← Back
CWE-79

47,387 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (47,387)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Air Transfer Project
1Air Transfer
Nov 21, 2024
Jun 27, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A vulnerability was found in Air Transfer 1.0.14/1.2.1. It has been rated as problematic. Affected by this issue is some unknown functionality. The manipulation leads to basic cross site scripting. The attack may be laun...Show more
A vulnerability was found in Air Transfer 1.0.14/1.2.1. It has been rated as problematic. Affected by this issue is some unknown functionality. The manipulation leads to basic cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.Show less
1Parse Url Project
1Parse Url
Jun 17, 2026
Jun 27, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site Scripting (XSS) - Stored in GitHub repository ionicabizau/parse-url prior to 7.0.0.
1Parse Url Project
1Parse Url
Jun 17, 2026
Jun 27, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site Scripting (XSS) - Generic in GitHub repository ionicabizau/parse-url prior to 7.0.0.
1Brizy
1Brizy
Jun 17, 2026
Jun 27, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The Brizy WordPress plugin before 2.4.2 does not sanitise and escape some element content, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks
1Brizy
1Brizy
Jun 17, 2026
Jun 27, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The Brizy WordPress plugin before 2.4.2 does not sanitise and escape some element URL, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks
1Miniorange
1Malware Scanner
Jun 17, 2026
Jun 27, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The Malware Scanner WordPress plugin before 4.5.2 does not sanitise and escape some of its settings, leading to malicious users with administrator privileges to store malicious Javascript code leading to Cross-Site Scrip...Show more
The Malware Scanner WordPress plugin before 4.5.2 does not sanitise and escape some of its settings, leading to malicious users with administrator privileges to store malicious Javascript code leading to Cross-Site Scripting attacks when unfiltered_html is disallowed (for example in multisite setup)Show less
1Miniorange
1Login With Otp Over Sms, Email, Whatsapp And Google Authenticator
Jun 17, 2026
Jun 27, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The Login With OTP Over SMS, Email, WhatsApp and Google Authenticator WordPress plugin before 1.0.8 does not escape its settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even w...Show more
The Login With OTP Over SMS, Email, WhatsApp and Google Authenticator WordPress plugin before 1.0.8 does not escape its settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowedShow less
1Kylephillips
1Nested Pages
Jun 17, 2026
Jun 27, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The Nested Pages WordPress plugin before 3.1.21 does not escape and sanitize the some of its settings, which could allow high privilege users to perform Stored Cross-Site Scripting attacks when the unfiltered_html is dis...Show more
The Nested Pages WordPress plugin before 3.1.21 does not escape and sanitize the some of its settings, which could allow high privilege users to perform Stored Cross-Site Scripting attacks when the unfiltered_html is disallowedShow less
1Wpgetready
1Nextcellent Gallery
Jun 17, 2026
Jun 27, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The NextCellent Gallery WordPress plugin through 1.9.35 does not sanitise and escape some of its image settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when th...Show more
The NextCellent Gallery WordPress plugin through 1.9.35 does not sanitise and escape some of its image settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed (for example in multisite setup)Show less
1Easy Svg Support Project
1Easy Svg Support
Jun 17, 2026
Jun 27, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The Easy SVG Support WordPress plugin before 3.3.0 does not sanitise uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads
1Pluginus
1Woot
Jun 17, 2026
Jun 27, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Active Products Tables for WooCommerce. Professional products tables for WooCommerce store WordPress plugin before 1.0.5 does not sanitise and escape a parameter before outputting it back in the response of an AJAX a...Show more
The Active Products Tables for WooCommerce. Professional products tables for WooCommerce store WordPress plugin before 1.0.5 does not sanitise and escape a parameter before outputting it back in the response of an AJAX action (available to both unauthenticated and authenticated users), leading to a Reflected cross-Site ScriptingShow less
1Fatcatapps
1Easy Pricing Tables
Jun 17, 2026
Jun 27, 2022
N/A· v4
6.1 MEDIUM· v3
2.6 LOW· v2
