← Back
CWE-79

47,417 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (47,417)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Vfbpro
1Visual Form Builder
Jun 17, 2026
May 2, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The Visual Form Builder WordPress plugin before 3.0.7 does not sanitise and escape the form's 'Email to' field , which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_htm...Show more
The Visual Form Builder WordPress plugin before 3.0.7 does not sanitise and escape the form's 'Email to' field , which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowedShow less
1Ajdg
1Adrotate
Jun 17, 2026
May 2, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The AdRotate WordPress plugin before 5.8.23 does not sanitise and escape Advert Names which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
1Ajdg
1Adrotate
Jun 17, 2026
May 2, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The AdRotate WordPress plugin before 5.8.23 does not escape Group Names, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
1Keywordrush
1Content Egg
Jun 17, 2026
May 2, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Content Egg WordPress plugin before 5.3.0 does not sanitise and escape the page parameter before outputting back in an attribute in the Autoblogging admin dashboard, leading to a Reflected Cross-Site Scripting
1Event List Project
1Event List
Jun 17, 2026
May 2, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The Event List WordPress plugin before 0.8.8 does not sanitise and escape some of its settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks against other admin even when the unfilt...Show more
The Event List WordPress plugin before 0.8.8 does not sanitise and escape some of its settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks against other admin even when the unfiltered_html is disallowedShow less
1Tipsandtricks Hq
1All In One Wp Security & Firewall
Jun 17, 2026
May 2, 2022
N/A· v4
4.7 MEDIUM· v3
2.6 LOW· v2
The All In One WP Security & Firewall WordPress plugin before 4.4.11 does not validate, sanitise and escape the redirect_to parameter before using it to redirect user, either via a Location header, or meta url attribute,...Show more
The All In One WP Security & Firewall WordPress plugin before 4.4.11 does not validate, sanitise and escape the redirect_to parameter before using it to redirect user, either via a Location header, or meta url attribute, when the Rename Login Page is active, which could lead to an Arbitrary Redirect as well as Cross-Site Scripting issue. Exploitation of this issue requires the Login Page URL value to be known, which should be hard to guess, reducing the riskShow less
1Advanced Page Visit Counter Project
1Advanced Page Visit Counter
Jun 17, 2026
May 2, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Advanced Page Visit Counter WordPress plugin before 6.1.2 does not sanitise and escape some input before outputting it in an admin dashboard page, allowing unauthenticated attackers to perform Cross-Site Scripting at...Show more
The Advanced Page Visit Counter WordPress plugin before 6.1.2 does not sanitise and escape some input before outputting it in an admin dashboard page, allowing unauthenticated attackers to perform Cross-Site Scripting attacks against admins viewing itShow less
1Vendure
1Vendure
Jun 17, 2026
May 2, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
In Vendure versions 0.1.0-alpha.2 to 1.5.1 are affected by Stored XSS vulnerability, where an attacker having catalog permission can upload a SVG file that contains malicious JavaScript into the “Assets” tab. The uploade...Show more
In Vendure versions 0.1.0-alpha.2 to 1.5.1 are affected by Stored XSS vulnerability, where an attacker having catalog permission can upload a SVG file that contains malicious JavaScript into the “Assets” tab. The uploaded file will affect administrators as well as regular users.Show less
1Mediawiki
1Rss For Mediawiki
Jun 17, 2026
May 2, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The RSS extension before 2022-04-29 for MediaWiki allows XSS via an rss element (if the feed is in $wgRSSUrlWhitelist and $wgRSSAllowLinkTag is true).
1Cyclos
1Cyclos
Jul 9, 2026
May 2, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cyclos 4 PRO 4.14.7 and before does not validate user input at error inform, which allows remote unauthenticated attacker to execute javascript code via undefine enum constant.
