Desktop And Laptop Option Jun 17, 2026 Sep 23, 2022 N/A· v4 6.1 MEDIUM· v3 N/A· v2 A Reflected Cross-Site Scripting (XSS) vulnerability affects the Veritas Desktop Laptop Option (DLO) application login page (aka the DLOServer/restore/login.jsp URI). This affects versions before 9.8 (e.g., 9.1 through 9...Show more |
1Simple College Website Project 1Simple College Website Jun 17, 2026 Sep 22, 2022 N/A· v4 6.1 MEDIUM· v3 N/A· v2 Simple College Website v1.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /college_website/index.php?page=. This vulnerability allows attackers to execute arbitrary web...Show more |
Toast UI Grid is a component to display and edit data. Versions prior to 4.21.3 are vulnerable to cross-site scripting attacks when pasting specially crafted content into editable cells. This issue was fixed in version 4...Show more |
University Library Automation System developed by Yordam Bilgi Teknolojileri before version 19.2 has an unauthenticated Reflected XSS vulnerability. This has been fixed in the version 19.2 |
An XSS (Cross Site Scripting) vulnerability was found in HelpSystems Cobalt Strike through 4.7 that allowed a remote attacker to execute HTML on the Cobalt Strike teamserver. To exploit the vulnerability, one must first...Show more |
Multiple cross-site scripting (XSS) vulnerabilities in Liferay Portal v7.4.3.4 and Liferay DXP v7.4 GA allows attackers to execute arbitrary web scripts or HTML via parameters with the filter_ prefix. |
A cross-site scripting (XSS) vulnerability in Liferay Portal v7.3.3 through v7.4.2 and Liferay DXP v7.3 before service pack 3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into...Show more |
1Liferay 3Digital Experience Platform DxpLiferay PortalJul 9, 2026 Sep 22, 2022 N/A· v4 6.1 MEDIUM· v3 N/A· v2 Liferay Portal v7.1.0 through v7.4.2 and Liferay DXP 7.1 before fix pack 26, 7.2 before fix pack 15, and 7.3 before service pack 3 was discovered to contain a cross-site scripting (XSS) vulnerability in the Portal Search...Show more |
1Liferay 3Digital Experience Platform DxpLiferay PortalJul 9, 2026 Sep 22, 2022 N/A· v4 5.4 MEDIUM· v3 N/A· v2 Stored cross-site scripting (XSS) vulnerability in the Site module's user membership administration page in Liferay Portal 7.0.1 through 7.4.1, and Liferay DXP 7.0 before fix pack 102, 7.1 before fix pack 26, 7.2 before...Show more |
1Getawesomesupport 1Awesome Support Jun 17, 2026 Sep 21, 2022 N/A· v4 5.4 MEDIUM· v3 N/A· v2 Multiple Authenticated (custom specific plugin role) Persistent Cross-Site Scripting (XSS) vulnerability in Awesome Support plugin <= 6.0.7 at WordPress. |
Authenticated (subscriber+) Reflected Cross-Site Scripting (XSS) vulnerability in Totalsoft Event Calendar – Calendar plugin <= 1.4.6 at WordPress. |
Multiple Authenticated (contributor+) Stored Cross-Site Scripting (XSS) vulnerabilities in WHA Word Search Puzzles game plugin <= 2.0.1 at WordPress. |
Multiple Authenticated (contributor+) Stored Cross-Site Scripting (XSS) vulnerabilities in WHA Crossword plugin <= 1.1.10 at WordPress. |
1Simple Task Managing System Project 1Simple Task Managing System Jul 9, 2026 Sep 21, 2022 N/A· v4 4.8 MEDIUM· v3 N/A· v2 SourceCodester Simple Task Managing System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component newProjectValidation.php. This vulnerability allows attackers to execute arbitrary we...Show more |
1Simple Task Managing System Project 1Simple Task Managing System Jul 9, 2026 Sep 21, 2022 N/A· v4 4.8 MEDIUM· v3 N/A· v2 SourceCodester Simple Task Managing System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component newProjectValidation.php. This vulnerability allows attackers to execute arbitrary we...Show more |