← Back
CWE-79

47,382 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (47,382)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Visualcomposer
1Visual Composer Website Builder
Jun 17, 2026
Sep 6, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
The Visual Composer Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the post/page 'Title' value in versions up to, and including, 45.0 due to insufficient input sanitization and outp...Show more
The Visual Composer Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the post/page 'Title' value in versions up to, and including, 45.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with access to the visual composer editor to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.Show less
1Simple Banner Project
1Simple Banner
Jun 17, 2026
Sep 6, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
The Simple Banner plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `pro_version_activation_code` parameter in versions up to, and including, 2.11.0 due to insufficient input sanitization and outp...Show more
The Simple Banner plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `pro_version_activation_code` parameter in versions up to, and including, 2.11.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, including those without administrative capabilities when access is granted to those users, to inject arbitrary web scripts in page that will execute whenever a user role having access to "Simple Banner" accesses the plugin's settings.Show less
1Wp Useronline Project
1Wp Useronline
Jun 17, 2026
Sep 6, 2022
N/A· v4
4.8 MEDIUM· v3
N/A· v2
The WP-UserOnline plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘templates[browsingpage][text]' parameter in versions up to, and including, 2.87.6 due to insufficient input sanitization and ou...Show more
The WP-UserOnline plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘templates[browsingpage][text]' parameter in versions up to, and including, 2.87.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with administrative capabilities and above to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The only affects multi-site installations and installations where unfiltered_html is disabled.Show less
1Visualcomposer
1Visual Composer Website Builder
Jun 17, 2026
Sep 6, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
The Visual Composer Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Text Block' feature in versions up to, and including, 45.0 due to insufficient input sanitization and output...Show more
The Visual Composer Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Text Block' feature in versions up to, and including, 45.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with access to the visual composer editor to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.Show less
1Coleds
1Simple Seo
Jun 17, 2026
Sep 6, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
The Simple SEO plugin for WordPress is vulnerable to attribute-based stored Cross-Site Scripting in versions up to, and including 1.7.91, due to insufficient sanitization or escaping on the SEO social and standard title...Show more
The Simple SEO plugin for WordPress is vulnerable to attribute-based stored Cross-Site Scripting in versions up to, and including 1.7.91, due to insufficient sanitization or escaping on the SEO social and standard title parameters. This can be exploited by authenticated users with Contributor and above permissions to inject arbitrary web scripts into posts/pages that execute whenever an administrator access the page.Show less
1Mythemeshop
1Launcher
Jun 17, 2026
Sep 6, 2022
N/A· v4
4.8 MEDIUM· v3
N/A· v2
Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in MyThemeShop Launcher: Coming Soon & Maintenance Mode plugin <= 1.0.11 at WordPress.
1Fortinet
1Fortimail
Jun 17, 2026
Sep 6, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
An improper neutralization of input during web page generation vulnerability [CWE-79] in the Webmail of FortiMail before 7.2.0 may allow an unauthenticated attacker to trigger a cross-site scripting (XSS) attack via send...Show more
An improper neutralization of input during web page generation vulnerability [CWE-79] in the Webmail of FortiMail before 7.2.0 may allow an unauthenticated attacker to trigger a cross-site scripting (XSS) attack via sending specially crafted mail messages.Show less
1Fortinet
1Fortios
Jun 17, 2026
Sep 6, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiOS version 7.2.0, version 6.4.0 through 6.4.9, version 7.0.0 through 7.0.5 may allow an authenticated attacker to perform a st...Show more
An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiOS version 7.2.0, version 6.4.0 through 6.4.9, version 7.0.0 through 7.0.5 may allow an authenticated attacker to perform a stored cross site scripting (XSS) attack through the URI parameter via the Threat Feed IP address section of the Security Fabric External connectors.Show less
1Diagrams
1Drawio
Jun 17, 2026
Sep 5, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Cross-site Scripting (XSS) - Stored in GitHub repository jgraph/drawio prior to 20.2.8.
