CWE-79
47,395 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (47,395)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The Google Tag Manager for WordPress plugin for WordPress is vulnerable to reflected Cross-Site Scripting via the s parameter due to the site search populating into the data layer of sites with insufficient sanitization...Show more |
1Mailerlite 1Mailerlite Signup Forms Jun 17, 2026 Jun 13, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The MailerLite WordPress plugin before 1.5.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting |
1Wp Athletics Project 1Wp Athletics Jun 17, 2026 Jun 13, 2022 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 The WP Athletics WordPress plugin through 1.1.7 does not sanitize parameters before storing them in the database, nor does it escape the values when outputting them back in the admin dashboard, leading to a Stored Cross-...Show more |
1Themify 1Woocommerce Product Filter Jun 17, 2026 Jun 13, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Themify WordPress plugin before 1.3.8 does not sanitise and escape the page parameter before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Site Scripting |
The Carousel CK WordPress plugin through 1.1.0 does not sanitize and escape Slide's descriptions, which could allow high-privileged users such as admin to perform Cross-Site Scripting attacks when unfiltered_html is disa...Show more |
The Slideshow CK WordPress plugin before 1.4.10 does not sanitize and escape Slide's descriptions, which could allow high-privileged users such as admin to perform Cross-Site Scripting attacks when unfiltered_html is dis...Show more |
1Ultimatemember 1Ultimate Member Jun 17, 2026 Jun 13, 2022 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 The Ultimate Member plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Biography field featured on individual user profile pages due to insufficient input sanitization and output escaping that allo...Show more |
1Kuroit 1Advanced Admin Search Jun 17, 2026 Jun 13, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The Advanced Admin Search WordPress plugin before 1.1.6 does not sanitize and escape some parameters before outputting them back in an admin page, leading to a Reflected Cross-Site Scripting. |
flatCore-CMS version 2.0.8 is affected by Cross Site Scripting (XSS) in the "Create New Page" option through the index page. |
Cross-site Scripting (XSS) - Stored in GitHub repository dolibarr/dolibarr prior to 16.0. |
A vulnerability was found in Navetti PricePoint 4.6.0.0. It has been classified as problematic. This affects an unknown part. The manipulation leads to basic cross site scripting (Reflected). It is possible to initiate t...Show more |
A vulnerability was found in Navetti PricePoint 4.6.0.0 and classified as problematic. Affected by this issue is some unknown functionality. The manipulation leads to basic cross site scripting (Persistent). The attack m...Show more |
Strapi v3.x.x versions and earlier contain a stored cross-site scripting vulnerability in file upload function. By exploiting this vulnerability, an arbitrary script may be executed on the web browser of the user who is...Show more |
Cross-site scripting vulnerability exists in WP Statistics versions prior to 13.2.0 because it improperly processes a platform parameter. By exploiting this vulnerability, an arbitrary script may be executed on the web b...Show more |
A cross-site scripting (XSS) vulnerability in the SEOmatic plugin 3.4.10 for Craft CMS 3 allows remote attackers to inject arbitrary web script via a GET to /index.php?action=seomatic/file/seo-file-link with url paramete...Show more |
1Technicolor 1Thomson Tcw710 Firmware Nov 21, 2024 Jun 12, 2022 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 A vulnerability was found in Thomson TCW710 ST5D.10.05. It has been declared as problematic. This vulnerability affects unknown code of the file /goform/RgUrlBlock.asp. The manipulation of the argument BasicParentalNewKe...Show more |
1Technicolor 1Thomson Tcw710 Firmware Nov 21, 2024 Jun 12, 2022 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 A vulnerability was found in Thomson TCW710 ST5D.10.05. It has been classified as problematic. This affects an unknown part of the file /goform/RgDhcp. The manipulation of the argument PppUserName with the input ><script...Show more |
1Technicolor 1Thomson Tcw710 Firmware Nov 21, 2024 Jun 12, 2022 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 A vulnerability was found in Thomson TCW710 ST5D.10.05 and classified as problematic. Affected by this issue is some unknown functionality of the file /goform/RgDdns. The manipulation of the argument DdnsHostName with th...Show more |
1Technicolor 1Thomson Tcw710 Firmware Nov 21, 2024 Jun 12, 2022 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 A vulnerability has been found in Thomson TCW710 ST5D.10.05 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /goform/RgTime. The manipulation of the argument TimeServe...Show more |
1Technicolor 1Thomson Tcw710 Firmware Nov 21, 2024 Jun 12, 2022 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 A vulnerability, which was classified as problematic, was found in Thomson TCW710 ST5D.10.05. Affected is an unknown function of the file /goform/RGFirewallEL. The manipulation of the argument EmailAddress/SmtpServerName...Show more |