CWE-79
47,382 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (47,382)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Better Tag Cloud Project 1Better Tag Cloud Jun 17, 2026 Aug 8, 2022 N/A· v4 4.8 MEDIUM· v3 N/A· v2 The Better Tag Cloud WordPress plugin through 0.99.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfilte...Show more |
1Auto More Tag Project 1Auto More Tag Jun 17, 2026 Aug 8, 2022 N/A· v4 4.8 MEDIUM· v3 N/A· v2 The Auto More Tag WordPress plugin through 4.0.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_...Show more |
The mTouch Quiz WordPress plugin through 3.1.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_ht...Show more |
The Rough Chart WordPress plugin through 1.0.0 does not properly escape chart data label, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallo...Show more |
1Najeebmedia 1Wordpress Comments Fields Jun 17, 2026 Aug 8, 2022 N/A· v4 4.8 MEDIUM· v3 N/A· v2 The WordPress Comments Fields WordPress plugin before 4.1 does not escape Field Error Message, which could allow high-privileged users to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed |
The weForms WordPress plugin before 1.6.14 does not sanitise and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disall...Show more |
The Inspiro PRO WordPress plugin does not sanitize the portfolio slider description, allowing users with privileges as low as Contributor to inject JavaScript into the description. |
The Crowdsignal Dashboard WordPress plugin before 3.0.8 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting |
The YaySMTP WordPress plugin before 2.2.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html ca...Show more |
The YaySMTP WordPress plugin before 2.2.1 does not have proper authorisation when saving its settings, allowing users with a role as low as subscriber to change them, and use that to conduct Stored Cross-Site Scripting a...Show more |
1Simple E Learning System Project 1Simple E Learning System Jun 17, 2026 Aug 8, 2022 N/A· v4 6.1 MEDIUM· v3 N/A· v2 A vulnerability classified as problematic was found in SourceCodester Simple E-Learning System. This vulnerability affects unknown code of the file /claire_blake. The manipulation of the argument Bio leads to cross site...Show more |
1Wedding Hall Booking System Project 1Wedding Hall Booking System Jun 17, 2026 Aug 6, 2022 N/A· v4 5.4 MEDIUM· v3 N/A· v2 A vulnerability, which was classified as problematic, was found in SourceCodester Wedding Hall Booking System. This affects an unknown part of the file /whbs/admin/?page=user of the component Staff User Profile. The mani...Show more |
1Wedding Hall Booking System Project 1Wedding Hall Booking System Jun 17, 2026 Aug 6, 2022 N/A· v4 5.4 MEDIUM· v3 N/A· v2 A vulnerability, which was classified as problematic, has been found in SourceCodester Wedding Hall Booking System. Affected by this issue is some unknown functionality of the file /whbs/?page=manage_account of the compo...Show more |
1Wedding Hall Booking System Project 1Wedding Hall Booking System Jun 17, 2026 Aug 6, 2022 N/A· v4 5.4 MEDIUM· v3 N/A· v2 A vulnerability classified as problematic was found in SourceCodester Wedding Hall Booking System. Affected by this vulnerability is an unknown functionality of the file /whbs/?page=my_bookings of the component Booking F...Show more |
1Wedding Hall Booking System Project 1Wedding Hall Booking System Jun 17, 2026 Aug 6, 2022 N/A· v4 5.4 MEDIUM· v3 N/A· v2 A vulnerability classified as problematic has been found in SourceCodester Wedding Hall Booking System. Affected is an unknown function of the file /whbs/?page=contact_us of the component Contact Page. The manipulation o...Show more |
1Fast Food Ordering System Project 1Fast Food Ordering System Jun 17, 2026 Aug 6, 2022 N/A· v4 5.4 MEDIUM· v3 N/A· v2 A vulnerability, which was classified as problematic, was found in oretnom23 Fast Food Ordering System. This affects an unknown part of the component Menu List Page. The manipulation of the argument Description leads to...Show more |
1Complete Online Job Search System Project 1Complete Online Job Search System Jun 17, 2026 Aug 5, 2022 N/A· v4 4.8 MEDIUM· v3 N/A· v2 Complete Online Job Search System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the U_NAME parameter at /category/controller.php?action=edit. |
1Complete Online Job Search System Project 1Complete Online Job Search System Jun 17, 2026 Aug 5, 2022 N/A· v4 4.8 MEDIUM· v3 N/A· v2 Complete Online Job Search System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the CATEGORY parameter at /category/controller.php?action=edit. |
A vulnerability was found in SourceCodester Interview Management System 1.0 and classified as problematic. This issue affects some unknown processing of the file /addQuestion.php. The manipulation of the argument questio...Show more |
1Apartment Visitors Management System Project 1Apartment Visitors Management System Jun 17, 2026 Aug 5, 2022 N/A· v4 5.4 MEDIUM· v3 N/A· v2 A vulnerability has been found in SourceCodester Apartment Visitor Management System 1.0 and classified as problematic. This vulnerability affects unknown code of the file /manage-apartment.php. The manipulation of the a...Show more |