1Fastflow
1Fastflow
Jun 17, 2026
Sep 5, 2022
N/A· v4
5.5 MEDIUM· v3
N/A· v2
The Fast Flow WordPress plugin before 1.2.13 does not sanitise and escape some of its Widget settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unf...Show more
The Fast Flow WordPress plugin before 1.2.13 does not sanitise and escape some of its Widget settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)Show less
1Paymattic
1Simple Payment Donations & Subscriptions
Jun 17, 2026
Sep 5, 2022
N/A· v4
7.2 HIGH· v3
N/A· v2
The Simple Payment Donations & Subscriptions WordPress plugin before 4.2.1 does not sanitise and escape user input given in its forms, which could allow unauthenticated attackers to perform Cross-Site Scripting attacks a...Show more
The Simple Payment Donations & Subscriptions WordPress plugin before 4.2.1 does not sanitise and escape user input given in its forms, which could allow unauthenticated attackers to perform Cross-Site Scripting attacks against adminsShow less
1Wpseeds
1Wp Database Backup
Jun 17, 2026
Sep 5, 2022
N/A· v4
4.8 MEDIUM· v3
N/A· v2
The WP Database Backup WordPress plugin before 5.9 does not escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capabi...Show more
The WP Database Backup WordPress plugin before 5.9 does not escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed (for example in multisite setup)Show less
2Dokuwiki
Fedoraproject
2Dokuwiki
Fedora
Jun 17, 2026
Sep 5, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Cross-site Scripting (XSS) - Reflected in GitHub repository splitbrain/dokuwiki prior to 2022-07-31a.
1Otrs
1Otrs
Jun 17, 2026
Sep 5, 2022
N/A· v4
4.8 MEDIUM· v3
N/A· v2
An attacker who is logged into OTRS as an admin user may manipulate customer URL field to store JavaScript code to be run later by any other agent when clicking the customer URL link. Then the stored JavaScript is execut...Show more
An attacker who is logged into OTRS as an admin user may manipulate customer URL field to store JavaScript code to be run later by any other agent when clicking the customer URL link. Then the stored JavaScript is executed in the context of OTRS. The same issue applies for the usage of external data sources e.g. database or ldapShow less
1Otrs
1Otrs
Jun 17, 2026
Sep 5, 2022
N/A· v4
4.8 MEDIUM· v3
N/A· v2
An attacker who is logged into OTRS as an admin user may manipulate the URL to cause execution of JavaScript in the context of OTRS.
1Cotonti
1Cotonti Siena
Jun 17, 2026
Sep 5, 2022
N/A· v4
4.8 MEDIUM· v3
N/A· v2
Cotonti Siena 0.9.20 allows admins to conduct stored XSS attacks via a direct message (DM).
1Cotonti
1Cotonti Siena
Jun 17, 2026
Sep 5, 2022
N/A· v4
4.8 MEDIUM· v3
N/A· v2
Cotonti Siena 0.9.20 allows admins to conduct stored XSS attacks via a forum post.
1Appsmith
1Appsmith
Jun 17, 2026
Sep 5, 2022
N/A· v4
8.9 HIGH· v3
N/A· v2
Server-side JavaScript injection in Appsmith through 1.7.14 allows remote attackers to execute arbitrary JavaScript code from the server via the currentItem property of the list widget, e.g., to perform DoS attacks or ac...Show more
Server-side JavaScript injection in Appsmith through 1.7.14 allows remote attackers to execute arbitrary JavaScript code from the server via the currentItem property of the list widget, e.g., to perform DoS attacks or achieve an information leak.Show less
1Garage Management System Project
1Garage Management System
Jun 17, 2026
Sep 2, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
A stored cross-site scripting (XSS) vulnerability in /client.php of Garage Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the name parameter.
1Prestashop
1Productcomments
Jun 17, 2026
Sep 2, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
This package is a PrestaShop module that allows users to post reviews and rate products. There is a vulnerability where the attacker could steal an administrator's cookie. The issue is fixed in version 5.0.2.