← Back
CWE-79

47,408 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (47,408)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Barco
1Control Room Management Suite
Jun 17, 2026
Jun 2, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Barco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing a file upload mechanism. Lack of input sanitization in the upload mechanism leads to reflected XSS.
1Barco
1Control Room Management Suite
Jun 17, 2026
Jun 2, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Barco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing a URL /cgi-bin endpoint. The URL parameters are not correctly sanitized, leading to reflected XSS.
1Blackrainbow
1Nimbus
Jun 17, 2026
Jun 2, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Black Rainbow NIMBUS before 3.7.0 allows stored Cross-site Scripting (XSS).
1Aceware
1Aceweb Online Portal
Jul 9, 2026
Jun 2, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
ACEweb Online Portal 3.5.065 was discovered to contain a cross-site scripting (XSS) vulnerability via the txtNmName1 parameter in person.awp.
1Fatcatapps
1Easy Pricing Tables
Jun 17, 2026
Jun 2, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Authenticated (author or higher role) Stored Cross-Site Scripting (XSS) vulnerability in Fatcat Apps Easy Pricing Tables plugin <= 3.1.2 at WordPress.
1Acquia
1Mautic
Jun 17, 2026
Jun 1, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
A cross-site scripting (XSS) vulnerability in the installer component of Mautic before 4.3.0 allows admins to inject executable javascript
1Hcltech
1Traveler
Jun 17, 2026
Jun 1, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
HCL Traveler is vulnerable to a cross-site scripting (XSS) caused by improper validation of the Name parameter for Approved Applications in the Traveler administration web pages. An attacker could exploit this vulnerabil...Show more
HCL Traveler is vulnerable to a cross-site scripting (XSS) caused by improper validation of the Name parameter for Approved Applications in the Traveler administration web pages. An attacker could exploit this vulnerability to execute a malicious script to access any cookies, session tokens, or other sensitive information retained by the browser and used with that site.Show less
1Xwiki
1Xwiki
Jun 17, 2026
May 31, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
XWiki Platform Filter UI provides a generic user interface to convert from a XWiki Filter input stream to an output stream with settings for each stream. Starting with versions 6.0-milestone-2 and 5.4.4 and prior to vers...Show more
XWiki Platform Filter UI provides a generic user interface to convert from a XWiki Filter input stream to an output stream with settings for each stream. Starting with versions 6.0-milestone-2 and 5.4.4 and prior to versions 12.10.11, 14.0-rc-1, 13.4.7, and 13.10.3, XWiki Platform Filter UI contains a possible cross-site scripting vector in the `Filter.FilterStreamDescriptorForm` wiki page related to pretty much all the form fields printed in the home page of the application. The issue is patched in versions 12.10.11, 14.0-rc-1, 13.4.7, and 13.10.3. The easiest workaround is to edit the wiki page `Filter.FilterStreamDescriptorForm` (with wiki editor) according to the instructions in the GitHub Security Advisory.Show less
1Simple Real Estate Pack Project
1Simple Real Estate Pack
Jun 17, 2026
May 30, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The Simple Real Estate Pack WordPress plugin through 1.4.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the u...Show more
The Simple Real Estate Pack WordPress plugin through 1.4.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowedShow less
1Amazon Link Project
1Amazon Link
Jun 17, 2026
May 30, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The Amazon Link WordPress plugin through 3.2.10 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is...Show more
The Amazon Link WordPress plugin through 3.2.10 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed.Show less
1Call&book Mobile Bar Project
1Call&book Mobile Bar
Jun 17, 2026
May 30, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The Call&Book Mobile Bar WordPress plugin through 1.2.2 does not sanitize and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered...Show more
The Call&Book Mobile Bar WordPress plugin through 1.2.2 does not sanitize and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed.Show less
1Birthdays Widget Project
1Birthdays Widget
Jun 17, 2026
May 30, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The Birthdays Widget WordPress plugin through 1.7.18 does not sanitise and escape some of its fields, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltere...Show more
The Birthdays Widget WordPress plugin through 1.7.18 does not sanitise and escape some of its fields, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowedShow less
1Webfactoryltd
1External Links In New Window / New Tab
Jun 17, 2026
May 30, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The External Links in New Window / New Tab WordPress plugin before 1.43 does not properly escape URLs it concatenates to onclick event handlers, which makes Stored Cross-Site Scripting attacks possible.
1Wpdarko
1Team Members
Jun 17, 2026
May 30, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The Team Members WordPress plugin before 5.1.1 does not escape some of its Team settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallow...Show more
The Team Members WordPress plugin before 5.1.1 does not escape some of its Team settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowedShow less
1Quotes Llama Project
1Quotes Llama
Jun 17, 2026
May 30, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The Quotes llama WordPress plugin before 1.0.0 does not sanitise and escape Quotes, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed. Th...Show more
The Quotes llama WordPress plugin before 1.0.0 does not sanitise and escape Quotes, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed. The attack could also be performed by tricking an admin to import a malicious CSV fileShow less
110web
1Form Maker
Jun 17, 2026
May 30, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The Form Maker by 10Web WordPress plugin before 1.14.12 does not sanitize and escape the Custom Text settings, which could allow high privilege user such as admin to perform Cross-Site Scripting attacks even when unfilte...Show more
The Form Maker by 10Web WordPress plugin before 1.14.12 does not sanitize and escape the Custom Text settings, which could allow high privilege user such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowedShow less
1Room 34 Creative Services
1Enable Svg
Jun 17, 2026
May 30, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The Enable SVG WordPress plugin before 1.4.0 does not sanitise uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads
1Justsystems
1Hpb Dashboard
Jun 17, 2026
May 30, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The HPB Dashboard WordPress plugin through 1.3.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html i...Show more
The HPB Dashboard WordPress plugin through 1.3.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed.Show less
1Vikwp
1Vik Booking
Jun 17, 2026
May 30, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.5.9 does not escape the current URL before putting it back in a JavaScript context, leading to a Reflected Cross-Site Scripting
1Wpwhitesecurity
1Wp 2fa
Jun 17, 2026
May 30, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The WP 2FA WordPress plugin before 2.2.1 does not sanitise and escape a parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting