← Back
CWE-79

47,382 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (47,382)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Givewp
1Givewp
Jun 17, 2026
Aug 1, 2022
N/A· v4
4.8 MEDIUM· v3
N/A· v2
The GiveWP WordPress plugin before 2.21.3 does not properly sanitise and escape the currency settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfilter...Show more
The GiveWP WordPress plugin before 2.21.3 does not properly sanitise and escape the currency settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed (for example in multisite setup)Show less
1Sigmaplugin
1Advanced Wordpress Reset
Jun 17, 2026
Aug 1, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
The Advanced WordPress Reset WordPress plugin before 1.6 does not escape some generated URLs before outputting them back in href attributes of admin dashboard pages, leading to Reflected Cross-Site Scripting
1Microsoft
1Microsoft Advertising Universal Event Tracking
Jun 17, 2026
Aug 1, 2022
N/A· v4
4.8 MEDIUM· v3
N/A· v2
The Microsoft Advertising Universal Event Tracking (UET) WordPress plugin before 1.0.4 does not sanitise and escape its settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even w...Show more
The Microsoft Advertising Universal Event Tracking (UET) WordPress plugin before 1.0.4 does not sanitise and escape its settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed. Due to the nature of this plugin, well crafted XSS can also leak into the frontpage.Show less
1Digiprove
1Copyright Proof
Jun 17, 2026
Aug 1, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
The Copyright Proof WordPress plugin through 4.16 does not sanitise and escape a parameter before outputting it back via an AJAX action available to both unauthenticated and authenticated users, leading to a Reflected Cr...Show more
The Copyright Proof WordPress plugin through 4.16 does not sanitise and escape a parameter before outputting it back via an AJAX action available to both unauthenticated and authenticated users, leading to a Reflected Cross-Site Scripting when a specific setting is enabled.Show less
1Rich Web
1Event Timeline
Jun 17, 2026
Aug 1, 2022
N/A· v4
4.8 MEDIUM· v3
N/A· v2
The Event Timeline WordPress plugin through 1.1.5 does not sanitize and escape Timeline Text, which could allow high-privileged users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is dis...Show more
The Event Timeline WordPress plugin through 1.1.5 does not sanitize and escape Timeline Text, which could allow high-privileged users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowedShow less
1Idehweb
1Login With Phone Number
Jun 17, 2026
Aug 1, 2022
N/A· v4
4.8 MEDIUM· v3
N/A· v2
The Login with phone number WordPress plugin before 1.3.8 does not sanitise and escape plugin settings which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capabili...Show more
The Login with phone number WordPress plugin before 1.3.8 does not sanitise and escape plugin settings which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.Show less
1Ibm
1Datapower Gateway
Jun 17, 2026
Aug 1, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
IBM DataPower Gateway 10.0.2.0 through 10.0.4.0, 10.0.1.0 through 10.0.1.8, 10.5.0.0, and 2018.4.1.0 through 2018.4.1.21 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScrip...Show more
IBM DataPower Gateway 10.0.2.0 through 10.0.4.0, 10.0.1.0 through 10.0.1.8, 10.5.0.0, and 2018.4.1.0 through 2018.4.1.21 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 228435.Show less
1Ibm
1Datapower Gateway
Jun 17, 2026
Aug 1, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
IBM DataPower Gateway 10.0.2.0 through 10.0.4.0, 10.0.1.0 through 10.0.1.8, 10.5.0.0, and 2018.4.1.0 through 2018.4.1.21 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScrip...Show more
IBM DataPower Gateway 10.0.2.0 through 10.0.4.0, 10.0.1.0 through 10.0.1.8, 10.5.0.0, and 2018.4.1.0 through 2018.4.1.21 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 228358.Show less
1Gutenberg Project
1Gutenberg
Jun 17, 2026
Jul 30, 2022
N/A· v4
3.0 LOW· v3
N/A· v2
The Gutenberg plugin through 13.7.3 for WordPress allows stored XSS by the Contributor role via an SVG document to the "Insert from URL" feature. NOTE: the XSS payload does not execute in the context of the WordPress ins...Show more
The Gutenberg plugin through 13.7.3 for WordPress allows stored XSS by the Contributor role via an SVG document to the "Insert from URL" feature. NOTE: the XSS payload does not execute in the context of the WordPress instance's domain; however, analogous attempts by low-privileged users to reference SVG documents are blocked by some similar products, and this behavioral difference might have security relevance to some WordPress site administrators.Show less
1Floating Div Project
1Floating Div
Jun 17, 2026
Jul 29, 2022
N/A· v4
4.8 MEDIUM· v3
N/A· v2
Authenticated (author or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in PluginlySpeaking Floating Div plugin <= 3.0 at WordPress.
