← Back
CWE-79

47,393 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (47,393)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Webkul
1Krayin
Jun 17, 2026
Jun 21, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Webkul krayin crm before 1.2.2 is vulnerable to Cross Site Scripting (XSS).
1Unioncms Project
1Unioncms
Jul 9, 2026
Jun 21, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Unioncms v1.0.13 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Default settings.
1Nuuo
1Nvrsolo Firmware
Jun 17, 2026
Jun 21, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
NUUO Network Video Recorder NVRsolo v03.06.02 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via login.php.
1Contec
1Sv Cpt Mc310 Firmware
Jun 17, 2026
Jun 21, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
SolarView Compact v6.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component Solar_AiConf.php.
1Maccms
1Maccms
Jun 17, 2026
Jun 21, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
maccms10 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Server Group text field.
1Maccms
1Maccms
Jun 17, 2026
Jun 21, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
maccms8 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Server Group text field.
1Tandoor
1Recipes
Jun 17, 2026
Jun 21, 2022
N/A· v4
N/A· v3
3.5 LOW· v2
In Recipes, versions 0.17.0 through 1.2.5 are vulnerable to Stored Cross-Site Scripting (XSS), in the ‘Name’ field of Keyword, Food and Unit components. When a victim accesses the Keyword/Food/Unit endpoints, the XSS pay...Show more
In Recipes, versions 0.17.0 through 1.2.5 are vulnerable to Stored Cross-Site Scripting (XSS), in the ‘Name’ field of Keyword, Food and Unit components. When a victim accesses the Keyword/Food/Unit endpoints, the XSS payload will trigger. A low privileged attacker will have the victim's API key and can lead to admin's account takeover.Show less
1Tandoor
1Recipes
Jun 17, 2026
Jun 21, 2022
N/A· v4
N/A· v3
3.5 LOW· v2
In Recipes, versions 1.0.5 through 1.2.5 are vulnerable to Stored Cross-Site Scripting (XSS), in copy to clipboard functionality. When a victim accesses the food list page, then adds a new Food with a malicious javascrip...Show more
In Recipes, versions 1.0.5 through 1.2.5 are vulnerable to Stored Cross-Site Scripting (XSS), in copy to clipboard functionality. When a victim accesses the food list page, then adds a new Food with a malicious javascript payload in the ‘Name’ parameter and clicks on the clipboard icon, an XSS payload will trigger. A low privileged attacker will have the victim's API key and can lead to admin's account takeover.Show less
1Tandoor
1Recipes
Jun 17, 2026
Jun 21, 2022
N/A· v4
N/A· v3
3.5 LOW· v2
In Recipes, versions 1.0.5 through 1.2.5 are vulnerable to Stored Cross-Site Scripting (XSS), in “Add to Cart” functionality. When a victim accesses the food list page, then adds a new Food with a malicious javascript pa...Show more
In Recipes, versions 1.0.5 through 1.2.5 are vulnerable to Stored Cross-Site Scripting (XSS), in “Add to Cart” functionality. When a victim accesses the food list page, then adds a new Food with a malicious javascript payload in the ‘Name’ parameter and clicks on the Add to Shopping Cart icon, an XSS payload will trigger. A low privileged attacker will have the victim's API key and can lead to admin's account takeover.Show less
1Acquia
1Mautic
Jun 17, 2026
Jun 20, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A cross-site scripting (XSS) vulnerability in the web tracking component of Mautic before 4.3.0 allows remote attackers to inject executable javascript
1Colorlib
1Coming Soon & Maintenance Mode
Jun 17, 2026
Jun 20, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The Coming Soon & Maintenance Mode by Colorlib WordPress plugin before 1.0.99 does not sanitize and escape some settings, allowing high privilege users such as admin to perform Stored Cross-Site Scripting when unfiltered...Show more
The Coming Soon & Maintenance Mode by Colorlib WordPress plugin before 1.0.99 does not sanitize and escape some settings, allowing high privilege users such as admin to perform Stored Cross-Site Scripting when unfiltered_html is disallowed (for example in multisite setup)Show less
1Wpreviewslider
1Wp Zillow Review Slider
Jun 17, 2026
Jun 20, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The WP Zillow Review Slider WordPress plugin before 2.4 does not escape a settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (f...Show more
