CWE-79
47,422 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (47,422)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Liferay 2Digital Experience Platform Liferay PortalJul 9, 2026 Apr 19, 2022 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 Cross-site scripting (XSS) vulnerability in the Asset module's asset categories selector in Liferay Portal 7.3.3 through 7.4.0, and Liferay DXP 7.3 before service pack 3 allows remote attackers to inject arbitrary web sc...Show more |
Veritas NetBackup OpsCenter Analytics 9.1 allows XSS via the NetBackup Master Server Name, Display Name, NetBackup User Name, or NetBackup Password field during a Settings/Configuration Add operation. |
The Autolinks WordPress plugin through 1.0.1 does not have CSRF check in place when updating its settings, and does not sanitise as well as escape them, which could allow attackers to perform Stored Cross-Site scripting...Show more |
The sanitisation step of the Safe SVG WordPress plugin before 1.9.10 can be bypassed by spoofing the content-type in the POST request to upload a file. Exploiting this vulnerability, an attacker will be able to perform t...Show more |
1Good Bad Comments Project 1Good Bad Comments Jun 17, 2026 Apr 18, 2022 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 The Good & Bad Comments WordPress plugin through 1.0.0 does not sanitise and escape its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfilter...Show more |
1Contextureintl 1Page Security & Membership Jun 17, 2026 Apr 18, 2022 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 The Page Security & Membership WordPress plugin through 1.5.15 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even w...Show more |
1Thank Me Later Project 1Thank Me Later Jun 17, 2026 Apr 18, 2022 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 The Thank Me Later WordPress plugin through 3.3.4 does not sanitise and escape the Message Subject field before outputting it in the Messages list, which could allow high privileges users such as admin to perform Cross-S...Show more |
1Wp Downgrade Project 1Wp Downgrade Jun 17, 2026 Apr 18, 2022 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 The WP Downgrade WordPress plugin before 1.2.3 only perform client side validation of its "WordPress Target Version" settings, but does not sanitise and escape it server side, allowing high privilege users such as admin...Show more |
The Hummingbird WordPress plugin before 3.3.2 does not sanitise and escape the Config Name, which could allow high privilege users, such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capa...Show more |
The Caldera Forms WordPress plugin before 1.9.7 does not validate and escape the cf-api parameter before outputting it back in the response, leading to a Reflected Cross-Site Scripting |
The SearchIQ WordPress plugin before 3.9 contains a flag to disable the verification of CSRF nonces, granting unauthenticated attackers access to the siq_ajax AJAX action and allowing them to perform Cross-Site Scripting...Show more |
1Loco Translate Project 1Loco Translate Jun 17, 2026 Apr 18, 2022 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 The Loco Translate WordPress plugin before 2.6.1 does not properly remove inline events from elements in the source translation strings before outputting them in the editor in the plugin admin panel, allowing any user wi...Show more |
The Text Hover WordPress plugin before 4.2 does not sanitize and escape the text to hover, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disall...Show more |
1Awesomemotive 1Easy Digital Downloads Jun 17, 2026 Apr 18, 2022 N/A· v4 4.8 MEDIUM· v3 2.1 LOW· v2 The Easy Digital Downloads WordPress plugin before 2.11.6 does not sanitise and escape the Downloadable File Name in the Logs, which could allow high privilege users to perform Cross-Site Scripting attacks when the unfil...Show more |
1Easysocialfeed 1Easy Social Feed Jun 17, 2026 Apr 18, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The Easy Social Feed Free and Pro WordPress plugins before 6.2.7 do not sanitise some of their parameters used via AJAX actions before outputting them back in the response, leading to Reflected Cross-Site Scripting issue...Show more |
1Contest Gallery 1Contest Gallery Jun 17, 2026 Apr 18, 2022 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 Authenticated (author or higher role) Stored Cross-Site Scripting (XSS) in Contest Gallery (WordPress plugin) <= 13.1.0.9 |
1Eaton 1Intelligent Power Manager Jun 17, 2026 Apr 18, 2022 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 Eaton Intelligent Power Manager Infrastructure (IPM Infrastructure) version 1.5.0plus205 and all prior versions are vulnerable to reflected Cross-site Scripting vulnerability. This issue affects: Eaton Intelligent Power...Show more |
1Eaton 1Intelligent Power Manager Infrastructure Jun 17, 2026 Apr 18, 2022 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 Eaton Intelligent Power Manager Infrastructure (IPM Infrastructure) version 1.5.0plus205 and all prior versions are vulnerable to Stored Cross-site Scripting vulnerability. This issue affects: Eaton Intelligent Power Man...Show more |
A remote attacker with write access to PI ProcessBook files could inject code that is imported into OSIsoft PI Vision 2020 versions prior to 3.5.0. Unauthorized information disclosure, modification, or deletion is also p...Show more |
Stored Cross Site Scripting vulnerability in Item name parameter in GitHub repository snipe/snipe-it prior to v5.4.3. The vulnerability is capable of stolen the user Cookie. |