← Back
CWE-79

47,422 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (47,422)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Liferay
2Digital Experience Platform
Liferay Portal
Jul 9, 2026
Apr 19, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-site scripting (XSS) vulnerability in the Asset module's asset categories selector in Liferay Portal 7.3.3 through 7.4.0, and Liferay DXP 7.3 before service pack 3 allows remote attackers to inject arbitrary web sc...Show more
Cross-site scripting (XSS) vulnerability in the Asset module's asset categories selector in Liferay Portal 7.3.3 through 7.4.0, and Liferay DXP 7.3 before service pack 3 allows remote attackers to inject arbitrary web script or HTML via the name of a asset category.Show less
1Veritas
1Netbackup
Jun 17, 2026
Apr 19, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Veritas NetBackup OpsCenter Analytics 9.1 allows XSS via the NetBackup Master Server Name, Display Name, NetBackup User Name, or NetBackup Password field during a Settings/Configuration Add operation.
1Autolinks Project
1Autolinks
Jun 17, 2026
Apr 18, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The Autolinks WordPress plugin through 1.0.1 does not have CSRF check in place when updating its settings, and does not sanitise as well as escape them, which could allow attackers to perform Stored Cross-Site scripting...Show more
The Autolinks WordPress plugin through 1.0.1 does not have CSRF check in place when updating its settings, and does not sanitise as well as escape them, which could allow attackers to perform Stored Cross-Site scripting against a logged in admin via a CSRF attackShow less
110up
1Safe Svg
Jun 17, 2026
Apr 18, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The sanitisation step of the Safe SVG WordPress plugin before 1.9.10 can be bypassed by spoofing the content-type in the POST request to upload a file. Exploiting this vulnerability, an attacker will be able to perform t...Show more
The sanitisation step of the Safe SVG WordPress plugin before 1.9.10 can be bypassed by spoofing the content-type in the POST request to upload a file. Exploiting this vulnerability, an attacker will be able to perform the kinds of attacks that this plugin should prevent (mainly XSS, but depending on further use of uploaded SVG files potentially other XML attacks).Show less
1Good Bad Comments Project
1Good Bad Comments
Jun 17, 2026
Apr 18, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The Good & Bad Comments WordPress plugin through 1.0.0 does not sanitise and escape its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfilter...Show more
The Good & Bad Comments WordPress plugin through 1.0.0 does not sanitise and escape its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowedShow less
1Contextureintl
1Page Security & Membership
Jun 17, 2026
Apr 18, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The Page Security & Membership WordPress plugin through 1.5.15 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even w...Show more
The Page Security & Membership WordPress plugin through 1.5.15 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowedShow less
1Thank Me Later Project
1Thank Me Later
Jun 17, 2026
Apr 18, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The Thank Me Later WordPress plugin through 3.3.4 does not sanitise and escape the Message Subject field before outputting it in the Messages list, which could allow high privileges users such as admin to perform Cross-S...Show more
The Thank Me Later WordPress plugin through 3.3.4 does not sanitise and escape the Message Subject field before outputting it in the Messages list, which could allow high privileges users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowedShow less
1Wp Downgrade Project
1Wp Downgrade
Jun 17, 2026
Apr 18, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The WP Downgrade WordPress plugin before 1.2.3 only perform client side validation of its "WordPress Target Version" settings, but does not sanitise and escape it server side, allowing high privilege users such as admin...Show more
The WP Downgrade WordPress plugin before 1.2.3 only perform client side validation of its "WordPress Target Version" settings, but does not sanitise and escape it server side, allowing high privilege users such as admin to perform Cross-Site attacks even when the unfiltered_html capability is disallowedShow less
1Incsub
1Hummingbird
Jun 17, 2026
Apr 18, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The Hummingbird WordPress plugin before 3.3.2 does not sanitise and escape the Config Name, which could allow high privilege users, such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capa...Show more
The Hummingbird WordPress plugin before 3.3.2 does not sanitise and escape the Config Name, which could allow high privilege users, such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowedShow less
1Calderaforms
1Caldera Forms
Jun 17, 2026
Apr 18, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Caldera Forms WordPress plugin before 1.9.7 does not validate and escape the cf-api parameter before outputting it back in the response, leading to a Reflected Cross-Site Scripting
1Searchiq
1Searchiq
Jun 17, 2026
