CWE-79
47,408 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (47,408)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The Poll Maker WordPress plugin before 4.0.2 does not sanitise and escape some settings, which could allow high privilege users such as admin to perform Store Cross-Site Scripting attack even when unfiltered_html is disa...Show more |
1Easy Faq With Expanding Text Project 1Easy Faq With Expanding Text Jun 17, 2026 May 30, 2022 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 The Easy FAQ with Expanding Text WordPress plugin through 3.2.8.3.1 does not sanitise and escape its settings, allowing high privilege users to perform Cross-Site Scripting attacks when unfiltered_html is disallowed |
1No Future Posts Project 1No Future Posts Jun 17, 2026 May 30, 2022 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 The No Future Posts WordPress plugin through 1.4 does not escape its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks when unfiltered_html is disallowed |
The Slideshow WordPress plugin through 2.3.1 does not sanitize and escape some of its default slideshow settings, which could allow high-privileged users such as admin to perform Cross-Site Scripting attacks even when th...Show more |
The IMDB info box WordPress plugin through 2.0 does not sanitize and escape some of its settings, which could allow high-privileged users to perform Cross-Site Scripting attacks even when the unfiltered_html capability i...Show more |
The BannerMan WordPress plugin through 0.2.4 does not sanitize or escape its settings, which could allow high-privileged users to perform Cross-Site Scripting attacks when the unfiltered_html is disallowed (such as in mu...Show more |
1Wpmudev 1Smush Image Compression And Optimization Jun 17, 2026 May 30, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The Smush WordPress plugin before 3.9.9 does not sanitise and escape a configuration parameter before outputting it back in an admin page when uploading a malicious preset configuration, leading to a Reflected Cross-Site...Show more |
1User Meta 1User Meta User Profile Builder And User Management Jun 17, 2026 May 30, 2022 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 The User Meta WordPress plugin before 2.4.3 does not sanitise and escape the Form Name, as well as Shared Field Labels before outputting them in the admin dashboard when editing a form, which could allow high privilege u...Show more |
Cross-site Scripting (XSS) - Stored in GitHub repository go-gitea/gitea prior to 1.16.9. |
1Hcltech 2Bigfix Mobile Modern Client ManagementJun 17, 2026 May 27, 2022 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 The Master operator may be able to embed script tag in HTML with alert pop-up display cookie. |
1Cisco 1Enterprise Chat And Email Jun 17, 2026 May 27, 2022 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 A vulnerability in the web interface of Cisco Enterprise Chat and Email (ECE) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerabili...Show more |
A vulnerability in the web applications of Cisco UCS Director could allow an authenticated, remote attacker to conduct a cross-site scripting attack on an affected system. This vulnerability is due to unsanitized user in...Show more |
1Cisco 1Common Services Platform Collector Jun 17, 2026 May 27, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Multiple vulnerabilities in the web-based management interface of Cisco Common Services Platform Collector (CSPC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack ag...Show more |
1Cisco 1Common Services Platform Collector Jun 17, 2026 May 27, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Multiple vulnerabilities in the web-based management interface of Cisco Common Services Platform Collector (CSPC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack ag...Show more |
1Cisco 1Common Services Platform Collector Jun 17, 2026 May 27, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Multiple vulnerabilities in the web-based management interface of Cisco Common Services Platform Collector (CSPC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack ag...Show more |
1Cisco 1Common Services Platform Collector Jun 17, 2026 May 27, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Multiple vulnerabilities in the web-based management interface of Cisco Common Services Platform Collector (CSPC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack ag...Show more |
1Cisco 1Common Services Platform Collector Jun 17, 2026 May 27, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Multiple vulnerabilities in the web-based management interface of Cisco Common Services Platform Collector (CSPC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack ag...Show more |
1Cisco 1Common Services Platform Collector Jun 17, 2026 May 27, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Multiple vulnerabilities in the web-based management interface of Cisco Common Services Platform Collector (CSPC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack ag...Show more |
1Cisco 1Common Services Platform Collector Jun 17, 2026 May 27, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Multiple vulnerabilities in the web-based management interface of Cisco Common Services Platform Collector (CSPC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack ag...Show more |
1Cisco 1Common Services Platform Collector Jun 17, 2026 May 27, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Multiple vulnerabilities in the web-based management interface of Cisco Common Services Platform Collector (CSPC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack ag...Show more |