← Back
CWE-79

47,403 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (47,403)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Pieforms
1Drag & Drop Builder
Jun 17, 2026
Jun 8, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The Drag & Drop Builder, Human Face Detector, Pre-built Templates, Spam Protection, User Email Notifications & more! WordPress plugin before 1.4.9.4 does not sanitise and escape some of its form fields, which could allow...Show more
The Drag & Drop Builder, Human Face Detector, Pre-built Templates, Spam Protection, User Email Notifications & more! WordPress plugin before 1.4.9.4 does not sanitise and escape some of its form fields, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks when unfiltered_html is disallowedShow less
1Richweb
1Video Slider
Jun 17, 2026
Jun 8, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The Video Slider WordPress plugin before 1.4.8 does not sanitize or escape some of its video settings, which could allow high-privileged users to perform Cross-Site Scripting attacks even when unfiltered_html is disallow...Show more
The Video Slider WordPress plugin before 1.4.8 does not sanitize or escape some of its video settings, which could allow high-privileged users to perform Cross-Site Scripting attacks even when unfiltered_html is disallowedShow less
1Wp Born Babies Project
1Wp Born Babies
Jun 17, 2026
Jun 8, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The WP Born Babies WordPress plugin through 1.0 does not sanitise and escape some of its fields, which could allow users with a role as low as contributor to perform Cross-Site Scripting attacks
1Fibosearch
1Fibosearch
Jun 17, 2026
Jun 8, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The FiboSearch WordPress plugin before 1.17.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_htm...Show more
The FiboSearch WordPress plugin before 1.17.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowedShow less
110web
1Photo Gallery
Jun 17, 2026
Jun 8, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The Photo Gallery by 10Web WordPress plugin before 1.6.4 does not properly validate and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks when unfil...Show more
The Photo Gallery by 10Web WordPress plugin before 1.6.4 does not properly validate and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks when unfiltered_html is disallowedShow less
12code
1Ask Me
Jun 17, 2026
Jun 8, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Ask me WordPress theme before 6.8.2 does not properly sanitise and escape several of the fields in the Edit Profile page, leading to Reflected Cross-Site Scripting issues
1Veronalabs
1Wp Statistics
Jun 17, 2026
Jun 8, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The WP Statistics WordPress plugin before 13.2.2 does not sanitise the REQUEST_URI parameter before outputting it back in the rendered page, leading to Cross-Site Scripting (XSS) in web browsers which do not encode chara...Show more
The WP Statistics WordPress plugin before 13.2.2 does not sanitise the REQUEST_URI parameter before outputting it back in the rendered page, leading to Cross-Site Scripting (XSS) in web browsers which do not encode charactersShow less
1Sialweb
1Sialweb Cms
Jun 17, 2026
Jun 8, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A vulnerability has been found in SialWeb CMS and classified as problematic. This vulnerability affects unknown code of the component Search Handler. The manipulation leads to cross site scripting. The attack can be init...Show more
A vulnerability has been found in SialWeb CMS and classified as problematic. This vulnerability affects unknown code of the component Search Handler. The manipulation leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.Show less
1Axigen
1Axigen Mobile Webmail
Jun 17, 2026
Jun 7, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An XSS vulnerability in the index_mobile_changepass.hsp reset-password section of Axigen Mobile WebMail before 10.2.3.12 and 10.3.x before 10.3.3.47 allows attackers to run arbitrary Javascript code that, using an active...Show more
An XSS vulnerability in the index_mobile_changepass.hsp reset-password section of Axigen Mobile WebMail before 10.2.3.12 and 10.3.x before 10.3.3.47 allows attackers to run arbitrary Javascript code that, using an active end-user session (for a logged-in user), can access and retrieve mailbox content.Show less
1Nocodb
1Nocodb
Jun 17, 2026
Jun 7, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-site Scripting (XSS) - Stored in GitHub repository nocodb/nocodb prior to 0.91.7.
1Aptis Solutions
1Server Status
Jun 17, 2026
Jun 7, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A vulnerability, which was classified as problematic, has been found in Server Status. This issue affects some unknown processing of the component HTTP Status/SMTP Status. The manipulation leads to cross site scripting....Show more
A vulnerability, which was classified as problematic, has been found in Server Status. This issue affects some unknown processing of the component HTTP Status/SMTP Status. The manipulation leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.Show less
1Akeles
1Countdown Timer
Jun 17, 2026
Jun 7, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A vulnerability classified as problematic was found in Countdown Timer. This vulnerability affects unknown code of the component Macro Handler. The manipulation leads to cross site scripting. The attack can be initiated...Show more
A vulnerability classified as problematic was found in Countdown Timer. This vulnerability affects unknown code of the component Macro Handler. The manipulation leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.Show less
1Servicerocket
1Linking
Jun 17, 2026
Jun 7, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A vulnerability classified as problematic has been found in Linking. This affects an unknown part of the component New Windows Macro. The manipulation leads to cross site scripting. It is possible to initiate the attack...Show more
A vulnerability classified as problematic has been found in Linking. This affects an unknown part of the component New Windows Macro. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.Show less
1Refined
1Refined Toolkit
Jun 17, 2026
Jun 7, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A vulnerability was found in Refined Toolkit. It has been rated as problematic. Affected by this issue is some unknown functionality of the component UI-Image/UI-Button. The manipulation leads to cross site scripting. Th...Show more
A vulnerability was found in Refined Toolkit. It has been rated as problematic. Affected by this issue is some unknown functionality of the component UI-Image/UI-Button. The manipulation leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.Show less
1Avono
1Plantuml
Jun 17, 2026
Jun 7, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A vulnerability was found in PlantUML 6.43. It has been declared as problematic. Affected by this vulnerability is the component Database Information Macro. The manipulation leads to cross site scripting. The attack can...Show more
A vulnerability was found in PlantUML 6.43. It has been declared as problematic. Affected by this vulnerability is the component Database Information Macro. The manipulation leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.Show less
1Librehealth
1Librehealth Ehr
Jun 17, 2026
Jun 7, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
LibreHealth EHR Base 2.0.0 allows gacl/admin/acl_admin.php return_page XSS.
1Fast Food Ordering System Project
1Fast Food Ordering System
Jun 17, 2026
Jun 7, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
A vulnerability classified as problematic has been found in Fast Food Ordering System 1.0. Affected is the file Master.php of the Master List. The manipulation of the argument Description with the input foo "><img src=""...Show more
A vulnerability classified as problematic has been found in Fast Food Ordering System 1.0. Affected is the file Master.php of the Master List. The manipulation of the argument Description with the input foo "><img src="" onerror="alert(document.cookie)"> leads to cross site scripting. It is possible to launch the attack remotely but it requires authentication. Exploit details have been disclosed to the public.Show less
1Librehealth
1Librehealth Ehr
Jun 17, 2026
Jun 6, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
LibreHealth EHR Base 2.0.0 allows gacl/admin/acl_admin.php action XSS.
1Avantune
1Genialcloud Proj
Jun 17, 2026
Jun 6, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A reflected cross-site scripting (XSS) vulnerability in the login portal of Avantune Genialcloud ProJ - 10 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
1Seeddms
1Seeddms
Jun 17, 2026
Jun 6, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
SeedDMS versions 6.0.18 and 5.1.25 and below are vulnerable to stored XSS. An attacker with admin privileges can inject the payload inside the "Role management" menu and then trigger the payload by loading the "Users man...Show more
SeedDMS versions 6.0.18 and 5.1.25 and below are vulnerable to stored XSS. An attacker with admin privileges can inject the payload inside the "Role management" menu and then trigger the payload by loading the "Users management" menuShow less