← Back
CWE-79

47,414 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (47,414)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Commonninja
1Easily Generate Rest Api
Jun 17, 2026
May 9, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The Easily Generate Rest API Url WordPress plugin through 1.0.0 does not escape some of its settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capa...Show more
The Easily Generate Rest API Url WordPress plugin through 1.0.0 does not escape some of its settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowedShow less
1Slide Anything Project
1Slide Anything
Jun 17, 2026
May 9, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The Slide Anything WordPress plugin before 2.3.44 does not sanitize and escape sliders' description, which could allow high privilege users such as editor and above to perform Cross-Site Scripting attacks even when the u...Show more
The Slide Anything WordPress plugin before 2.3.44 does not sanitize and escape sliders' description, which could allow high privilege users such as editor and above to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowedShow less
1Vertical Scroll Recent Post Project
1Vertical Scroll Recent Post
Jun 17, 2026
May 9, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Vertical scroll recent post WordPress plugin before 14.0 does not sanitise and escape a parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting
1Code Atlantic
1Popup Maker
Jun 17, 2026
May 9, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The Popup Maker WordPress plugin before 1.16.5 does not sanitise and escape some of its Popup settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the un...Show more
The Popup Maker WordPress plugin before 1.16.5 does not sanitise and escape some of its Popup settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowedShow less
1Themify
1Post Type Builder Search Addon
Jun 17, 2026
May 9, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Themify Post Type Builder Search Addon WordPress plugin before 1.4.0 does not properly escape the current page URL before reusing it in a HTML attribute, leading to a reflected cross site scripting vulnerability.
1Getigniteup
1Igniteup
Jun 17, 2026
May 9, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The IgniteUp WordPress plugin through 3.4.1 does not sanitise and escape some fields when high privilege users don't have the unfiltered_html capability, which could lead to Stored Cross-Site Scripting issues
1Wp Experts
1Wp Social Buttons
Jun 17, 2026
May 9, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The WP Social Buttons WordPress plugin through 2.1 does not sanitise and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability i...Show more
The WP Social Buttons WordPress plugin through 2.1 does not sanitise and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.Show less
1Admin Menu Editor Project
1Admin Menu Editor
Jun 17, 2026
May 9, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Admin Menu Editor WordPress plugin through 1.0.4 does not sanitize and escape a parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting.
1Edmonsoft
1Countdown Builder
Jun 17, 2026
May 6, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Multiple Authenticated (admin+) Persistent Cross-Site Scripting (XSS) vulnerabilities in Adam Skaat's Countdown & Clock plugin <= 2.3.2 at WordPress via &ycd-countdown-width, &ycd-progress-height, &ycd-progress-width, &y...Show more
Multiple Authenticated (admin+) Persistent Cross-Site Scripting (XSS) vulnerabilities in Adam Skaat's Countdown & Clock plugin <= 2.3.2 at WordPress via &ycd-countdown-width, &ycd-progress-height, &ycd-progress-width, &ycd-button-margin-top, &ycd-button-margin-right, &ycd-button-margin-bottom, &ycd-button-margin-left, &ycd-circle-countdown-before-countdown, &ycd-circle-countdown-after-countdown vulnerable parameters.Show less
1Edmonsoft
1Countdown Builder
Jun 17, 2026
May 6, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Reflected Cross-Site Scripting (XSS) vulnerability in Adam Skaat's Countdown & Clock plugin on WordPress via &ycd_type vulnerable parameter.
1Edmonsoft
1Countdown Builder
Jun 17, 2026
May 6, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Adam Skaat Countdown & Clock (WordPress plugin) countdown-builder allows Stored XSS.This issue affects Countdow...Show more
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Adam Skaat Countdown & Clock (WordPress plugin) countdown-builder allows Stored XSS.This issue affects Countdown & Clock (WordPress plugin): from n/a through 2.3.2.Show less
1Fudforum
1Fudforum
Jun 17, 2026
May 6, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
FUDforum 3.1.1 is vulnerable to Stored XSS.
1Bdt 121 Project
1Bdt 121 Firmware
Jun 17, 2026
May 6, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Dragon Path Technologies Bharti Airtel Routers Hardware BDT-121 version 1.0 is vulnerable to Cross Site Scripting (XSS) via Dragon path router admin page.
1Splunk
1Splunk
Jun 17, 2026
May 6, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Monitoring Console app configured in Distributed mode allows for a Reflected XSS in a query parameter in Splunk Enterprise versions before 8.1.4. The Monitoring Console app is a bundled app included in Splunk Enterpr...Show more
The Monitoring Console app configured in Distributed mode allows for a Reflected XSS in a query parameter in Splunk Enterprise versions before 8.1.4. The Monitoring Console app is a bundled app included in Splunk Enterprise, not for download on SplunkBase, and not installed on Splunk Cloud Platform instances. Note that the Cloud Monitoring Console is not impacted.Show less
1Google News Sitemap Project
1Google News Sitemap
Jun 17, 2026
May 6, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Stored Cross-Site Scripting (XSS) vulnerability in Andrea Pernici News Sitemap for Google plugin <= 1.0.16 on WordPress, attackers must have contributor or higher user role.
1Contao
1Contao
Jun 17, 2026
May 6, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Contao is a powerful open source CMS that allows you to create professional websites and scalable web applications. In versions of Contao prior to 4.13.3 it is possible to inject code into the canonical tag. As a workaro...Show more
Contao is a powerful open source CMS that allows you to create professional websites and scalable web applications. In versions of Contao prior to 4.13.3 it is possible to inject code into the canonical tag. As a workaround users may disable canonical tags in the root page settings.Show less
1Auth0
1Lock
Jun 17, 2026
May 5, 2022
N/A· v4
6.1 MEDIUM· v3
2.6 LOW· v2
Auth0 is an authentication broker that supports both social and enterprise identity providers, including Active Directory, LDAP, Google Apps, and Salesforce. In versions before `11.33.0`, when the “additional signup fiel...Show more
Auth0 is an authentication broker that supports both social and enterprise identity providers, including Active Directory, LDAP, Google Apps, and Salesforce. In versions before `11.33.0`, when the “additional signup fields” feature [is configured](https://github.com/auth0/lock#additional-sign-up-fields), a malicious actor can inject invalidated HTML code into these additional fields, which is then stored in the service `user_metdata` payload (using the `name` property). Verification emails, when applicable, are generated using this metadata. It is therefor possible for an actor to craft a malicious link by injecting HTML, which is then rendered as the recipient's name within the delivered email template. You are impacted by this vulnerability if you are using `auth0-lock` version `11.32.2` or lower and are using the “additional signup fields” feature in your application. Upgrade to version `11.33.0`.Show less
1Sophos
1Firewall Firmware
Jun 17, 2026
May 5, 2022
N/A· v4
8.4 HIGH· v3
6.0 MEDIUM· v2
Multiple XSS vulnerabilities in Webadmin allow for privilege escalation from MySophos admin to SFOS admin in Sophos Firewall older than version 19.0 GA.
1Sophos
1Firewall Firmware
Jun 17, 2026
May 5, 2022
N/A· v4
8.4 HIGH· v3
8.5 HIGH· v2
Multiple XSS vulnerabilities in Webadmin allow for privilege escalation from admin to super-admin in Sophos Firewall older than version 19.0 GA.
1F5
3Big Ip Advanced Firewall Manager
Big Ip Carrier Grade NatBig Ip Policy Enforcement Manager
Jun 17, 2026
May 5, 2022
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
On 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all versions of 12.1.x 11.6.x, a DOM-based cross-site scripting (XSS) vulne...Show more
On 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all versions of 12.1.x 11.6.x, a DOM-based cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP AFM, CGNAT, and PEM Configuration utility that allows an attacker to execute JavaScript in the context of the currently logged-in user. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluatedShow less