← Back
CWE-79

47,418 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (47,418)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Liferay
2Digital Experience Platform
Liferay Portal
Jul 9, 2026
Apr 25, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in Journal module's web content display configuration page in Liferay Portal 7.1.0 through 7.3.3, and Liferay DXP 7.0 before fix pack 94, 7.1 before fix pack 19, and 7.2 before fi...Show more
Cross-site scripting (XSS) vulnerability in Journal module's web content display configuration page in Liferay Portal 7.1.0 through 7.3.3, and Liferay DXP 7.0 before fix pack 94, 7.1 before fix pack 19, and 7.2 before fix pack 8, allows remote attackers to inject arbitrary web script or HTML via web content template names.Show less
1Donorbox
1Donorbox
Jun 17, 2026
Apr 25, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The Donorbox WordPress plugin before 7.1.7 does not sanitise and escape its Campaign URL settings before outputting it in an attribute, leading to a Stored Cross-Site Scripting issue even when the unfiltered_html capabil...Show more
The Donorbox WordPress plugin before 7.1.7 does not sanitise and escape its Campaign URL settings before outputting it in an attribute, leading to a Stored Cross-Site Scripting issue even when the unfiltered_html capability is disallowedShow less
1Opensea Project
1Opeansea
Jun 17, 2026
Apr 25, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The Opensea WordPress plugin before 1.0.3 does not sanitize and escape some of its settings, like its "Referer address" field, which could allow high privilege users to perform Cross-Site Scripting attacks even when the...Show more
The Opensea WordPress plugin before 1.0.3 does not sanitize and escape some of its settings, like its "Referer address" field, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.Show less
1Books & Papers Project
1Books & Papers
Jun 17, 2026
Apr 25, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The Books & Papers WordPress plugin through 0.20210223 does not escape its Custom DB prefix settings, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disa...Show more
The Books & Papers WordPress plugin through 0.20210223 does not escape its Custom DB prefix settings, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowedShow less
1Kreaturamedia
1Layerslider
Jun 17, 2026
Apr 25, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The LayerSlider WordPress plugin before 7.1.2 does not sanitise and escape Project's slug before outputting it back in various place, which could allow high privilege users such as admin to perform Cross-Site Scripting a...Show more
The LayerSlider WordPress plugin before 7.1.2 does not sanitise and escape Project's slug before outputting it back in various place, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowedShow less
1Menubar
1Menubar
Jun 17, 2026
Apr 25, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The Menubar WordPress plugin before 5.8 does not sanitise and escape the command parameter before outputting it back in the response via the menubar AJAX action (available to any authenticated users), leading to a Reflec...Show more
The Menubar WordPress plugin before 5.8 does not sanitise and escape the command parameter before outputting it back in the response via the menubar AJAX action (available to any authenticated users), leading to a Reflected Cross-Site ScriptingShow less
1Anmari
1Amr Users
Jun 17, 2026
Apr 25, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The amr users WordPress plugin before 4.59.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered...Show more
The amr users WordPress plugin before 4.59.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowedShow less
1Minioragne
1Page Restriction
Jun 17, 2026
Apr 25, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The Page Restriction WordPress (WP) WordPress plugin before 1.2.7 allows bad actors with administrator privileges to the settings page to inject Javascript code to its settings leading to stored Cross-Site Scripting that...Show more
The Page Restriction WordPress (WP) WordPress plugin before 1.2.7 allows bad actors with administrator privileges to the settings page to inject Javascript code to its settings leading to stored Cross-Site Scripting that will only affect administrator users.Show less
1Download Anti Malware Security And Brute Force Firewall Project
1Download Anti Malware Security And Brute Force Firewall
Jun 17, 2026
Apr 25, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Anti-Malware Security and Brute-Force Firewall WordPress plugin before 4.20.96 does not sanitise and escape the QUERY_STRING before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting in...Show more
The Anti-Malware Security and Brute-Force Firewall WordPress plugin before 4.20.96 does not sanitise and escape the QUERY_STRING before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting in browsers which do not encode charactersShow less
1Wpdevart
1Social Comments
Jun 17, 2026
Apr 25, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The Social comments by WpDevArt WordPress plugin before 2.5.0 does not sanitise and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when unfiltered_html is di...Show more
The Social comments by WpDevArt WordPress plugin before 2.5.0 does not sanitise and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when unfiltered_html is disallowedShow less
1Supsystic
1Price Table
Jun 17, 2026
Apr 25, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Pricing Table by Supsystic WordPress plugin before 1.9.5 does not escape the tab parameter before outputting it back in an attribute in the admin dashboard, leading to a Reflected Cross-Site Scripting
1Subsystic
1Coming Soon
Jun 17, 2026
Apr 25, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Coming Soon by Supsystic WordPress plugin before 1.7.6 does not sanitise and escape the tab parameter before outputting it back in an attribute in the admin dashboard, leading to a Reflected Cross-Site Scripting
1Supsystic
1Easy Google Maps
Jun 17, 2026
Apr 25, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Easy Google Maps WordPress plugin before 1.9.32 does not escape the tab parameter before outputting it back in an attribute in the admin dashboard, leading to a Reflected Cross-Site Scripting
1Online Sports Complex Booking System Project
1Online Sports Complex Booking System
Jul 9, 2026
Apr 25, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
SCBS Online Sports Venue Reservation System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the fid parameter at booking.php.
1Hoosk
1Hoosk
Jun 17, 2026
Apr 25, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
XSS in edit page of Hoosk 1.8.0 allows attacker to execute javascript code in user browser via edit page with XSS payload bypass filter some special chars.
1Gallerycms Project
1Gallerycms
Jun 17, 2026
Apr 25, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A stored cross-site scripting (XSS) vulnerability in /index.php/album/add of GalleryCMS v2.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the album_name parameter.
1Element Plus
1Element Plus
Jun 17, 2026
Apr 25, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
element-plus 2.0.5 is vulnerable to Cross Site Scripting (XSS) via el-table-column.
1Open Emr
1Openemr
Jun 17, 2026
Apr 25, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Stored XSS Leads To Session Hijacking in GitHub repository openemr/openemr prior to 6.1.0.1.
1Facturascripts
1Facturascripts
Jun 17, 2026
Apr 25, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Store XSS in title parameter executing at EditUser Page & EditProducto page in GitHub repository neorazorx/facturascripts prior to 2022.04. Cross-site scripting attacks can have devastating consequences. Code injected in...Show more
Store XSS in title parameter executing at EditUser Page & EditProducto page in GitHub repository neorazorx/facturascripts prior to 2022.04. Cross-site scripting attacks can have devastating consequences. Code injected into a vulnerable application can exfiltrate data or install malware on the user's machine. Attackers can masquerade as authorized users via session cookies, allowing them to perform any action allowed by the user account.Show less
1Snipeitapp
1Snipe It
Jun 17, 2026
Apr 24, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Stored Cross Site Scripting vulnerability in the checked_out_to parameter in GitHub repository snipe/snipe-it prior to 5.4.3. The vulnerability is capable of stolen the user Cookie.