← Back
CWE-79

47,382 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (47,382)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Wwbn
1Avideo
Jun 17, 2026
Aug 22, 2022
N/A· v4
9.0 CRITICAL· v3
N/A· v2
A cross-site scripting (xss) vulnerability exists in the videoAddNew functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lead to arbitrary Javascript execution. An attac...Show more
A cross-site scripting (xss) vulnerability exists in the videoAddNew functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lead to arbitrary Javascript execution. An attacker can get an authenticated user to send a crafted HTTP request to trigger this vulnerability.Show less
1Wwbn
1Avideo
Jun 17, 2026
Aug 22, 2022
N/A· v4
9.6 CRITICAL· v3
N/A· v2
A reflected cross-site scripting (xss) vulnerability exists in the charts tab selection functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lead to arbitrary Javascript...Show more
A reflected cross-site scripting (xss) vulnerability exists in the charts tab selection functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lead to arbitrary Javascript execution. An attacker can get an authenticated user to send a crafted HTTP request to trigger this vulnerability.Show less
1Frappe
1Erpnext
Jul 9, 2026
Aug 22, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Frappe ERPNext 12.29.0 is vulnerable to XSS where the software does not neutralize or incorrectly neutralize user-controllable input before it is placed in output that is used as a web page that is served to other users.
1Pega
1Pega Platform
Jun 17, 2026
Aug 22, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Pega Platform from 7.3 to 8.7.3 is affected by an XSS issue due to a misconfiguration of a datapage setting.
1Pega
1Pega Platform
Jun 17, 2026
Aug 22, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Pega Platform from 8.5.4 to 8.7.3 is affected by an XSS issue with an unauthenticated user and the redirect parameter.
1Smartypantsplugins
1Sp Project & Document Manager
Jun 17, 2026
Aug 22, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Reflected Cross-Site Scripting (XSS) vulnerability in smartypants SP Project & Document Manager plugin <= 4.59 at WordPress
1Slickremix
1Feed Them Social
Jun 17, 2026
Aug 22, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
The Feed Them Social WordPress plugin before 3.0.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting
1Puvox
1Wp Phpmyadmin
Jun 17, 2026
Aug 22, 2022
N/A· v4
4.8 MEDIUM· v3
N/A· v2
The WP phpMyAdmin WordPress plugin before 5.2.0.4 does not escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capabil...Show more
The WP phpMyAdmin WordPress plugin before 5.2.0.4 does not escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed (for example in multisite setup)Show less
1Slickremix
1Feed Them Social
Jun 17, 2026
Aug 22, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
The Feed Them Social WordPress plugin before 3.0.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting
1Okapitech
1Wp Sticky Button
Jun 17, 2026
Aug 22, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
The WP Sticky Button WordPress plugin before 1.4.1 does not have authorisation and CSRF checks when saving its settings, allowing unauthenticated users to update them. Furthermore, due to the lack of escaping in some of...Show more
The WP Sticky Button WordPress plugin before 1.4.1 does not have authorisation and CSRF checks when saving its settings, allowing unauthenticated users to update them. Furthermore, due to the lack of escaping in some of them, it could lead to Stored Cross-Site Scripting issuesShow less
1W3eden
1Download Manager
Jun 17, 2026
Aug 22, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
The Download Manager WordPress plugin before 3.2.50 prioritizes getting a visitor's IP from certain HTTP headers over PHP's REMOTE_ADDR, which makes it possible to bypass IP-based download blocking restrictions.
1Quadlayers
1Wp Social Chat
Jun 17, 2026
Aug 22, 2022
N/A· v4
4.8 MEDIUM· v3
N/A· v2
The WP Social Chat WordPress plugin before 6.0.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks.
1Rezgo
1Rezgo Online Booking
Jun 17, 2026
Aug 22, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
The Rezgo Online Booking WordPress plugin before 4.1.8 does not sanitise and escape some parameters before outputting them back in a page, leading to a Reflected Cross-Site Scripting, which can be exploited either via a...Show more
The Rezgo Online Booking WordPress plugin before 4.1.8 does not sanitise and escape some parameters before outputting them back in a page, leading to a Reflected Cross-Site Scripting, which can be exploited either via a LFI in an AJAX action, or direct call to the affected fileShow less
1Rich Web
1Coming Soon
Jun 17, 2026
Aug 22, 2022
N/A· v4
4.8 MEDIUM· v3
N/A· v2
The Coming Soon - Under Construction WordPress plugin through 1.1.9 does not sanitize and escape some of its settings, which could allow high-privileged users to perform Cross-Site Scripting attacks even when unfiltered_...Show more
The Coming Soon - Under Construction WordPress plugin through 1.1.9 does not sanitize and escape some of its settings, which could allow high-privileged users to perform Cross-Site Scripting attacks even when unfiltered_html is disallowedShow less
1Simple Banner Project
1Simple Banner
Jun 17, 2026
Aug 22, 2022
N/A· v4
4.8 MEDIUM· v3
N/A· v2
The Simple Banner WordPress plugin before 2.12.0 does not properly sanitize its "Simple Banner Text" Settings allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability...Show more
The Simple Banner WordPress plugin before 2.12.0 does not properly sanitize its "Simple Banner Text" Settings allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.Show less
1Wpshopmart
1Testimonial Builder
Jun 17, 2026
Aug 22, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Authenticated (editor+) Stored Cross-Site Scripting (XSS) vulnerability in wpshopmart Testimonial Builder plugin <= 1.6.1 at WordPress.
1Webba Booking
1Webba Booking
Jun 17, 2026
Aug 22, 2022
N/A· v4
4.8 MEDIUM· v3
N/A· v2
Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WebbaPlugins Webba Booking plugin <= 4.2.21 at WordPress.
1Transposh
1Transposh Wordpress Translation
Jun 17, 2026
Aug 22, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
The Transposh WordPress Translation WordPress plugin before 1.0.8 does not have CSRF check in its tp_translation AJAX action, which could allow attackers to make authorised users add a translation. Given the lack of sani...Show more
The Transposh WordPress Translation WordPress plugin before 1.0.8 does not have CSRF check in its tp_translation AJAX action, which could allow attackers to make authorised users add a translation. Given the lack of sanitisation in the tk0 parameter, this could lead to a Stored Cross-Site Scripting issue which will be executed in the context of a logged in adminShow less
1Transposh
1Transposh Wordpress Translation
Jun 17, 2026
Aug 22, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
The Transposh WordPress Translation WordPress plugin before 1.0.8 does not sanitise and escape the tk0 parameter from the tp_translation AJAX action, leading to Stored Cross-Site Scripting, which will trigger in the admi...Show more
The Transposh WordPress Translation WordPress plugin before 1.0.8 does not sanitise and escape the tk0 parameter from the tp_translation AJAX action, leading to Stored Cross-Site Scripting, which will trigger in the admin dashboard of the plugin. The minimum role needed to perform such attack depends on the plugin "Who can translate ?" setting.Show less
1Transposh
1Transposh Wordpress Translation
Jun 17, 2026
Aug 22, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
The Transposh WordPress Translation WordPress plugin before 1.0.8 does not sanitise and escape the a parameter via an AJAX action (available to both unauthenticated and authenticated users when the curl library is instal...Show more
The Transposh WordPress Translation WordPress plugin before 1.0.8 does not sanitise and escape the a parameter via an AJAX action (available to both unauthenticated and authenticated users when the curl library is installed) before outputting it back in the response, leading to a Reflected Cross-Site Scripting issueShow less