The Pricing Tables WordPress Plugin WordPress plugin before 3.2.1 does not sanitise and escape parameter before outputting it back in a page available to any user (both authenticated and unauthenticated) when a specific...Show more
The Pricing Tables WordPress Plugin WordPress plugin before 3.2.1 does not sanitise and escape parameter before outputting it back in a page available to any user (both authenticated and unauthenticated) when a specific setting is enabled, leading to a Reflected Cross-Site ScriptingShow less
1Icegram
1Popups, Welcome Bar, Optins And Lead Generation Plugin
Jun 17, 2026
Jun 27, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The Popups, Welcome Bar, Optins and Lead Generation Plugin WordPress plugin before 2.1.8 does not sanitize and escape some campaign parameters, which could allow users with a role as low as contributor to perform Stored...Show more
The Popups, Welcome Bar, Optins and Lead Generation Plugin WordPress plugin before 2.1.8 does not sanitize and escape some campaign parameters, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacksShow less
1Site Offline Or Coming Soon Project
1Site Offline Or Coming Soon
Jun 17, 2026
Jun 27, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Site Offline or Coming Soon WordPress plugin through 1.6.6 does not have CSRF check in place when updating its settings, and it also lacking sanitisation as well as escaping in some of them. As a result, attackers co...Show more
The Site Offline or Coming Soon WordPress plugin through 1.6.6 does not have CSRF check in place when updating its settings, and it also lacking sanitisation as well as escaping in some of them. As a result, attackers could make a logged in admin change them and put Cross-Site Scripting payloads in them via a CSRF attackShow less
1Ultimate Woocommerce Csv Importer Project
1Ultimate Woocommerce Csv Importer
Jun 17, 2026
Jun 27, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Ultimate WooCommerce CSV Importer WordPress plugin through 2.0 does not sanitise and escape the imported data before outputting it back in the page, leading to a Reflected Cross-Site Scripting
1Rich Web
1Image Gallery
Jun 17, 2026
Jun 27, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The Image Gallery WordPress plugin before 1.1.6 does not sanitize and escape some of its Image fields, which could allow high-privileged users such as admin to perform Cross-Site Scripting attacks even when unfiltered_ht...Show more
The Image Gallery WordPress plugin before 1.1.6 does not sanitize and escape some of its Image fields, which could allow high-privileged users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowedShow less
1Form Contact Form Project
1Form Contact Form
Jun 17, 2026
Jun 27, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The Form - Contact Form WordPress plugin through 1.2.0 does not sanitize and escape Custom text fields, which could allow high-privileged users such as admin to perform Cross-Site Scripting attacks even when unfiltered_h...Show more
The Form - Contact Form WordPress plugin through 1.2.0 does not sanitize and escape Custom text fields, which could allow high-privileged users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowedShow less
1Miniorange
1Google Authenticator
Jun 17, 2026
Jun 27, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The miniOrange's Google Authenticator WordPress plugin before 5.5.6 does not sanitise and escape some of its settings, leading to malicious users with administrator privileges to store malicious Javascript code leading t...Show more
The miniOrange's Google Authenticator WordPress plugin before 5.5.6 does not sanitise and escape some of its settings, leading to malicious users with administrator privileges to store malicious Javascript code leading to Cross-Site Scripting attacks when unfiltered_html is disallowed (for example in multisite setup)Show less
1Mihdan\
1 No External Links Project
Jun 17, 2026
Jun 27, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The Mihdan: No External Links WordPress plugin before 5.0.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when...Show more
The Mihdan: No External Links WordPress plugin before 5.0.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)Show less
1Miniorange
1Limit Login Attempts
Jun 17, 2026
Jun 27, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The Limit Login Attempts WordPress plugin before 4.0.72 does not sanitise and escape some of its settings, leading to malicious users with administrator privileges to store malicious Javascript code leading to Cross-Site...Show more
The Limit Login Attempts WordPress plugin before 4.0.72 does not sanitise and escape some of its settings, leading to malicious users with administrator privileges to store malicious Javascript code leading to Cross-Site Scripting attacks when unfiltered_html is disallowed (for example in multisite setup)Show less