← Back
CWE-79

47,383 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (47,383)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Simple Sales Management System Project
1Simple Sales Management System
Jun 17, 2026
Jul 12, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A vulnerability classified as problematic was found in SourceCodester Simple Sales Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /ci_ssms/index.php/orders/create. The manip...Show more
A vulnerability classified as problematic was found in SourceCodester Simple Sales Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /ci_ssms/index.php/orders/create. The manipulation of the argument customer_name with the input <script>alert("XSS")</script> leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.Show less
1Hotel Management System Project
1Hotel Management System
Jun 17, 2026
Jul 12, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A vulnerability classified as problematic has been found in SourceCodester Hotel Management System 2.0. Affected is an unknown function of the file /ci_hms/massage_room/edit/1 of the component Room Edit Page. The manipul...Show more
A vulnerability classified as problematic has been found in SourceCodester Hotel Management System 2.0. Affected is an unknown function of the file /ci_hms/massage_room/edit/1 of the component Room Edit Page. The manipulation of the argument massageroomDetails with the input "><script>alert("XSS")</script> leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.Show less
1Hotel Management System Project
1Hotel Management System
Jun 17, 2026
Jul 12, 2022
N/A· v4
5.4 MEDIUM· v3
4.3 MEDIUM· v2
A vulnerability was found in SourceCodester Hotel Management System 2.0. It has been rated as problematic. This issue affects some unknown processing of the file /ci_hms/search of the component Search. The manipulation o...Show more
A vulnerability was found in SourceCodester Hotel Management System 2.0. It has been rated as problematic. This issue affects some unknown processing of the file /ci_hms/search of the component Search. The manipulation of the argument search with the input "><script>alert("XSS")</script> leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.Show less
1Whoogle Search Project
1Whoogle Search
Jun 17, 2026
Jul 12, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The package whoogle-search before 0.7.2 are vulnerable to Cross-site Scripting (XSS) via the query string parameter q. In the case where it does not contain the http string, it is used to build the error_message that is...Show more
The package whoogle-search before 0.7.2 are vulnerable to Cross-site Scripting (XSS) via the query string parameter q. In the case where it does not contain the http string, it is used to build the error_message that is then rendered in the error.html template, using the [flask.render_template](https://flask.palletsprojects.com/en/2.1.x/api/flask.render_template) function. However, the error_message is rendered using the [| safe filter](https://jinja.palletsprojects.com/en/3.1.x/templates/working-with-automatic-escaping), meaning the user input is not escaped.Show less
1Uberrider
1Mediacenter
Jul 9, 2026
Jul 12, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
EGT-Kommunikationstechnik UG Mediacenter before v2.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component Online_Update.php.
1Synology
1Calendar
Jun 17, 2026
Jul 12, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in Event Management in Synology Calendar before 2.4.5-10930 allows remote authenticated users to inject arbitrary web scr...Show more
Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in Event Management in Synology Calendar before 2.4.5-10930 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.Show less
1Ninjateam
1Wp Duplicate Page
Jun 17, 2026
Jul 11, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The WP Duplicate Page WordPress plugin before 1.3 does not sanitize and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html...Show more
The WP Duplicate Page WordPress plugin before 1.3 does not sanitize and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed.Show less
1Wpovernight
1Woocommerce Pdf Invoices& Packing Slips
Jun 17, 2026
Jul 11, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The WooCommerce PDF Invoices & Packing Slips WordPress plugin before 2.16.0 doesn't escape a parameter on its setting page, making it possible for attackers to conduct reflected cross-site scripting attacks.
1Bold Themes
1Bold Page Builder
Jun 17, 2026
Jul 11, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The Bold Page Builder WordPress plugin before 4.3.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_htm...Show more
The Bold Page Builder WordPress plugin before 4.3.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed.Show less
1Maxfoundry
1Wp Paginate
Jun 17, 2026
Jul 11, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The WP-Paginate WordPress plugin before 2.1.9 does not escape one of its settings, which could allow high privilege users to perform Stored Cross-Site Scripting attacks when unfiltered_html is disallowed
1Kitestudio
1Core Plugin For Kitestudio Themes
Jun 17, 2026
Jul 11, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The core plugin for kitestudio WordPress plugin before 2.3.1 does not sanitise and escape some parameters before outputting them back in a response of an AJAX action, available to both unauthenticated and authenticated u...Show more
The core plugin for kitestudio WordPress plugin before 2.3.1 does not sanitise and escape some parameters before outputting them back in a response of an AJAX action, available to both unauthenticated and authenticated users when a premium theme from the vendor is active, leading to a Reflected Cross-Site Scripting.Show less
1Awin
1Awin Data Feed
Jun 17, 2026
Jul 11, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The Awin Data Feed WordPress plugin before 1.8 does not sanitise and escape a header when processing request to generate analytics data, allowing unauthenticated users to perform Stored Cross-Site Scripting attacks again...Show more
The Awin Data Feed WordPress plugin before 1.8 does not sanitise and escape a header when processing request to generate analytics data, allowing unauthenticated users to perform Stored Cross-Site Scripting attacks against a logged in admin viewing the plugin's settingsShow less
1Awin
1Awin Data Feed
Jun 17, 2026
Jul 11, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Awin Data Feed WordPress plugin before 1.8 does not sanitise and escape a parameter before outputting it back via an AJAX action (available to both unauthenticated and authenticated users), leading to a Reflected Cro...Show more
The Awin Data Feed WordPress plugin before 1.8 does not sanitise and escape a parameter before outputting it back via an AJAX action (available to both unauthenticated and authenticated users), leading to a Reflected Cross-Site ScriptingShow less
1Averta
1Shortcodes And Extra Features For Phlox Theme
Jun 17, 2026
Jul 11, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Shortcodes and extra features for Phlox WordPress plugin before 2.9.8 does not sanitise and escape a parameter before outputting it back in the response, leading to a Reflected Cross-Site Scripting
1Sygnoos
1Popup Builder
Jun 17, 2026
Jul 11, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The Popup Builder WordPress plugin before 4.1.11 does not escape and sanitize some settings, which could allow high privilege users to perform Stored Cross-Site Scripting attacks when the unfiltred_html is disallowed
1Pagebar Project
1Pagebar
Jun 17, 2026
Jul 11, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The pagebar WordPress plugin before 2.70 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack. Furthermore, due to the lack of...Show more
The pagebar WordPress plugin before 2.70 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack. Furthermore, due to the lack of sanitisation in some of them, it could also lead to Stored XSS issuesShow less
1Visser
1Woocommerce Product Importer
Jun 17, 2026
Jul 11, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The WooCommerce - Product Importer WordPress plugin through 1.5.2 does not sanitise and escape the imported data before outputting it back in the page, leading to a Reflected Cross-Site Scripting
1Wp Eventmanager
1Wp Event Manager
Jun 17, 2026
Jul 11, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The WP Event Manager WordPress plugin before 3.1.28 does not sanitise and escape its search before outputting it back in an attribute on the event dashboard, leading to a Reflected Cross-Site Scripting
1Foxy Shop
1Foxyshop
Jun 17, 2026
Jul 11, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The FoxyShop WordPress plugin before 4.8.2 does not sanitise and escape a parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting
1H3c
1Ssl Vpn
Jun 17, 2026
Jul 11, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
H3C SSL VPN through 2022-07-10 allows wnm/login/login.json svpnlang cookie XSS.