← Back
CWE-79

47,394 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (47,394)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Maianmedia
1Maianaffiliate
Jun 17, 2026
Jun 16, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
A PHP code injection vulnerability in MaianAffiliate v.1.0 allows an authenticated attacker to gain RCE through the MaianAffiliate admin panel.
1Maianmedia
1Maianaffiliate
Jun 17, 2026
Jun 16, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A stored XSS vulnerability in MaianAffiliate v.1.0 allows an authenticated attacker for arbitrary JavaScript code execution in the context of authenticated and unauthenticated users through the MaianAffiliate admin panel...Show more
A stored XSS vulnerability in MaianAffiliate v.1.0 allows an authenticated attacker for arbitrary JavaScript code execution in the context of authenticated and unauthenticated users through the MaianAffiliate admin panel.Show less
1Phpgurukul
1Zoo Management System
Jun 17, 2026
Jun 16, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Zoo Management System v1.0 is vulnerable to Cross Site Scripting (XSS) via zms/admin/public_html/save_animal?an_id=24.
1Razormist
1Online Discussion Forum Site
Jun 17, 2026
Jun 16, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Online Discussion Forum Site v1.0 is vulnerable to Cross Site Scripting (XSS) via /odfs/classes/Master.php?f=save_category, name.
1Online Tutor Portal Site Project
1Online Tutor Portal Site
Jun 17, 2026
Jun 16, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Online Tutor Portal Site v1.0 is vulnerable to Cross Site Scripting (XSS). via /otps/classes/Master.php.
1Online Fire Reporting System Project
1Online Fire Reporting System
Jun 17, 2026
Jun 16, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Online Fire Reporting System v1.0 is vulnerable to Cross Site Scripting (XSS) via /ofrs/classes/Master.php.
1Angtech
1Haraj
Jun 17, 2026
Jun 16, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A cross-site scripting vulnerability in the DM Section component of Haraj v3.7 allows attackers to execute arbitrary web scripts or HTML via a crafted POST request.
1Intechnosoftware
1User Login Log
Nov 21, 2024
Jun 16, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A vulnerability was found in weblizar User Login Log Plugin 2.2.1. It has been classified as problematic. Affected is an unknown function. The manipulation leads to basic cross site scripting (Stored). It is possible to...Show more
A vulnerability was found in weblizar User Login Log Plugin 2.2.1. It has been classified as problematic. Affected is an unknown function. The manipulation leads to basic cross site scripting (Stored). It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.Show less
1Bestwebsoft
1Contact Form
Nov 21, 2024
Jun 16, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A vulnerability classified as problematic has been found in BestWebSoft Contact Form Plugin 4.0.0. This affects an unknown part. The manipulation leads to basic cross site scripting (Stored). It is possible to initiate t...Show more
A vulnerability classified as problematic has been found in BestWebSoft Contact Form Plugin 4.0.0. This affects an unknown part. The manipulation leads to basic cross site scripting (Stored). It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 4.0.2 is able to address this issue. It is recommended to upgrade the affected component.Show less
1Xyzscripts
1Contact Form Manager
Nov 21, 2024
Jun 16, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A vulnerability was found in XYZScripts Contact Form Manager Plugin. It has been rated as problematic. Affected by this issue is some unknown functionality. The manipulation leads to basic cross site scripting. The attac...Show more
A vulnerability was found in XYZScripts Contact Form Manager Plugin. It has been rated as problematic. Affected by this issue is some unknown functionality. The manipulation leads to basic cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.Show less
1Webnus
1Modern Events Calendar Lite
Jun 17, 2026
Jun 16, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-site scripting vulnerability in Modern Events Calendar Lite versions prior to 6.3.0 allows remote an authenticated attacker to inject an arbitrary script via unspecified vectors.
1Johnsoncontrols
3Metasys Application And Data Server
Metasys Extended Application And Data ServerMetasys Open Application Server
Jun 17, 2026
Jun 15, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Under certain circumstances, a vulnerability in Metasys ADS/ADX/OAS 10 versions prior to 10.1.5 and Metasys ADS/ADX/OAS 11 versions prior to 11.0.2 could allow a user to inject malicious code into the MUI Graphics web in...Show more
Under certain circumstances, a vulnerability in Metasys ADS/ADX/OAS 10 versions prior to 10.1.5 and Metasys ADS/ADX/OAS 11 versions prior to 11.0.2 could allow a user to inject malicious code into the MUI Graphics web interface.Show less
1Xakuro
1Xo Slider
Jun 17, 2026
Jun 15, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Authenticated (contributor or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in Xakuro's XO Slider plugin <= 3.3.2 at WordPress.
1Atlasgondal
1Export All Urls
Jun 17, 2026
Jun 15, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Authenticated (editor or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in Export All URLs plugin <= 4.1 at WordPress.
1Custom Popup Builder Project
1Custom Popup Builder
Jun 17, 2026
Jun 15, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Improper Access Control vulnerability leading to multiple Authenticated (contributor or higher user role) Stored Cross-Site Scripting (XSS) vulnerabilities in Muneeb's Custom Popup Builder plugin <= 1.3.1 at WordPress.
1Johnsoncontrols
3Metasys Application And Data Server
Metasys Extended Application And Data ServerMetasys Open Application Server
Jun 17, 2026
Jun 15, 2022
N/A· v4
5.4 MEDIUM· v3
2.1 LOW· v2
Under certain circumstances, a vulnerability in Metasys ADS/ADX/OAS 10 versions prior to 10.1.5 and Metasys ADS/ADX/OAS 11 versions prior to 11.0.2 could allow a user to inject malicious code into the web interface.
1Subscription Manager Project
1Subscription Manager
Jun 17, 2026
Jun 15, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Subscription-Manager v1.0 /main.js has a cross-site scripting (XSS) vulnerability in the machineDetail parameter.
1Nicdark
1Hotel Booking
Jun 17, 2026
Jun 15, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Multiple Authenticated (contributor or higher user role) Stored Cross-Site Scripting (XSS) vulnerabilities in Nicdark's Hotel Booking plugin <= 3.0 at WordPress.
1Vanderbilt
1Redcap
Jun 17, 2026
Jun 15, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A Stored Cross-Site Scripting (XSS) vulnerability was discovered in ProjectGeneral/edit_project_settings.php in REDCap 12.0.11. This issue allows any user with project management permissions to inject arbitrary code into...Show more
A Stored Cross-Site Scripting (XSS) vulnerability was discovered in ProjectGeneral/edit_project_settings.php in REDCap 12.0.11. This issue allows any user with project management permissions to inject arbitrary code into the project title (app_title) field when editing an existing project. The payload is then reflected within the title tag of the page.Show less
1Vanderbilt
1Redcap
Jun 17, 2026
Jun 15, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A Stored Cross-Site Scripting (XSS) vulnerability was discovered in Messenger/messenger_ajax.php in REDCap 12.0.11. This issue allows any authenticated user to inject arbitrary code into the messenger title (aka new_titl...Show more
A Stored Cross-Site Scripting (XSS) vulnerability was discovered in Messenger/messenger_ajax.php in REDCap 12.0.11. This issue allows any authenticated user to inject arbitrary code into the messenger title (aka new_title) field when editing an existing conversation. The payload executes in the browser of any conversation participant with the sidebar shown.Show less