← Back
CWE-79

47,376 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (47,376)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1News247 News Magazine (cms) Project
1News247 News Magazine (cms)
Jun 17, 2026
Sep 16, 2022
N/A· v4
4.8 MEDIUM· v3
N/A· v2
Cross Site Scripting (XSS vulnerability exists in )Sourcecodester News247 News Magazine (CMS) PHP 5.6 or higher and MySQL 5.7 or higher via the blog category name field
1Craftcms
1Craft Cms
Jun 17, 2026
Sep 16, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Craft CMS 4.2.0.1 is vulnerable to Cross Site Scripting (XSS) via src/helpers/Cp.php.
1Craftcms
1Craft Cms
Jun 17, 2026
Sep 16, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Craft CMS 4.2.0.1 suffers from Stored Cross Site Scripting (XSS) in /admin/myaccount.
1Espocrm
1Espocrm
Jun 17, 2026
Sep 16, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Cross Site Scripting in Import feature in EspoCRM 7.1.8 allows remote users to run malicious JavaScript in victim s browser via sending crafted csv file containing malicious JavaScript to authenticated user. Any authenti...Show more
Cross Site Scripting in Import feature in EspoCRM 7.1.8 allows remote users to run malicious JavaScript in victim s browser via sending crafted csv file containing malicious JavaScript to authenticated user. Any authenticated user importing the crafted CSV file may end up running the malicious JavaScripting in the browser.Show less
1Diagrams
1Drawio
Jun 17, 2026
Sep 16, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Cross-site Scripting (XSS) - Stored in GitHub repository jgraph/drawio prior to 20.3.1.
1Acnam
1Wp Server Health Stats
Jun 17, 2026
Sep 16, 2022
N/A· v4
4.8 MEDIUM· v3
N/A· v2
The WP Server Health Stats WordPress plugin before 1.7.0 does not escape some of its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is di...Show more
The WP Server Health Stats WordPress plugin before 1.7.0 does not escape some of its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.Show less
1Wpaffiliatemanager
1Affiliates Manager
Jun 17, 2026
Sep 16, 2022
N/A· v4
4.8 MEDIUM· v3
N/A· v2
The Affiliates Manager WordPress plugin before 2.9.14 does not sanitise and escape some of its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capabi...Show more
The Affiliates Manager WordPress plugin before 2.9.14 does not sanitise and escape some of its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.Show less
1Wp Staging
1Wp Staging
Jun 17, 2026
Sep 16, 2022
N/A· v4
4.8 MEDIUM· v3
N/A· v2
The WP STAGING WordPress plugin before 2.9.18 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltere...Show more
The WP STAGING WordPress plugin before 2.9.18 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)Show less
1Wp Taxonomy Import Project
1Wp Taxonomy Import
Jun 17, 2026
Sep 16, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
The WP Taxonomy Import WordPress plugin through 1.0.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting
1Radiustheme
1Classified Listing
Jun 17, 2026
Sep 16, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
The Classified Listing Pro WordPress plugin before 2.0.20 does not escape a generated URL before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Site Scripting
1Radiustheme
4Classified Listing
Classified Listing Store & MembershipClassima+1 more
Jun 17, 2026
Sep 16, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
The Classima WordPress theme before 2.1.11 and some of its required plugins (Classified Listing before 2.2.14, Classified Listing Pro before 2.0.20, Classified Listing Store & Membership before 1.4.20 and Classima Core b...Show more
The Classima WordPress theme before 2.1.11 and some of its required plugins (Classified Listing before 2.2.14, Classified Listing Pro before 2.0.20, Classified Listing Store & Membership before 1.4.20 and Classima Core before 1.10) do not escape a parameter before outputting it back in attributes, leading to Reflected Cross-Site ScriptingShow less
1Autoptimize
1Autoptimize
Jun 17, 2026
Sep 16, 2022
N/A· v4
4.8 MEDIUM· v3
N/A· v2
The Autoptimize WordPress plugin before 3.1.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltere...Show more
The Autoptimize WordPress plugin before 3.1.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)Show less
1Woobewoo
1Wbw Currency Switcher For Woocommerce
Jun 17, 2026
Sep 16, 2022
N/A· v4
4.8 MEDIUM· v3
N/A· v2
The WBW Currency Switcher for WooCommerce WordPress plugin before 1.6.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attac...Show more
The WBW Currency Switcher for WooCommerce WordPress plugin before 1.6.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)Show less
1Wpexperts
1Post Smtp
Jun 17, 2026
Sep 16, 2022
N/A· v4
4.8 MEDIUM· v3
N/A· v2
The Post SMTP Mailer/Email Log WordPress plugin before 2.1.4 does not escape some of its settings before outputting them in the admins dashboard, allowing high privilege users to perform Cross-Site Scripting attacks agai...Show more
The Post SMTP Mailer/Email Log WordPress plugin before 2.1.4 does not escape some of its settings before outputting them in the admins dashboard, allowing high privilege users to perform Cross-Site Scripting attacks against other users even when the unfiltered_html capability is disallowed.Show less
1Syncovery
1Syncovery
Jul 9, 2026
Sep 16, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Super Flexible Software GmbH & Co. KG Syncovery 9 for Linux v9.47x and below was discovered to contain a cross-site scripting (XSS) vulnerability.
1Hcltech
1Traveler
Jun 17, 2026
Sep 15, 2022
N/A· v4
4.8 MEDIUM· v3
N/A· v2
There is a reflected Cross-Site Scripting vulnerability in the HCL Traveler web admin (LotusTraveler.nsf).
1Fiberhome
1An5506 02 B Firmware
Jun 17, 2026
Sep 15, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
A stored cross-site scripting (XSS) vulnerability in the auth_settings component of FiberHome AN5506-02-B vRP2521 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the sncfg_lo...Show more
A stored cross-site scripting (XSS) vulnerability in the auth_settings component of FiberHome AN5506-02-B vRP2521 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the sncfg_loid text field.Show less
1Qsmart Next Project
1Qsmart Next
Jul 9, 2026
Sep 15, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Qsmart Next v4.1.2 was discovered to contain a cross-site scripting (XSS) vulnerability.
1Pimcore
1Pimcore
Jun 17, 2026
Sep 15, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.5.6.
1Crushftp
1Crushftp
Jun 17, 2026
Sep 15, 2022
N/A· v4
4.8 MEDIUM· v3
N/A· v2
An issue was discovered in CrushFTP 9. The creation of a new user through the /WebInterface/UserManager/ interface allows an attacker, with access to the administration panel, to perform Stored Cross-Site Scripting (XSS)...Show more
An issue was discovered in CrushFTP 9. The creation of a new user through the /WebInterface/UserManager/ interface allows an attacker, with access to the administration panel, to perform Stored Cross-Site Scripting (XSS). The payload can be executed in multiple scenarios, for example when the user's page appears in the Most Visited section of the page.Show less