CWE-79
47,387 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (47,387)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Wp Spamfree Anti Spam Project 1Wp Spamfree Anti Spam Nov 21, 2024 Jun 24, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 A vulnerability classified as problematic has been found in WP-SpamFree Anti-Spam Plugin 2.1.1.4. This affects an unknown part. The manipulation leads to basic cross site scripting. It is possible to initiate the attack...Show more |
1Newstatpress Project 1Newstatpress Nov 21, 2024 Jun 24, 2022 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 A vulnerability, which was classified as problematic, has been found in NewStatPress Plugin 1.2.4. This issue affects some unknown processing. The manipulation leads to basic cross site scripting (Persistent). The attack...Show more |
1Yoast 1Google Analytics Dashboard Nov 21, 2024 Jun 24, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 A vulnerability classified as problematic was found in Google Analytics Dashboard Plugin 2.1.1. Affected by this vulnerability is an unknown functionality. The manipulation leads to basic cross site scripting. The attack...Show more |
1Simple Bakery Shop Management System Project 1Simple Bakery Shop Management System Jun 17, 2026 Jun 23, 2022 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 Multiple cross-site scripting (XSS) vulnerabilities in /bsms/?page=manage_account of Simple Bakery Shop Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into...Show more |
PMB 7.3.10 allows reflected XSS via the id parameter in an lvl=author_see request to index.php. |
1Jenkins 1Stash Branch Parameter Jun 17, 2026 Jun 23, 2022 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 Jenkins Stash Branch Parameter Plugin 0.3.0 and earlier does not escape the name and description of Stash Branch parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability e...Show more |
Jenkins Sauce OnDemand Plugin 1.204 and earlier does not escape the name and description of Sauce Labs Browsers parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability ex...Show more |
Jenkins REST List Parameter Plugin 1.5.2 and earlier does not escape the name and description of REST list parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploit...Show more |
Jenkins Repository Connector Plugin 2.2.0 and earlier does not escape the name and description of Maven Repository Artifact parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vuln...Show more |
Jenkins Readonly Parameter Plugin 1.0.0 and earlier does not escape the name and description of Readonly String and Readonly Text parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS...Show more |
Jenkins Package Version Plugin 1.0.1 and earlier does not escape the name of Package version parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attack...Show more |
Jenkins ontrack Jenkins Plugin 4.0.0 and earlier does not escape the name of Ontrack: Multi Parameter choice, Ontrack: Parameter choice, and Ontrack: SingleParameter parameters on views displaying parameters, resulting i...Show more |
1Jenkins 1Ns Nd Integration Performance Publisher Jun 17, 2026 Jun 23, 2022 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.77 and earlier does not escape the name of NetStorm Test parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerabil...Show more |
Jenkins Maven Metadata Plugin for Jenkins CI server Plugin 2.1 and earlier does not escape the name and description of List maven artifact versions parameters on views displaying parameters, resulting in a stored cross-s...Show more |
Jenkins Image Tag Parameter Plugin 1.10 and earlier does not escape the name and description of Image Tag parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploita...Show more |
Jenkins Hidden Parameter Plugin 0.0.4 and earlier does not escape the name and description of Hidden Parameter parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exp...Show more |
1Jenkins 1Filesystem List Parameter Jun 17, 2026 Jun 23, 2022 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 Jenkins Filesystem List Parameter Plugin 0.0.7 and earlier does not escape the name and description of File system objects list parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS)...Show more |
1Jenkins 1Dynamic Extended Choice Parameter Jun 17, 2026 Jun 23, 2022 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 Jenkins Dynamic Extended Choice Parameter Plugin 1.0.1 and earlier does not escape the name and description of Moded Extended Choice parameters on views displaying parameters, resulting in a stored cross-site scripting (...Show more |
Jenkins Date Parameter Plugin 0.0.4 and earlier does not escape the name and description of Date parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by at...Show more |
1Jenkins 1Crx Content Package Deployer Jun 17, 2026 Jun 23, 2022 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 Jenkins CRX Content Package Deployer Plugin 1.9 and earlier does not escape the name and description of CRX Content Package Choice parameters on views displaying parameters, resulting in a stored cross-site scripting (XS...Show more |