← Back
CWE-79

47,408 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (47,408)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Curtain Project
1Curtain
Jun 17, 2026
May 23, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The Curtain WordPress plugin through 1.0.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html c...Show more
The Curtain WordPress plugin through 1.0.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowedShow less
1Wpchill
1Check & Log Email
Jun 17, 2026
May 23, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Check & Log Email WordPress plugin before 1.0.6 does not sanitise and escape a parameter before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Site Scripting
110web
1Sliderby10web
Jun 17, 2026
May 23, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The Sliderby10Web WordPress plugin before 1.2.52 does not properly sanitize and escape some of its settings, which could allow high-privileged users such as admin to perform Cross-Site Scripting attacks even when unfilte...Show more
The Sliderby10Web WordPress plugin before 1.2.52 does not properly sanitize and escape some of its settings, which could allow high-privileged users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowedShow less
1Wpshopmart
1Tabs Responsive
Jun 17, 2026
May 23, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The Tabs WordPress plugin before 2.2.8 does not sanitise and escape Tab descriptions, which could allow high privileged users with a role as low as editor to perform Cross-Site Scripting attacks even when the unfiltered_...Show more
The Tabs WordPress plugin before 2.2.8 does not sanitise and escape Tab descriptions, which could allow high privileged users with a role as low as editor to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowedShow less
1Donate Extra Project
1Donate Extra
Jun 17, 2026
May 23, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Donate Extra WordPress plugin through 2.02 does not sanitise and escape a parameter before outputting it back in the response, leading to a Reflected cross-Site Scripting
1Gwyn's Imagemap Selector Project
1Gwyn's Imagemap Selector
Jun 17, 2026
May 23, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Gwyn's Imagemap Selector WordPress plugin through 0.3.3 does not sanitise and escape some parameters before outputting them back in attributes, leading to a Reflected Cross-Site Scripting.
1Duogeek
1Domain Replace
Jun 17, 2026
May 23, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Domain Replace WordPress plugin through 1.3.8 does not sanitise and escape a parameter before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Site Scripting
1Turn Off All Comments Project
1Turn Off All Comments
Jun 17, 2026
May 23, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Turn off all comments WordPress plugin through 1.0 does not sanitise and escape the rows parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting
1Joomunited
1Wp Meta Seo
Jun 17, 2026
May 23, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The WP Meta SEO WordPress plugin before 4.4.7 does not sanitise or escape the breadcrumb separator before outputting it to the page, allowing a high privilege user such as an administrator to inject arbitrary javascript...Show more
The WP Meta SEO WordPress plugin before 4.4.7 does not sanitise or escape the breadcrumb separator before outputting it to the page, allowing a high privilege user such as an administrator to inject arbitrary javascript into the page even when unfiltered html is disallowed.Show less
1Xmlsitemapgenerator
1Xml Sitemap Generator
Jun 17, 2026
May 23, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The XML Sitemap Generator for Google WordPress plugin before 2.0.4 does not validate a parameter which can be set to an arbitrary value, thus causing XSS via error message or RCE if allow_url_include is turned on.
1Tms Outsource
1Wpdatatables
Jun 17, 2026
May 20, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Multiple Authenticated (administrator or higher user role) Persistent Cross-Site Scripting (XSS) vulnerabilities in TMS-Plugins wpDataTables plugin <= 2.1.27 on WordPress via &data-link-text, &data-link-url, &data, &data...Show more
Multiple Authenticated (administrator or higher user role) Persistent Cross-Site Scripting (XSS) vulnerabilities in TMS-Plugins wpDataTables plugin <= 2.1.27 on WordPress via &data-link-text, &data-link-url, &data, &data-shortcode, &data-star-num vulnerable parameters.Show less
1Png To Jpg Project
1Png To Jpg
Jun 17, 2026
May 20, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-Site Scripting (XSS) vulnerability in KubiQ's PNG to JPG plugin <= 4.0 at WordPress via Cross-Site Request Forgery (CSRF). Vulnerable parameter &jpg_quality.
1Muneeb
1Wp Slider
Jun 17, 2026
May 20, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Cross-Site Scripting (XSS) vulnerability in Muneeb's WP Slider Plugin <= 1.4.5 at WordPress.
12joomla
12j Slideshow
Jun 17, 2026
May 20, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Authenticated (contributor or higher user role) Reflected Cross-Site Scripting (XSS) vulnerability in 2J Slideshow Team's Slideshow, Image Slider by 2J plugin <= 1.3.54 at WordPress.
1Wpwham
1Checkout Files Upload For Woocommerce
Jun 17, 2026
May 20, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-Site Scripting (XSS) vulnerability in WP Wham's Checkout Files Upload for WooCommerce plugin <= 2.1.2 at WordPress.
1Oxilab
1Image Hover Effects Ultimate
Jun 17, 2026
May 20, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Authenticated (admin or higher user role) Reflected Cross-Site Scripting (XSS) vulnerability in Biplob Adhikari's Image Hover Effects Ultimate plugin <= 9.7.1 at WordPress.
1Ibericode
1Mailchimp For Wordpress
Jun 17, 2026
May 20, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Authenticated (admin or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in ibericode's MC4WP plugin <= 4.8.6 at WordPress.
1Thoughtworks
1Gocd
Jun 17, 2026
May 20, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
GoCD is a continuous delivery server. GoCD versions 20.2.0 until 21.4.0 are vulnerable to reflected cross-site scripting via abuse of the pipeline comparison function's error handling to render arbitrary HTML into the re...Show more
GoCD is a continuous delivery server. GoCD versions 20.2.0 until 21.4.0 are vulnerable to reflected cross-site scripting via abuse of the pipeline comparison function's error handling to render arbitrary HTML into the returned page. This could allow an attacker to trick a victim into executing code which would allow the attacker to operate on, or gain control over the same resources as the victim had access to. This issue is fixed in GoCD 21.4.0. As a workaround, block access to `/go/compare/.*` prior to GoCD Server via a reverse proxy, web application firewall or equivalent, which would prevent use of the pipeline comparison function.Show less
1Thoughtworks
1Gocd
Jun 17, 2026
May 20, 2022
N/A· v4
5.4 MEDIUM· v3
4.3 MEDIUM· v2
GoCD is a continuous delivery server. GoCD versions 19.11.0 through 21.4.0 (inclusive) are vulnerable to a Document Object Model (DOM)-based cross-site scripting attack via a pipeline run's Stage Details > Graphs tab. It...Show more
GoCD is a continuous delivery server. GoCD versions 19.11.0 through 21.4.0 (inclusive) are vulnerable to a Document Object Model (DOM)-based cross-site scripting attack via a pipeline run's Stage Details > Graphs tab. It is possible for a malicious script on a attacker-hosted site to execute script that will run within the user's browser context and GoCD session via abuse of a messaging channel used for communication between with the parent page and the stage details graph's iframe. This could allow an attacker to steal a GoCD user's session cookies and/or execute malicious code in the user's context. This issue is fixed in GoCD 22.1.0. There are currently no known workarounds.Show less
1Ibm
1Jazz Team Server
Jun 17, 2026
May 20, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM Jazz Team Server 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functio...Show more
IBM Jazz Team Server 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 214032.Show less