CWE-79
47,383 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (47,383)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Simple Sales Management System Project 1Simple Sales Management System Jun 17, 2026 Jul 12, 2022 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 A vulnerability classified as problematic was found in SourceCodester Simple Sales Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /ci_ssms/index.php/orders/create. The manip...Show more |
1Hotel Management System Project 1Hotel Management System Jun 17, 2026 Jul 12, 2022 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 A vulnerability classified as problematic has been found in SourceCodester Hotel Management System 2.0. Affected is an unknown function of the file /ci_hms/massage_room/edit/1 of the component Room Edit Page. The manipul...Show more |
1Hotel Management System Project 1Hotel Management System Jun 17, 2026 Jul 12, 2022 N/A· v4 5.4 MEDIUM· v3 4.3 MEDIUM· v2 A vulnerability was found in SourceCodester Hotel Management System 2.0. It has been rated as problematic. This issue affects some unknown processing of the file /ci_hms/search of the component Search. The manipulation o...Show more |
1Whoogle Search Project 1Whoogle Search Jun 17, 2026 Jul 12, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The package whoogle-search before 0.7.2 are vulnerable to Cross-site Scripting (XSS) via the query string parameter q. In the case where it does not contain the http string, it is used to build the error_message that is...Show more |
EGT-Kommunikationstechnik UG Mediacenter before v2.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component Online_Update.php. |
Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in Event Management in Synology Calendar before 2.4.5-10930 allows remote authenticated users to inject arbitrary web scr...Show more |
The WP Duplicate Page WordPress plugin before 1.3 does not sanitize and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html...Show more |
1Wpovernight 1Woocommerce Pdf Invoices& Packing Slips Jun 17, 2026 Jul 11, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The WooCommerce PDF Invoices & Packing Slips WordPress plugin before 2.16.0 doesn't escape a parameter on its setting page, making it possible for attackers to conduct reflected cross-site scripting attacks. |
The Bold Page Builder WordPress plugin before 4.3.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_htm...Show more |
The WP-Paginate WordPress plugin before 2.1.9 does not escape one of its settings, which could allow high privilege users to perform Stored Cross-Site Scripting attacks when unfiltered_html is disallowed |
1Kitestudio 1Core Plugin For Kitestudio Themes Jun 17, 2026 Jul 11, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The core plugin for kitestudio WordPress plugin before 2.3.1 does not sanitise and escape some parameters before outputting them back in a response of an AJAX action, available to both unauthenticated and authenticated u...Show more |
The Awin Data Feed WordPress plugin before 1.8 does not sanitise and escape a header when processing request to generate analytics data, allowing unauthenticated users to perform Stored Cross-Site Scripting attacks again...Show more |
The Awin Data Feed WordPress plugin before 1.8 does not sanitise and escape a parameter before outputting it back via an AJAX action (available to both unauthenticated and authenticated users), leading to a Reflected Cro...Show more |
1Averta 1Shortcodes And Extra Features For Phlox Theme Jun 17, 2026 Jul 11, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The Shortcodes and extra features for Phlox WordPress plugin before 2.9.8 does not sanitise and escape a parameter before outputting it back in the response, leading to a Reflected Cross-Site Scripting |
The Popup Builder WordPress plugin before 4.1.11 does not escape and sanitize some settings, which could allow high privilege users to perform Stored Cross-Site Scripting attacks when the unfiltred_html is disallowed |
The pagebar WordPress plugin before 2.70 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack. Furthermore, due to the lack of...Show more |
1Visser 1Woocommerce Product Importer Jun 17, 2026 Jul 11, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The WooCommerce - Product Importer WordPress plugin through 1.5.2 does not sanitise and escape the imported data before outputting it back in the page, leading to a Reflected Cross-Site Scripting |
1Wp Eventmanager 1Wp Event Manager Jun 17, 2026 Jul 11, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The WP Event Manager WordPress plugin before 3.1.28 does not sanitise and escape its search before outputting it back in an attribute on the event dashboard, leading to a Reflected Cross-Site Scripting |
The FoxyShop WordPress plugin before 4.8.2 does not sanitise and escape a parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting |
H3C SSL VPN through 2022-07-10 allows wnm/login/login.json svpnlang cookie XSS. |