← Back
CWE-79

47,383 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (47,383)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Allow Svg Files Project
1Allow Svg Files
Jun 17, 2026
Jul 25, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
The Allow SVG Files WordPress plugin through 1.1 does not sanitise uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads
1Brizy
1Unyson
Jun 17, 2026
Jul 25, 2022
N/A· v4
7.2 HIGH· v3
N/A· v2
The Unyson WordPress plugin before 2.7.27 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting
1Tipsandtricks Hq
1Wp Video Lightbox
Jun 17, 2026
Jul 25, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
The WP Video Lightbox WordPress plugin before 1.9.5 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsers
1Essentialplugin
1Popup Anything
Jun 17, 2026
Jul 25, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
The Popup Anything WordPress plugin before 2.1.7 does not sanitise and escape a parameter before outputting it back in a frontend page, leading to a Reflected Cross-Site Scripting
1Name Directory Project
1Name Directory
Jun 17, 2026
Jul 25, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
The Name Directory WordPress plugin before 1.25.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting. Furthermore, as the payload is also saved int...Show more
The Name Directory WordPress plugin before 1.25.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting. Furthermore, as the payload is also saved into the database after the request, it leads to a Stored XSS as wellShow less
1Draftpress
1Header Footer Code Manager
Jun 17, 2026
Jul 25, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
The Header Footer Code Manager WordPress plugin before 1.1.24 does not escape generated URLs before outputting them back in attributes in an admin page, leading to a Reflected Cross-Site Scripting.
1Django Rest Framework
1Django Rest Framework
Nov 21, 2024
Jul 23, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Django REST framework (aka django-rest-framework) before 3.9.1 allows XSS because the default DRF Browsable API view templates disable autoescaping.
1Wpwax
1Team
Jun 17, 2026
Jul 22, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Multiple Authenticated (contributor or higher user role) Persistent Cross-Site Scripting (XSS) vulnerabilities in wpWax Team plugin <= 1.2.6 at WordPress.
1Wpwax
1Team
Jun 17, 2026
Jul 22, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Multiple Authenticated (contributor or higher user role) Stored Cross-Site Scripting (XSS) vulnerabilities in wpWax Team plugin <= 1.2.6 at WordPress.
1Testimonials Project
1Testimonials
Jun 17, 2026
Jul 22, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Authenticated (contributor or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in Chinmoy Paul's Testimonials plugin <= 3.0.1 at WordPress.
1Hallowelt
1Bluespice
Jun 17, 2026
Jul 22, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Cross-site Scripting (XSS) vulnerability in the "commonuserinterface" component of BlueSpice allows an attacker to inject arbitrary HTML into a page using the title parameter of the call URL.
1Hallowelt
1Bluespice
Jun 17, 2026
Jul 22, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Cross-site Scripting (XSS) vulnerability in "Extension:ExtendedSearch" of Hallo Welt! GmbH BlueSpice allows attacker to inject arbitrary HTML (XSS) on page "Special:SearchCenter", using the search term in the URL.
1Microweber
1Microweber
Jun 17, 2026
Jul 22, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Cross-site Scripting (XSS) - Reflected in GitHub repository microweber/microweber prior to 1.2.21.
1Midori Global
1Better Pdf Exporter
Jun 17, 2026
Jul 22, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
The Better PDF Exporter add-on 10.0.0 for Atlassian Jira is prone to stored XSS via a crafted description to the PDF Templates overview page.
1Microweber
1Microweber
Jun 17, 2026
Jul 22, 2022
N/A· v4
4.8 MEDIUM· v3
N/A· v2
Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 1.2.21.
1Open Emr
1Openemr
Jun 17, 2026
Jul 22, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Cross-site Scripting (XSS) - Stored in GitHub repository openemr/openemr prior to 7.0.0.
1Cisco
1Iot Control Center
Jun 17, 2026
Jul 22, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
A vulnerability in the web-based management interface of Cisco IoT Control Center could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulne...Show more
A vulnerability in the web-based management interface of Cisco IoT Control Center could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability exists because the web-based management interface does not properly validate user-supplied input. An attacker could exploit this vulnerability by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.Show less
1Wp Maintenance Project
1Wp Maintenance
Jun 17, 2026
Jul 21, 2022
N/A· v4
4.8 MEDIUM· v3
N/A· v2
Authenticated Stored Cross-Site Scripting (XSS) vulnerability in Florent Maillefaud's WP Maintenance plugin <= 6.0.7 at WordPress.
5Debian
DrupalFedoraproject+2 more
10Debian Linux
FedoraH300s Firmware+7 more
Jun 17, 2026
Jul 20, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
jQuery UI is a curated set of user interface interactions, effects, widgets, and themes built on top of jQuery. Versions prior to 1.13.2 are potentially vulnerable to cross-site scripting. Initializing a checkboxradio wi...Show more
jQuery UI is a curated set of user interface interactions, effects, widgets, and themes built on top of jQuery. Versions prior to 1.13.2 are potentially vulnerable to cross-site scripting. Initializing a checkboxradio widget on an input enclosed within a label makes that parent label contents considered as the input label. Calling `.checkboxradio( "refresh" )` on such a widget and the initial HTML contained encoded HTML entities will make them erroneously get decoded. This can lead to potentially executing JavaScript code. The bug has been patched in jQuery UI 1.13.2. To remediate the issue, someone who can change the initial HTML can wrap all the non-input contents of the `label` in a `span`.Show less
1Thingsforrestaurants
1Quick Restaurant Reservations
Jun 17, 2026
Jul 20, 2022
N/A· v4
4.8 MEDIUM· v3
N/A· v2
Cross-site Scripting (XSS) vulnerability in ThingsForRestaurants Quick Restaurant Reservations (WordPress plugin) allows Reflected XSS.This issue affects Quick Restaurant Reservations (WordPress plugin): from n/a through...Show more
Cross-site Scripting (XSS) vulnerability in ThingsForRestaurants Quick Restaurant Reservations (WordPress plugin) allows Reflected XSS.This issue affects Quick Restaurant Reservations (WordPress plugin): from n/a through 1.4.1.Show less