1Cyclos
1Cyclos
Jul 9, 2026
May 2, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A Dom-based Cross-site scripting (XSS) vulnerability at registration account in Cyclos 4 PRO.14.7 and before allows remote attackers to inject arbitrary web script or HTML via the groupId parameter.
1Materializecss
1Materialize
Jun 17, 2026
May 1, 2022
N/A· v4
5.4 MEDIUM· v3
4.3 MEDIUM· v2
All versions of package materialize-css are vulnerable to Cross-site Scripting (XSS) due to improper escape of user input (such as <not-a-tag />) that is being parsed as HTML/JavaScript, and inserted into the Docum...Show more
All versions of package materialize-css are vulnerable to Cross-site Scripting (XSS) due to improper escape of user input (such as <not-a-tag />) that is being parsed as HTML/JavaScript, and inserted into the Document Object Model (DOM). This vulnerability can be exploited when the user-input is provided to the autocomplete component.Show less
1S Cart
1S Cart
Jun 17, 2026
May 1, 2022
N/A· v4
3.5 LOW· v3
3.5 LOW· v2
The package s-cart/s-cart before 6.9; the package s-cart/core before 6.9 are vulnerable to Cross-site Scripting (XSS) which can lead to cookie stealing of any victim that visits the affected URL so the attacker can gain...Show more
The package s-cart/s-cart before 6.9; the package s-cart/core before 6.9 are vulnerable to Cross-site Scripting (XSS) which can lead to cookie stealing of any victim that visits the affected URL so the attacker can gain unauthorized access to that user's account through the stolen cookie.Show less
1Shopizer
1Shopizer
Jun 17, 2026
May 1, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
A Stored Cross Site Scripting (XSS) vulnerability exists in Shopizer versions 2.0 through 2.17.0, where a privileged user (attacker) can inject malicious JavaScript in the filename under the “Manage files” tab
1Woodpecker Ci
1Woodpecker
Jun 17, 2026
Apr 29, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Woodpecker before 0.15.1 allows XSS via build logs because web/src/components/repo/build/BuildLog.vue lacks escaping.
1Tagify Project
1Tagify
Jun 17, 2026
Apr 29, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
This affects the package @yaireo/tagify before 4.9.8. The package is used for rendering UI components inside the input or text fields, and an attacker can pass a malicious placeholder value to it to fire the XSS payload.
1Intelliants
1Subrion
Jun 17, 2026
Apr 29, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A cross-site scripting (XSS) vulnerability exists in the "contact us" plugin for Subrion CMS <= 4.2.1 version via "List of subjects".
1Automad
1Automad
Jun 17, 2026
Apr 29, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A vulnerability has been found in automad up to 1.10.9 and classified as problematic. This vulnerability affects the Dashboard. The manipulation of the argument title with the input Home</title><script>alert("home")</scr...Show more
A vulnerability has been found in automad up to 1.10.9 and classified as problematic. This vulnerability affects the Dashboard. The manipulation of the argument title with the input Home</title><script>alert("home")</script><title> leads to a cross site scripting. The attack can be initiated remotely but requires an authentication. The exploit details have disclosed to the public and may be used.Show less
1Livehelperchat
1Live Helper Chat
Jun 17, 2026
Apr 29, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site Scripting (XSS) in GitHub repository livehelperchat/livehelperchat prior to 3.99v. The attacker can execute malicious JavaScript on the application.
1Emlog
1Emlog
Jun 17, 2026
Apr 29, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A vulnerability, which was classified as problematic, was found in Emlog Pro up to 1.2.2. This affects the POST parameter handling of articles. The manipulation with the input <script>alert(1);</script> leads to cross si...Show more
A vulnerability, which was classified as problematic, was found in Emlog Pro up to 1.2.2. This affects the POST parameter handling of articles. The manipulation with the input <script>alert(1);</script> leads to cross site scripting. It is possible to initiate the attack remotely but it requires a signup and login by the attacker. The exploit has been disclosed to the public and may be used.Show less