1Rapid7
1Velociraptor
Jun 17, 2026
Jul 29, 2022
N/A· v4
4.8 MEDIUM· v3
N/A· v2
The Velociraptor GUI contains an editor suggestion feature that can display the description field of a VQL function, plugin or artifact. This field was not properly sanitized and can lead to cross-site scripting (XSS). T...Show more
The Velociraptor GUI contains an editor suggestion feature that can display the description field of a VQL function, plugin or artifact. This field was not properly sanitized and can lead to cross-site scripting (XSS). This issue was resolved in Velociraptor 0.6.5-2.Show less
1Rapid7
1Velociraptor
Jun 17, 2026
Jul 29, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
A cross-site scripting (XSS) issue in generating a collection report made it possible for malicious clients to inject JavaScript code into the static HTML file. This issue was resolved in Velociraptor 0.6.5-2.
1Garage Management System Project
1Garage Management System
Jun 17, 2026
Jul 29, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
A vulnerability, which was classified as problematic, was found in SourceCodester Garage Management System 1.0. Affected is an unknown function of the file /php_action/createUser.php. The manipulation of the argument use...Show more
A vulnerability, which was classified as problematic, was found in SourceCodester Garage Management System 1.0. Affected is an unknown function of the file /php_action/createUser.php. The manipulation of the argument userName with the input lala<img src="" onerror=alert(1)> leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.Show less
1Advanced School Management System Project
1Advanced School Management System
Jun 17, 2026
Jul 28, 2022
N/A· v4
4.8 MEDIUM· v3
N/A· v2
Advanced School Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the address parameter at ip/school/index.php.
1Rainloop
1Webmail
Jun 17, 2026
Jul 28, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
The Email Viewer in RainLoop through 1.6.0 allows XSS via a crafted email message.
1Xmlsoft
1Libxml2
Nov 4, 2025
Jul 28, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Possible cross-site scripting vulnerability in libxml after commit 960f0e2.
1Gsplugins
1Gs Testimonial Slider
Jun 17, 2026
Jul 28, 2022
N/A· v4
4.8 MEDIUM· v3
N/A· v2
Authenticated (author or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in GS Plugins GS Testimonial Slider plugin <= 1.9.5 at WordPress.
1Gitlab
1Gitlab
Jun 17, 2026
Jul 28, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
An issue has been discovered in GitLab affecting all versions starting from 15.0 before 15.0.1. Missing validation of input used in quick actions allowed an attacker to exploit XSS by injecting HTML in contact details.
1Kippo Graph Project
1Kippo Graph
Nov 21, 2024
Jul 28, 2022
N/A· v4
6.4 MEDIUM· v3
N/A· v2
In kippo-graph before version 1.5.1, there is a cross-site scripting vulnerability in $file_link in class/KippoInput.class.php.
1Kippo Graph Project
1Kippo Graph
Nov 21, 2024
Jul 28, 2022
N/A· v4
6.4 MEDIUM· v3
N/A· v2
In kippo-graph before version 1.5.1, there is a cross-site scripting vulnerability in xss_clean() in class/KippoInput.class.php.