← Back
CWE-79

47,383 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (47,383)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Gentics
1Gentics Cms
Jun 17, 2026
Jul 17, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
An issue was discovered in Gentics CMS before 5.43.1. There is stored XSS in the profile description and in the username.
1Tipsandtricks Hq
1Accept Stripe
Jun 17, 2026
Jul 17, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The Accept Stripe Payments WordPress plugin before 2.0.64 does not sanitize and escape some of its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_ht...Show more
The Accept Stripe Payments WordPress plugin before 2.0.64 does not sanitize and escape some of its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.Show less
1Contact Form 7 Captcha Project
1Contact Form 7 Captcha
Jun 17, 2026
Jul 17, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Contact Form 7 Captcha WordPress plugin before 0.1.2 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web brow...Show more
The Contact Form 7 Captcha WordPress plugin before 0.1.2 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsersShow less
1Bracketspace
1Simple Post Notes
Jun 17, 2026
Jul 17, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The Simple Post Notes WordPress plugin before 1.7.6 does not sanitise and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability...Show more
The Simple Post Notes WordPress plugin before 1.7.6 does not sanitise and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.Show less
1Sigmaplugin
1Advanced Database Cleaner
Jun 17, 2026
Jul 17, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Advanced Database Cleaner WordPress plugin before 3.1.1 does not escape numerous generated URLs before outputting them back in href attributes of admin dashboard pages, leading to Reflected Cross-Site Scripting
1Dwbooster
1Loading Page With Loading Screen
Jun 17, 2026
Jul 17, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The Loading Page with Loading Screen WordPress plugin before 1.0.83 does not escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capabili...Show more
The Loading Page with Loading Screen WordPress plugin before 1.0.83 does not escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.Show less
1W3eden
1Download Manager
Jun 17, 2026
Jul 17, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Download Manager WordPress plugin before 3.2.44 does not escape a generated URL before outputting it back in an attribute of the history dashboard, leading to Reflected Cross-Site Scripting
1Emarketdesign
1Best Contact Management Software
Jun 17, 2026
Jul 17, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The Best Contact Management Software WordPress plugin through 3.7.3 does not sanitise and escape its settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_...Show more
The Best Contact Management Software WordPress plugin through 3.7.3 does not sanitise and escape its settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.Show less
1Very Simple Breadcrumb Project
1Very Simple Breadcrumb
Jun 17, 2026
Jul 17, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The Very Simple Breadcrumb WordPress plugin through 1.0 does not sanitise and escape its settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capabil...Show more
The Very Simple Breadcrumb WordPress plugin through 1.0 does not sanitise and escape its settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.Show less
1Linkedin Company Updates Project
1Linkedin Company Updates
Jun 17, 2026
Jul 17, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The LinkedIn Company Updates WordPress plugin through 1.5.3 does not sanitise and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html cap...Show more
The LinkedIn Company Updates WordPress plugin through 1.5.3 does not sanitise and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.Show less
1Tooltulips
1404s
Jun 17, 2026
Jul 17, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The 404s WordPress plugin before 3.5.1 does not sanitise and escape its fields, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
1Supsystic
1Data Tables Generator
Jun 17, 2026
Jul 17, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The Data Tables Generator by Supsystic WordPress plugin before 1.10.20 does not sanitise and escape some of its Table settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting...Show more
The Data Tables Generator by Supsystic WordPress plugin before 1.10.20 does not sanitise and escape some of its Table settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed (for example in multisite setup)Show less
1Wpzinc
1Page Generator
Jun 17, 2026
Jul 17, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The Page Generator WordPress plugin before 1.6.5 does not sanitise and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is...Show more
The Page Generator WordPress plugin before 1.6.5 does not sanitise and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.Show less
1Flycart
1Discount Rules For Woocommerce
Jun 17, 2026
Jul 17, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Discount Rules for WooCommerce WordPress plugin before 2.4.2 does not escape a parameter before outputting it back in an attribute of the plugin's discount rule page, leading to Reflected Cross-Site Scripting
1Collect And Deliver Interface For Woocommerce Project
1Collect And Deliver Interface For Woocommerce
Jun 17, 2026
Jul 17, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The CDI WordPress plugin before 5.1.9 does not sanitise and escape a parameter before outputting it back in the response of an AJAX action (available to both unauthenticated and authenticated users), leading to a Reflect...Show more
The CDI WordPress plugin before 5.1.9 does not sanitise and escape a parameter before outputting it back in the response of an AJAX action (available to both unauthenticated and authenticated users), leading to a Reflected Cross-Site ScriptingShow less
1Angularjs
1Angularjs
Jun 17, 2026
Jul 15, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
All versions of the package angular; all versions of the package angularjs.core; all versions of the package angularjs are vulnerable to Cross-site Scripting (XSS) due to insecure page caching in the Internet Explorer br...Show more
All versions of the package angular; all versions of the package angularjs.core; all versions of the package angularjs are vulnerable to Cross-site Scripting (XSS) due to insecure page caching in the Internet Explorer browser, which allows interpolation of <textarea> elements.Show less
1Adobe
1Robohelp
Jun 17, 2026
Jul 15, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Adobe RoboHelp versions 2020.0.7 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious Java...Show more
Adobe RoboHelp versions 2020.0.7 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.Show less
1Gollum Project
1Gollum
Jul 9, 2026
Jul 15, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Cross site scripting (XSS) in gollum 5.0 to 5.1.2 via the filename parameter to the 'New Page' dialog.
1Arox
1School Erp Pro
Jun 17, 2026
Jul 15, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Arox School ERP Pro v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the dispatchcategory parameter in backoffice.inc.php.
2Grafana
Netapp
2E Series Performance Analyzer
Grafana
Jun 17, 2026
Jul 15, 2022
N/A· v4
8.7 HIGH· v3
N/A· v2
Grafana is an open-source platform for monitoring and observability. Versions on the 8.x and 9.x branch prior to 9.0.3, 8.5.9, 8.4.10, and 8.3.10 are vulnerable to stored cross-site scripting via the Unified Alerting fea...Show more
Grafana is an open-source platform for monitoring and observability. Versions on the 8.x and 9.x branch prior to 9.0.3, 8.5.9, 8.4.10, and 8.3.10 are vulnerable to stored cross-site scripting via the Unified Alerting feature of Grafana. An attacker can exploit this vulnerability to escalate privilege from editor to admin by tricking an authenticated admin to click on a link. Versions 9.0.3, 8.5.9, 8.4.10, and 8.3.10 contain a patch. As a workaround, it is possible to disable alerting or use legacy alerting.Show less