Apr 18, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The SearchIQ WordPress plugin before 3.9 contains a flag to disable the verification of CSRF nonces, granting unauthenticated attackers access to the siq_ajax AJAX action and allowing them to perform Cross-Site Scripting...Show more
The SearchIQ WordPress plugin before 3.9 contains a flag to disable the verification of CSRF nonces, granting unauthenticated attackers access to the siq_ajax AJAX action and allowing them to perform Cross-Site Scripting attacks due to the lack of sanitisation and escaping in the customCss parameterShow less
1Loco Translate Project
1Loco Translate
Jun 17, 2026
Apr 18, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The Loco Translate WordPress plugin before 2.6.1 does not properly remove inline events from elements in the source translation strings before outputting them in the editor in the plugin admin panel, allowing any user wi...Show more
The Loco Translate WordPress plugin before 2.6.1 does not properly remove inline events from elements in the source translation strings before outputting them in the editor in the plugin admin panel, allowing any user with access to the plugin (Translator and Administrator by default) to add arbitrary javascript payloads to the source strings leading to a stored cross-site scripting (XSS) vulnerability.Show less
1Text Hover Project
1Text Hover
Jun 17, 2026
Apr 18, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The Text Hover WordPress plugin before 4.2 does not sanitize and escape the text to hover, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disall...Show more
The Text Hover WordPress plugin before 4.2 does not sanitize and escape the text to hover, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.Show less
1Awesomemotive
1Easy Digital Downloads
Jun 17, 2026
Apr 18, 2022
N/A· v4
4.8 MEDIUM· v3
2.1 LOW· v2
The Easy Digital Downloads WordPress plugin before 2.11.6 does not sanitise and escape the Downloadable File Name in the Logs, which could allow high privilege users to perform Cross-Site Scripting attacks when the unfil...Show more
The Easy Digital Downloads WordPress plugin before 2.11.6 does not sanitise and escape the Downloadable File Name in the Logs, which could allow high privilege users to perform Cross-Site Scripting attacks when the unfiltered_html capability is disallowedShow less
1Easysocialfeed
1Easy Social Feed
Jun 17, 2026
Apr 18, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Easy Social Feed Free and Pro WordPress plugins before 6.2.7 do not sanitise some of their parameters used via AJAX actions before outputting them back in the response, leading to Reflected Cross-Site Scripting issue...Show more
The Easy Social Feed Free and Pro WordPress plugins before 6.2.7 do not sanitise some of their parameters used via AJAX actions before outputting them back in the response, leading to Reflected Cross-Site Scripting issuesShow less
1Contest Gallery
1Contest Gallery
Jun 17, 2026
Apr 18, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Authenticated (author or higher role) Stored Cross-Site Scripting (XSS) in Contest Gallery (WordPress plugin) <= 13.1.0.9
1Eaton
1Intelligent Power Manager
Jun 17, 2026
Apr 18, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Eaton Intelligent Power Manager Infrastructure (IPM Infrastructure) version 1.5.0plus205 and all prior versions are vulnerable to reflected Cross-site Scripting vulnerability. This issue affects: Eaton Intelligent Power...Show more
Eaton Intelligent Power Manager Infrastructure (IPM Infrastructure) version 1.5.0plus205 and all prior versions are vulnerable to reflected Cross-site Scripting vulnerability. This issue affects: Eaton Intelligent Power Manager Infrastructure (IPM Infrastructure) all version 1.5.0plus205 and prior versions.Show less
1Eaton
1Intelligent Power Manager Infrastructure
Jun 17, 2026
Apr 18, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Eaton Intelligent Power Manager Infrastructure (IPM Infrastructure) version 1.5.0plus205 and all prior versions are vulnerable to Stored Cross-site Scripting vulnerability. This issue affects: Eaton Intelligent Power Man...Show more
Eaton Intelligent Power Manager Infrastructure (IPM Infrastructure) version 1.5.0plus205 and all prior versions are vulnerable to Stored Cross-site Scripting vulnerability. This issue affects: Eaton Intelligent Power Manager Infrastructure (IPM Infrastructure) all version 1.5.0plus205 and prior versions.Show less
1Osisoft
1Pi Vision
Jun 17, 2026
Apr 18, 2022
N/A· v4
7.3 HIGH· v3
4.9 MEDIUM· v2
A remote attacker with write access to PI ProcessBook files could inject code that is imported into OSIsoft PI Vision 2020 versions prior to 3.5.0. Unauthorized information disclosure, modification, or deletion is also p...Show more
A remote attacker with write access to PI ProcessBook files could inject code that is imported into OSIsoft PI Vision 2020 versions prior to 3.5.0. Unauthorized information disclosure, modification, or deletion is also possible if a victim views or interacts with the infected display. This vulnerability affects PI System data and other data accessible with victim’s user permissions.Show less
1Snipeitapp
1Snipe It
Jun 17, 2026
Apr 16, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Stored Cross Site Scripting vulnerability in Item name parameter in GitHub repository snipe/snipe-it prior to v5.4.3. The vulnerability is capable of stolen the user Cookie.