The WP Zillow Review Slider WordPress plugin before 2.4 does not escape a settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite)Show less
1Underconstruction Project
1Underconstruction
Jun 17, 2026
Jun 20, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The underConstruction WordPress plugin before 1.21 does not sanitise or escape the "Display a custom page using your own HTML" setting before outputting it, allowing high privilege users to perform Cross-Site Scripting a...Show more
The underConstruction WordPress plugin before 1.21 does not sanitise or escape the "Display a custom page using your own HTML" setting before outputting it, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiletred_html capability is disallowed.Show less
1Thenewsletterplugin
1Newsletter
Jun 17, 2026
Jun 20, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The Newsletter WordPress plugin before 7.4.6 does not escape and sanitise the preheader_text setting, which could allow high privilege users to perform Stored Cross-Site Scripting attacks when the unfilteredhtml is disal...Show more
The Newsletter WordPress plugin before 7.4.6 does not escape and sanitise the preheader_text setting, which could allow high privilege users to perform Stored Cross-Site Scripting attacks when the unfilteredhtml is disallowedShow less
1Wp Experts
1Custom Share Buttons With Floating Sidebar
Jun 17, 2026
Jun 20, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The Custom Share Buttons with Floating Sidebar WordPress plugin before 4.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting at...Show more
The Custom Share Buttons with Floating Sidebar WordPress plugin before 4.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowedShow less
1Wpwax
1Post Grid, Slider & Carousel Ultimate
Jun 17, 2026
Jun 20, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The Post Grid, Slider & Carousel Ultimate WordPress plugin before 1.5.0 does not sanitise and escape the Header Title, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfilter...Show more
The Post Grid, Slider & Carousel Ultimate WordPress plugin before 1.5.0 does not sanitise and escape the Header Title, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.Show less
1Printfriendly
1Print, Pdf, Email By Printfriendly
Jun 17, 2026
Jun 20, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The Print, PDF, Email by PrintFriendly WordPress plugin before 5.2.3 does not sanitise and escape the Custom Button Text settings, which could allow high privilege users such as admin to perform cross-Site Scripting atta...Show more
The Print, PDF, Email by PrintFriendly WordPress plugin before 5.2.3 does not sanitise and escape the Custom Button Text settings, which could allow high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowedShow less
1Oceanwp
1Ocean Extra
Jun 17, 2026
Jun 20, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Ocean Extra WordPress plugin before 1.9.5 does not escape generated links which are then used when the OceanWP is active, leading to a Reflected Cross-Site Scripting issue
1Google Xml Sitemaps Project
1Google Xml Sitemaps
Jun 17, 2026
Jun 20, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The XML Sitemaps WordPress plugin before 4.1.3 does not sanitise and escape a settings before outputting it in the Debug page, which could allow high privilege users to perform Cross-Site Scripting attacks even when the...Show more
The XML Sitemaps WordPress plugin before 4.1.3 does not sanitise and escape a settings before outputting it in the Debug page, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)Show less
1Cisco
2Ws C2940 8tf S Firmware
Ws C2940 8tt S Firmware
Jun 17, 2026
Jun 20, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cisco Catalyst 2940 Series Switches provided by Cisco Systems, Inc. contain a reflected cross-site scripting vulnerability regarding error page generation. An arbitrary script may be executed on the web browser of the us...Show more
Cisco Catalyst 2940 Series Switches provided by Cisco Systems, Inc. contain a reflected cross-site scripting vulnerability regarding error page generation. An arbitrary script may be executed on the web browser of the user who is using the product. The affected firmware is prior to 12.2(50)SY released in 2011, and Cisco Catalyst 2940 Series Switches have been retired since January 2015Show less