CWE-79
47,424 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (47,424)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Ibm 1Curam Social Program Management Jun 17, 2026 Apr 11, 2022 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 IBM Curam Social Program Management 8.0.1 and 7.0.11 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potent...Show more |
Daylight Studio Fuel CMS 1.5.1 is vulnerable to HTML Injection. |
Jfinal_CMS 5.1.0 allows attackers to use the feedback function to send malicious XSS code to the administrator backend and execute it. |
1Elbtide 1Advanced Booking Calendar Jun 17, 2026 Apr 11, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The Advanced Booking Calendar WordPress plugin before 1.7.1 does not sanitise and escape the room parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting issue |
1Vertistudio 1Image Optimization & Lazy Load By Optimole Jun 17, 2026 Apr 11, 2022 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 The Image optimization & Lazy Load by Optimole WordPress plugin before 3.3.2 does not sanitise and escape its "Lazyload background images for selectors" settings, which could allow high privilege users such as admin to p...Show more |
1Atlasgondal 1Export All Urls Jun 17, 2026 Apr 11, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The Export All URLs WordPress plugin before 4.2 does not sanitise and escape the CSV filename before outputting it back in the page, leading to a Reflected Cross-Site Scripting |
The Easy Social Icons WordPress plugin before 3.2.1 does not properly escape the image_file field when adding a new social icon, allowing high privileged users to inject arbitrary javascript even when the unfiltered_html...Show more |
1Pootlepress 1Easy Smooth Scroll Links Jun 17, 2026 Apr 11, 2022 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 The Easy Smooth Scroll Links WordPress plugin before 2.23.1 does not sanitise and escape its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered...Show more |
1Wpvivid 1Migration, Backup, Staging Jun 17, 2026 Apr 11, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The Migration, Backup, Staging WordPress plugin before 0.9.70 does not sanitise and escape the sub_page parameter before outputting it back in the page, leading to a reflected Cross-Site Scripting |
1Realfavicongenerator 1Favicon By Realfavicongenerator Jun 17, 2026 Apr 11, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The Favicon by RealFaviconGenerator WordPress plugin before 1.3.23 does not properly sanitise and escape the json_result_url parameter before outputting it back in the Favicon admin dashboard, leading to a Reflected Cros...Show more |
The Post Grid WordPress plugin before 2.1.16 does not sanitise and escape the post_types parameter before outputting it back in the response of the post_grid_update_taxonomies_terms_by_posttypes AJAX action, available to...Show more |
1Presscustomizr 1Nimble Page Builder Jun 17, 2026 Apr 11, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The Nimble Page Builder WordPress plugin before 3.2.2 does not sanitise and escape the preview-level-guid parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting |
The LearnPress WordPress plugin before 4.1.6 does not sanitise and escape the lp-dismiss-notice before outputting it back via the lp_background_single_email AJAX action, leading to a Reflected Cross-Site Scripting |
1Wpsofts 1Portfolio Gallery, Product Catalog Grid Kit Portfolio Jun 17, 2026 Apr 11, 2022 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 The Portfolio Gallery, Product Catalog WordPress plugin before 2.1.0 does not have authorisation and CSRF checks in various functions related to AJAX actions, allowing any authenticated users, such as subscriber, to call...Show more |
The Social Share, Social Login and Social Comments Plugin WordPress plugin before 7.13.30 does not sanitise and escape the urls parameter in its the_champ_sharing_count AJAX action (available to both unauthenticated and...Show more |
The Post Grid WordPress plugin before 2.1.16 does not escape the keyword parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting in pages containing a Post Grid with a search form |
Cross-site Scripting (XSS) - Stored in GitHub repository autolab/autolab prior to 2.8.0. |
A Cross-Site Scripting (XSS) vulnerability exists in Webmin 1.973 through the File Manager feature. |
A Cross-Site Scripting (XSS) vulnerability exists in Webmin 1.973 through the Add Users feature. |
A Cross-Site Scripting (XSS) vulnerability exists in Webmin 1.973 via the Upload and Download feature. |