CWE-79
47,413 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (47,413)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Scrollrevealjs Effects Project 1Scrollrevealjs Effects Jun 17, 2026 May 16, 2022 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 The ScrollReveal.js Effects WordPress plugin through 1.2 does not sanitise and escape its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed |
1Wpclever 1Wpc Smart Wishlist For Woocommerce Jun 17, 2026 May 16, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The WPC Smart Wishlist for WooCommerce WordPress plugin before 2.9.9 does not sanitise and escape a parameter before outputting it back in an attribute via an AJAX action, leading to a Reflected Cross-Site Scripting issu...Show more |
1Callnowbutton 1Call Now Button Jun 17, 2026 May 16, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The Call Now Button WordPress plugin before 1.1.2 does not escape a parameter before outputting it back in an attribute of a hidden input, leading to a Reflected Cross-Site Scripting when the premium is enabled |
The WPCargo Track & Trace WordPress plugin before 6.9.5 does not sanitise and escape the wpcargo_tracking_number parameter before outputting it back in the page, which could allow attackers to perform reflected Cross-Sit...Show more |
The WPCargo Track & Trace WordPress plugin before 6.9.5 does not sanitize and escapes some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltere...Show more |
1Pluginmirror 1Social Stickers Jun 17, 2026 May 16, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The Social Stickers WordPress plugin through 2.2.9 does not have CSRF checks in place when updating its Social Network settings, and does not escape some of these fields, which could allow attackers to make a logged-in a...Show more |
1Vikwp 1Hotel Booking Engine & Pms Jun 17, 2026 May 16, 2022 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.5.8 does not escape various settings before outputting them in attributes, which could allow high privilege users such as admin to perform Cross-Site Sc...Show more |
1Wp Subtitle Project 1Wp Subtitle Jun 17, 2026 May 16, 2022 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 The WP Subtitle WordPress plugin before 3.4.1 adds a subtitle field and provides a shortcode to display it via [wp_subtitle]. The subtitle is stored as a custom post meta with the key: "wps_subtitle", which is sanitized...Show more |
1Wp Youtube Live Project 1Wp Youtube Live Jun 17, 2026 May 16, 2022 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 The WP YouTube Live WordPress plugin before 1.8.3 does not validate, sanitise and escape various of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unf...Show more |
1Bmi Bmr Calculator Project 1Bmi Bmr Calculator Jun 17, 2026 May 16, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The BMI BMR Calculator WordPress plugin through 1.3 does not sanitise and escape arbitrary POST data before outputting it back in the response, leading to a Reflected Cross-Site Scripting |
The BulletProof Security WordPress plugin before 6.1 does not sanitize and escape some of its CAPTCHA settings, which could allow high-privileged users to perform Cross-Site Scripting attacks even when unfiltered_html is...Show more |
1Custom Tinymce Shortcode Button Project 1Custom Tinymce Shortcode Button Jun 17, 2026 May 16, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The Custom TinyMCE Shortcode Button WordPress plugin through 1.1 does not sanitise and escape the PHP_SELF variable before outputting it back in an attribute in an admin page, leading to Reflected Cross-Site Scripting. |
1Advanced Image Sitemap Project 1Advanced Image Sitemap Jun 17, 2026 May 16, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The Advanced Image Sitemap WordPress plugin through 1.2 does not sanitise and escape the PHP_SELF PHP variable before outputting it back in an attribute in an admin page, leading to Reflected Cross-Site Scripting. |
1Wpsheeteditor 1Bulk Edit And Create User Profiles Wp Sheet Editor Jun 17, 2026 May 16, 2022 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 The Bulk Edit and Create User Profiles WordPress plugin before 1.5.14 does not sanitise and escape the Users Login, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even...Show more |
The th23 Social WordPress plugin through 1.2.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html...Show more |
The WPQA Builder Plugin WordPress plugin before 5.2, used as a companion plugin for the Discy and Himer , does not sanitise and escape the city, phone or profile credentials fields when outputting it in the profile page,...Show more |
The Gmedia Photo Gallery WordPress plugin before 1.20.0 does not sanitise and escape the Album's name before outputting it in pages/posts with a media embed, which could allow high privilege users such as admin to perfor...Show more |
Parallels H-Sphere 3.6.1713 allows XSS via the index_en.php from parameter. |
atmail 6.5.0 allows XSS via the index.php/admin/index/ error parameter. |
A stored cross-site scripting (XSS) vulnerability in the upload function of totaljs CMS 3.4.5 allows attackers to execute arbitrary web scripts via a JavaScript embedded PDF file. |