← Back
CWE-79

47,395 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (47,395)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Nocodb
1Nocodb
Jun 17, 2026
Jun 14, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-site Scripting (XSS) - Stored in GitHub repository nocodb/nocodb prior to 0.91.7+.
1Ss Proj
1Shirasagi
Jun 17, 2026
Jun 14, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting vulnerability in SHIRASAGI v1.0.0 to v1.14.2, and v1.15.0 allows a remote attacker to inject an arbitrary script via unspecified vectors.
11234n
1Minicms
Jul 9, 2026
Jun 13, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A cross-site scripting (XSS) vulnerability exists in Mini CMS V1.11. The vulnerability exists in the article upload: post-edit.php page.
1Elementor
1Website Builder
Jun 17, 2026
Jun 13, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
DOM-based Reflected Cross-Site Scripting (XSS) vulnerability in Elementor's Elementor Website Builder plugin <= 3.5.5 versions.
1Gtm4wp
1Google Tag Manager
Jun 17, 2026
Jun 13, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The Google Tag Manager for WordPress (GTM4WP) plugin is vulnerable to Stored Cross-Site Scripting due to insufficient escaping via the `gtm4wp-options[scroller-contentid]` parameter found in the `~/public/frontend.php` f...Show more
The Google Tag Manager for WordPress (GTM4WP) plugin is vulnerable to Stored Cross-Site Scripting due to insufficient escaping via the `gtm4wp-options[scroller-contentid]` parameter found in the `~/public/frontend.php` file which allowed attackers with administrative user access to inject arbitrary web scripts, in versions up to and including 1.15.1. This affects multi-site installations where unfiltered_html is disabled for administrators, and sites where unfiltered_html is disabled.Show less
1Androidbubbles
1Keep Backup Daily
Jun 17, 2026
Jun 13, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Keep Backup Daily plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘t’ parameter in versions up to, and including, 2.0.2 due to insufficient input sanitization and output escaping. This ma...Show more
The Keep Backup Daily plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘t’ parameter in versions up to, and including, 2.0.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.Show less
1Sticky Popup Project
1Sticky Popup
Jun 17, 2026
Jun 13, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The Sticky Popup plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘ popup_title' parameter in versions up to, and including, 1.2 due to insufficient input sanitization and output escaping. This m...Show more
The Sticky Popup plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘ popup_title' parameter in versions up to, and including, 1.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with admin level capabilities and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This issue mostly affects sites where unfiltered_html has been disabled for administrators and on multi-site installations where unfiltered_html is disabled for administrators.Show less
1Facebook Wall And Social Integration Project
1Facebook Wall And Social Integration
Jun 17, 2026
Jun 13, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The Mitsol Social Post Feed WordPress plugin before 1.11 does not escape some of its settings before outputting them back in attributes, which could allow high privilege users such as admin to perform cross-Site Scriptin...Show more
The Mitsol Social Post Feed WordPress plugin before 1.11 does not escape some of its settings before outputting them back in attributes, which could allow high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowedShow less
1Helpdeskz
1Helpdeskz
Jun 17, 2026
Jun 13, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
A cross-site scripting (XSS) vulnerability in /staff/setup/email-addresses of Helpdeskz v2.0.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the email name field.
1Helpdeskz
1Helpdeskz
Jun 17, 2026
Jun 13, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
A cross-site scripting (XSS) vulnerability in /staff/tools/custom-fields of Helpdeskz v2.0.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the email name field.
1Facturascripts
1Facturascripts
Jun 17, 2026
Jun 13, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site Scripting (XSS) - Reflected in GitHub repository neorazorx/facturascripts prior to 2022.06.
1Facturascripts
1Facturascripts
Jun 17, 2026
Jun 13, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-site Scripting (XSS) - Stored in GitHub repository neorazorx/facturascripts prior to 2022.06.
1W3eden
1Download Manager
Jun 17, 2026
Jun 13, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Download Manager Plugin for WordPress is vulnerable to reflected Cross-Site Scripting in versions up to, and including 3.2.42. This is due to insufficient input sanitization and output escaping on the 'frameid' param...Show more
The Download Manager Plugin for WordPress is vulnerable to reflected Cross-Site Scripting in versions up to, and including 3.2.42. This is due to insufficient input sanitization and output escaping on the 'frameid' parameter found in the ~/src/Package/views/shortcode-iframe.php file.Show less
1Zephyr Project Manager Project
1Zephyr Project Manager
Jun 17, 2026
Jun 13, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Zephyr Project Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘project’ parameter in versions up to, and including, 3.2.40 due to insufficient input sanitization and output escap...Show more
The Zephyr Project Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘project’ parameter in versions up to, and including, 3.2.40 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.Show less
1Wp Admin Style Project
1Wp Admin Style
Jun 17, 2026
Jun 13, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The WP Admin Style WordPress plugin through 0.1.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered...Show more
The WP Admin Style WordPress plugin through 0.1.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowedShow less
1Wp Athletics Project
1Wp Athletics
Jun 17, 2026
Jun 13, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The WP Athletics WordPress plugin through 1.1.7 does not sanitise and escape a parameter before outputting back in an admin page, leading to a Reflected Cross-Site Scripting
1Google Places Reviews Project
1Google Places Reviews
Jun 17, 2026
Jun 13, 2022
N/A· v4
4.8 MEDIUM· v3
2.1 LOW· v2
The Google Places Reviews WordPress plugin before 2.0.0 does not properly escape its Google API key setting, which is reflected on the site's administration panel. A malicious administrator could abuse this bug, in a mul...Show more
The Google Places Reviews WordPress plugin before 2.0.0 does not properly escape its Google API key setting, which is reflected on the site's administration panel. A malicious administrator could abuse this bug, in a multisite WordPress configuration, to trick super-administrators into viewing the booby-trapped payload and taking over their account.Show less
1Thenewsletterplugin
1Newsletter
Jun 17, 2026
Jun 13, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Newsletter WordPress plugin before 7.4.5 does not sanitize and escape the $_SERVER['REQUEST_URI'] before echoing it back in admin pages. Although this uses addslashes, and most modern browsers automatically URLEncode...Show more
The Newsletter WordPress plugin before 7.4.5 does not sanitize and escape the $_SERVER['REQUEST_URI'] before echoing it back in admin pages. Although this uses addslashes, and most modern browsers automatically URLEncode requests, this is still vulnerable to Reflected XSS in older browsers such as Internet Explorer 9 or below.Show less
1Simple Membership Plugin
1Simple Membership
Jun 17, 2026
Jun 13, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Simple Membership WordPress plugin before 4.1.1 does not properly sanitise and escape parameters before outputting them back in AJAX actions, leading to Reflected Cross-Site Scripting
1Dwbooster
1Appointment Hour Booking
Jun 17, 2026
Jun 13, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The Appointment Hour Booking WordPress plugin before 1.3.56 does not sanitise and escape a settings of its Calendar fields, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unf...Show more
The Appointment Hour Booking WordPress plugin before 1.3.56 does not sanitise and escape a settings of its Calendar fields, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed.Show less