← Back
CWE-79

47,424 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (47,424)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ibm
1Curam Social Program Management
Jun 17, 2026
Apr 11, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM Curam Social Program Management 8.0.1 and 7.0.11 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potent...Show more
IBM Curam Social Program Management 8.0.1 and 7.0.11 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 215306.Show less
1Thedaylightstudio
1Fuel Cms
Jun 17, 2026
Apr 11, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Daylight Studio Fuel CMS 1.5.1 is vulnerable to HTML Injection.
1Jflyfox
1Jfinal Cms
Jun 17, 2026
Apr 11, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Jfinal_CMS 5.1.0 allows attackers to use the feedback function to send malicious XSS code to the administrator backend and execute it.
1Elbtide
1Advanced Booking Calendar
Jun 17, 2026
Apr 11, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Advanced Booking Calendar WordPress plugin before 1.7.1 does not sanitise and escape the room parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting issue
1Vertistudio
1Image Optimization & Lazy Load By Optimole
Jun 17, 2026
Apr 11, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The Image optimization & Lazy Load by Optimole WordPress plugin before 3.3.2 does not sanitise and escape its "Lazyload background images for selectors" settings, which could allow high privilege users such as admin to p...Show more
The Image optimization & Lazy Load by Optimole WordPress plugin before 3.3.2 does not sanitise and escape its "Lazyload background images for selectors" settings, which could allow high privilege users such as admin to perform Cross-Site scripting attacks even when the unfiltered_html capability is disallowed.Show less
1Atlasgondal
1Export All Urls
Jun 17, 2026
Apr 11, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Export All URLs WordPress plugin before 4.2 does not sanitise and escape the CSV filename before outputting it back in the page, leading to a Reflected Cross-Site Scripting
1Cybernetikz
1Easy Social Icons
Jun 17, 2026
Apr 11, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The Easy Social Icons WordPress plugin before 3.2.1 does not properly escape the image_file field when adding a new social icon, allowing high privileged users to inject arbitrary javascript even when the unfiltered_html...Show more
The Easy Social Icons WordPress plugin before 3.2.1 does not properly escape the image_file field when adding a new social icon, allowing high privileged users to inject arbitrary javascript even when the unfiltered_html capability is disallowed.Show less
1Pootlepress
1Easy Smooth Scroll Links
Jun 17, 2026
Apr 11, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The Easy Smooth Scroll Links WordPress plugin before 2.23.1 does not sanitise and escape its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered...Show more
The Easy Smooth Scroll Links WordPress plugin before 2.23.1 does not sanitise and escape its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowedShow less
1Wpvivid
1Migration, Backup, Staging
Jun 17, 2026
Apr 11, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Migration, Backup, Staging WordPress plugin before 0.9.70 does not sanitise and escape the sub_page parameter before outputting it back in the page, leading to a reflected Cross-Site Scripting
1Realfavicongenerator
1Favicon By Realfavicongenerator
Jun 17, 2026
Apr 11, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Favicon by RealFaviconGenerator WordPress plugin before 1.3.23 does not properly sanitise and escape the json_result_url parameter before outputting it back in the Favicon admin dashboard, leading to a Reflected Cros...Show more
The Favicon by RealFaviconGenerator WordPress plugin before 1.3.23 does not properly sanitise and escape the json_result_url parameter before outputting it back in the Favicon admin dashboard, leading to a Reflected Cross-Site Scripting issueShow less
1Pickplugins
1Post Grid
Jun 17, 2026
Apr 11, 2022
N/A· v4
6.4 MEDIUM· v3
3.5 LOW· v2
The Post Grid WordPress plugin before 2.1.16 does not sanitise and escape the post_types parameter before outputting it back in the response of the post_grid_update_taxonomies_terms_by_posttypes AJAX action, available to...Show more
The Post Grid WordPress plugin before 2.1.16 does not sanitise and escape the post_types parameter before outputting it back in the response of the post_grid_update_taxonomies_terms_by_posttypes AJAX action, available to any authenticated users, leading to a Reflected Cross-Site ScriptingShow less
1Presscustomizr
1Nimble Page Builder
Jun 17, 2026
Apr 11, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Nimble Page Builder WordPress plugin before 3.2.2 does not sanitise and escape the preview-level-guid parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting
1Thimpress
1Learnpress
Jun 17, 2026
Apr 11, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The LearnPress WordPress plugin before 4.1.6 does not sanitise and escape the lp-dismiss-notice before outputting it back via the lp_background_single_email AJAX action, leading to a Reflected Cross-Site Scripting
1Wpsofts
1Portfolio Gallery, Product Catalog Grid Kit Portfolio
Jun 17, 2026
Apr 11, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The Portfolio Gallery, Product Catalog WordPress plugin before 2.1.0 does not have authorisation and CSRF checks in various functions related to AJAX actions, allowing any authenticated users, such as subscriber, to call...Show more
The Portfolio Gallery, Product Catalog WordPress plugin before 2.1.0 does not have authorisation and CSRF checks in various functions related to AJAX actions, allowing any authenticated users, such as subscriber, to call them. Due to the lack of sanitisation and escaping, it could also allows attackers to perform Cross-Site Scripting attacks on pages where a Portfolio is embedShow less
1Heateor
1Super Socializer
Jun 17, 2026
Apr 11, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Social Share, Social Login and Social Comments Plugin WordPress plugin before 7.13.30 does not sanitise and escape the urls parameter in its the_champ_sharing_count AJAX action (available to both unauthenticated and...Show more
The Social Share, Social Login and Social Comments Plugin WordPress plugin before 7.13.30 does not sanitise and escape the urls parameter in its the_champ_sharing_count AJAX action (available to both unauthenticated and authenticated users) before outputting it back in the response, leading to a Reflected Cross-Site Scripting issue.Show less
1Pickplugins
1Post Grid
Jun 17, 2026
Apr 11, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Post Grid WordPress plugin before 2.1.16 does not escape the keyword parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting in pages containing a Post Grid with a search form
1Autolabproject
1Autolab
Jun 17, 2026
Apr 11, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-site Scripting (XSS) - Stored in GitHub repository autolab/autolab prior to 2.8.0.
1Webmin
1Webmin
Jun 17, 2026
Apr 11, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A Cross-Site Scripting (XSS) vulnerability exists in Webmin 1.973 through the File Manager feature.
1Webmin
1Webmin
Jun 17, 2026
Apr 11, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A Cross-Site Scripting (XSS) vulnerability exists in Webmin 1.973 through the Add Users feature.
1Webmin
1Webmin
Jun 17, 2026
Apr 11, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A Cross-Site Scripting (XSS) vulnerability exists in Webmin 1.973 via the Upload and Download feature.