← Back
CWE-79

47,413 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (47,413)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Scrollrevealjs Effects Project
1Scrollrevealjs Effects
Jun 17, 2026
May 16, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The ScrollReveal.js Effects WordPress plugin through 1.2 does not sanitise and escape its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed
1Wpclever
1Wpc Smart Wishlist For Woocommerce
Jun 17, 2026
May 16, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The WPC Smart Wishlist for WooCommerce WordPress plugin before 2.9.9 does not sanitise and escape a parameter before outputting it back in an attribute via an AJAX action, leading to a Reflected Cross-Site Scripting issu...Show more
The WPC Smart Wishlist for WooCommerce WordPress plugin before 2.9.9 does not sanitise and escape a parameter before outputting it back in an attribute via an AJAX action, leading to a Reflected Cross-Site Scripting issue.Show less
1Callnowbutton
1Call Now Button
Jun 17, 2026
May 16, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Call Now Button WordPress plugin before 1.1.2 does not escape a parameter before outputting it back in an attribute of a hidden input, leading to a Reflected Cross-Site Scripting when the premium is enabled
1Wptaskforce
1Track & Trace
Jun 17, 2026
May 16, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The WPCargo Track & Trace WordPress plugin before 6.9.5 does not sanitise and escape the wpcargo_tracking_number parameter before outputting it back in the page, which could allow attackers to perform reflected Cross-Sit...Show more
The WPCargo Track & Trace WordPress plugin before 6.9.5 does not sanitise and escape the wpcargo_tracking_number parameter before outputting it back in the page, which could allow attackers to perform reflected Cross-Site Scripting attacks.Show less
1Wptaskforce
1Track & Trace
Jun 17, 2026
May 16, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The WPCargo Track & Trace WordPress plugin before 6.9.5 does not sanitize and escapes some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltere...Show more
The WPCargo Track & Trace WordPress plugin before 6.9.5 does not sanitize and escapes some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed.Show less
1Pluginmirror
1Social Stickers
Jun 17, 2026
May 16, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Social Stickers WordPress plugin through 2.2.9 does not have CSRF checks in place when updating its Social Network settings, and does not escape some of these fields, which could allow attackers to make a logged-in a...Show more
The Social Stickers WordPress plugin through 2.2.9 does not have CSRF checks in place when updating its Social Network settings, and does not escape some of these fields, which could allow attackers to make a logged-in admin change them and lead to Stored Cross-Site Scripting issues.Show less
1Vikwp
1Hotel Booking Engine & Pms
Jun 17, 2026
May 16, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.5.8 does not escape various settings before outputting them in attributes, which could allow high privilege users such as admin to perform Cross-Site Sc...Show more
The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.5.8 does not escape various settings before outputting them in attributes, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowedShow less
1Wp Subtitle Project
1Wp Subtitle
Jun 17, 2026
May 16, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The WP Subtitle WordPress plugin before 3.4.1 adds a subtitle field and provides a shortcode to display it via [wp_subtitle]. The subtitle is stored as a custom post meta with the key: "wps_subtitle", which is sanitized...Show more
The WP Subtitle WordPress plugin before 3.4.1 adds a subtitle field and provides a shortcode to display it via [wp_subtitle]. The subtitle is stored as a custom post meta with the key: "wps_subtitle", which is sanitized upon post save/update, however is not sanitized when updating it directly from the post meta update button (via AJAX) - and this makes the XSS exploitable by authenticated users with a role as low as contributor.Show less
1Wp Youtube Live Project
1Wp Youtube Live
Jun 17, 2026
May 16, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The WP YouTube Live WordPress plugin before 1.8.3 does not validate, sanitise and escape various of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unf...Show more
The WP YouTube Live WordPress plugin before 1.8.3 does not validate, sanitise and escape various of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowedShow less
1Bmi Bmr Calculator Project
1Bmi Bmr Calculator
Jun 17, 2026
May 16, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The BMI BMR Calculator WordPress plugin through 1.3 does not sanitise and escape arbitrary POST data before outputting it back in the response, leading to a Reflected Cross-Site Scripting
1Ait Pro
1Bulletproof Security
Jun 17, 2026
May 16, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The BulletProof Security WordPress plugin before 6.1 does not sanitize and escape some of its CAPTCHA settings, which could allow high-privileged users to perform Cross-Site Scripting attacks even when unfiltered_html is...Show more
The BulletProof Security WordPress plugin before 6.1 does not sanitize and escape some of its CAPTCHA settings, which could allow high-privileged users to perform Cross-Site Scripting attacks even when unfiltered_html is disallowedShow less
1Custom Tinymce Shortcode Button Project
1Custom Tinymce Shortcode Button
Jun 17, 2026
May 16, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Custom TinyMCE Shortcode Button WordPress plugin through 1.1 does not sanitise and escape the PHP_SELF variable before outputting it back in an attribute in an admin page, leading to Reflected Cross-Site Scripting.
1Advanced Image Sitemap Project
1Advanced Image Sitemap
Jun 17, 2026
May 16, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Advanced Image Sitemap WordPress plugin through 1.2 does not sanitise and escape the PHP_SELF PHP variable before outputting it back in an attribute in an admin page, leading to Reflected Cross-Site Scripting.
1Wpsheeteditor
1Bulk Edit And Create User Profiles Wp Sheet Editor
Jun 17, 2026
May 16, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The Bulk Edit and Create User Profiles WordPress plugin before 1.5.14 does not sanitise and escape the Users Login, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even...Show more
The Bulk Edit and Create User Profiles WordPress plugin before 1.5.14 does not sanitise and escape the Users Login, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowedShow less
1Th23
1Th23 Social
Jun 17, 2026
May 16, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The th23 Social WordPress plugin through 1.2.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html...Show more
The th23 Social WordPress plugin through 1.2.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowedShow less
12code
1Wpqa Builder
Jun 17, 2026
May 16, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The WPQA Builder Plugin WordPress plugin before 5.2, used as a companion plugin for the Discy and Himer , does not sanitise and escape the city, phone or profile credentials fields when outputting it in the profile page,...Show more
The WPQA Builder Plugin WordPress plugin before 5.2, used as a companion plugin for the Discy and Himer , does not sanitise and escape the city, phone or profile credentials fields when outputting it in the profile page, allowing any authenticated user to perform Cross-Site Scripting attacks.Show less
1Codeasily
1Gmedia Gallery
Jun 17, 2026
May 16, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The Gmedia Photo Gallery WordPress plugin before 1.20.0 does not sanitise and escape the Album's name before outputting it in pages/posts with a media embed, which could allow high privilege users such as admin to perfor...Show more
The Gmedia Photo Gallery WordPress plugin before 1.20.0 does not sanitise and escape the Album's name before outputting it in pages/posts with a media embed, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered-html capability is disallowedShow less
1Parallels
1H Sphere
Jun 17, 2026
May 16, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Parallels H-Sphere 3.6.1713 allows XSS via the index_en.php from parameter.
1Atmail
1Atmail
Jun 17, 2026
May 16, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
atmail 6.5.0 allows XSS via the index.php/admin/index/ error parameter.
1Totaljs
1Total.js
Jun 17, 2026
May 16, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A stored cross-site scripting (XSS) vulnerability in the upload function of totaljs CMS 3.4.5 allows attackers to execute arbitrary web scripts via a JavaScript embedded PDF file.