← Back
CWE-79

47,376 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (47,376)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Add2fav Project
1Add2fav
Jun 17, 2026
Sep 9, 2022
N/A· v4
4.8 MEDIUM· v3
N/A· v2
Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Christian Salazar's add2fav plugin <= 1.0 at WordPress.
1Add User Role Project
1Add User Role
Jun 17, 2026
Sep 9, 2022
N/A· v4
4.8 MEDIUM· v3
N/A· v2
Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Nikhil Vaghela's Add User Role plugin <= 0.0.1 at WordPress.
1Webhelpagency
1Word Search Puzzles
Jun 17, 2026
Sep 9, 2022
N/A· v4
4.8 MEDIUM· v3
N/A· v2
Authenticated (author+) Stored Cross-Site Scripting (XSS) vulnerability in WHA's Word Search Puzzles game plugin <= 2.0.1 at WordPress.
1Samsung
1Smarttagplugin
Jun 17, 2026
Sep 9, 2022
N/A· v4
4.8 MEDIUM· v3
N/A· v2
Improper input validation vulnerability in SmartTagPlugin prior to version 1.2.21-6 allows privileged attackers to trigger a XSS on a victim&#39;s devices.
1Culture Object Project
1Culture Object
Jun 17, 2026
Sep 9, 2022
N/A· v4
4.8 MEDIUM· v3
N/A· v2
Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Liam Gladdy / Thirty8 Digital Culture Object plugin <= 4.0.1 at WordPress.
1Wp Forecast Project
1Wp Forecast
Jun 17, 2026
Sep 9, 2022
N/A· v4
4.8 MEDIUM· v3
N/A· v2
Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Hans Matzen's wp-forecast plugin <= 7.5 at WordPress.
1Algolplus
1Advanced Order Export For Woocommerce
Jun 17, 2026
Sep 9, 2022
N/A· v4
4.8 MEDIUM· v3
N/A· v2
Authenticated (shop manager+) Reflected Cross-Site Scripting (XSS) vulnerability in AlgolPlus Advanced Order Export For WooCommerce plugin <= 3.3.1 at WordPress.
1Appwrite
1Appwrite
Jun 17, 2026
Sep 9, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Cross-site Scripting (XSS) - Stored in GitHub repository appwrite/appwrite prior to 1.0.0-RC1.
1Xwiki
1Xwiki
Jun 17, 2026
Sep 8, 2022
N/A· v4
9.0 CRITICAL· v3
N/A· v2
XWiki Platform Mentions UI is a user interface for mentioning users in wiki content for XWiki Platform, a generic wiki platform. Starting in version 12.5-rc-1 and prior to versions 13.10.6 and 14.4, it's possible to stor...Show more
XWiki Platform Mentions UI is a user interface for mentioning users in wiki content for XWiki Platform, a generic wiki platform. Starting in version 12.5-rc-1 and prior to versions 13.10.6 and 14.4, it's possible to store Javascript or groovy scripts in a mention, macro anchor, or reference field. The stored code is executed by anyone visiting the page with the mention. This issue has been patched on XWiki 14.4 and 13.10.6. As a workaround, one may update `XWiki.Mentions.MentionsMacro` and edit the `Macro code` field of the `XWiki.WikiMacroClass` XObject.Show less
1Xwiki
1Xwiki
Jun 17, 2026
Sep 8, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
XWiki Platform Attachment UI provides a macro to easily upload and select attachments for XWiki Platform, a generic wiki platform. Starting with version 14.0-rc-1 and prior to 14.4-rc-1, it's possible to store JavaScript...Show more
XWiki Platform Attachment UI provides a macro to easily upload and select attachments for XWiki Platform, a generic wiki platform. Starting with version 14.0-rc-1 and prior to 14.4-rc-1, it's possible to store JavaScript in an attachment name, which will be executed by anyone trying to move the corresponding attachment. This issue has been patched in XWiki 14.4-rc-1. As a workaround, one may copy `moveStep1.vm` to `webapp/xwiki/templates/moveStep1.vm` and replace vulnerable code with code from the patch.Show less
1Xwiki
1Xwiki
Jun 17, 2026
Sep 8, 2022
N/A· v4
9.0 CRITICAL· v3
N/A· v2
The XWiki Platform Index UI is an Index of all pages, attachments, orphans and deleted pages and attachments for XWiki Platform, a generic wiki platform. Prior to versions 13.10.6 and 14.3, it's possible to store JavaScr...Show more
The XWiki Platform Index UI is an Index of all pages, attachments, orphans and deleted pages and attachments for XWiki Platform, a generic wiki platform. Prior to versions 13.10.6 and 14.3, it's possible to store JavaScript which will be executed by anyone viewing the deleted attachments index with an attachment containing javascript in its name. This issue has been patched in XWiki 13.10.6 and 14.3. As a workaround, modify fix the vulnerability by editing the wiki page `XWiki.DeletedAttachments` with the object editor, open the `JavaScriptExtension` object and apply on the content the changes that can be found on the fix commit.Show less
1Xwiki
1Xwiki
Jun 17, 2026
Sep 8, 2022
N/A· v4
9.0 CRITICAL· v3
N/A· v2
XWiki Platform Web Parent POM contains Web resources for the XWiki platform, a generic wiki platform. Starting with version 1.0 and prior to versions 13.10.6 and 14.30-rc-1, it's possible to store JavaScript which will b...Show more
XWiki Platform Web Parent POM contains Web resources for the XWiki platform, a generic wiki platform. Starting with version 1.0 and prior to versions 13.10.6 and 14.30-rc-1, it's possible to store JavaScript which will be executed by anyone viewing the history of an attachment containing javascript in its name. This issue has been patched in XWiki 13.10.6 and 14.3RC1. As a workaround, it is possible to replace `viewattachrev.vm`, the entry point for this attack, by a patched version from the patch without updating XWiki.Show less
1Tastyigniter
1Tastyigniter
Jun 17, 2026
Sep 8, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
TastyIgniter v3.5.0 was discovered to contain a cross-site scripting (XSS) vulnerability which allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
1Diagrams
1Drawio
Jun 17, 2026
Sep 8, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Cross-site Scripting (XSS) - Generic in GitHub repository jgraph/drawio prior to 20.3.0.
1Diagrams
1Drawio
Jun 17, 2026
Sep 8, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Cross-site Scripting (XSS) - Generic in GitHub repository jgraph/drawio prior to 20.3.0.
1Nagios
1Nagios Xi
Jun 17, 2026
Sep 7, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Nagios XI before v5.8.7 was discovered to contain a cross-site scripting (XSS) vulnerability via the ajax.php script in CCM 3.1.5.
1Nagios
1Nagios Xi
Jun 17, 2026
Sep 7, 2022
N/A· v4
4.8 MEDIUM· v3
N/A· v2
Nagios XI v5.8.6 was discovered to contain a cross-site scripting (XSS) vulnerability via the System Performance Settings page under the Admin panel.
1Nagios
1Nagios Xi
Jun 17, 2026
Sep 7, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Nagios XI v5.8.6 was discovered to contain a cross-site scripting (XSS) vulnerability via the MTR component in version 1.0.4.
1Nagios
1Nagios Xi
Jun 17, 2026
Sep 7, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Nagios XI before v5.8.7 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities at auditlog.php.
1Nagios
1Nagios Xi
Jun 17, 2026
Sep 7, 2022
N/A· v4
4.8 MEDIUM· v3
N/A· v2
Nagios XI v5.8.6 was discovered to contain a cross-site scripting (XSS) vulnerability via the System Settings page under the Admin panel.