CWE-79
47,425 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (47,425)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Web Settler 1Testimonial Slider Jun 17, 2026 Apr 4, 2022 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 Authenticated (editor or higher user role) Cross-Site Scripting (XSS) vulnerability in Web-Settler Testimonial Slider – Free Testimonials Slider Plugin (WordPress plugin) via parameters mpsp_posts_bg_color, mpsp_posts_de...Show more |
Authenticated (subscriber or higher user role if allowed to access projects) Stored Cross-Site Scripting (XSS) vulnerability in weDevs WP Project Manager plugin <= 2.4.13 versions. |
Directus is a real-time API and App dashboard for managing SQL database content. Prior to version 9.7.0, unauthorized JavaScript (JS) can be executed by inserting an iframe into the rich text html interface that links to...Show more |
In the Noo JobMonster WordPress theme before 4.5.2.9 JobMonster there is a XSS vulnerability as the input for the search form is provided through unsanitized GET requests. |
There is a XSS vulnerability in Careerfy. |
1Eyecix 1Jobsearch Wp Job Board Jun 17, 2026 Apr 4, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 There is a Cross-Site Scripting vulnerability in the JobSearch WP JobSearch WordPress plugin before 1.5.1. |
There are unauthenticated reflected Cross-Site Scripting (XSS) vulnerabilities in CareerUp Careerup WordPress theme before 2.3.1, via the filter parameters. |
The Wyzi Theme was affected by reflected XSS vulnerabilities in the business search feature |
The Mark Posts WordPress plugin before 2.0.1 does not escape new markers, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed |
1Ad Inserter Project 1Ad Inserter Jun 17, 2026 Apr 4, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The Ad Inserter Free and Pro WordPress plugins before 2.7.12 do not sanitise and escape the REQUEST_URI before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting in browsers which do not enc...Show more |
The Profile Builder WordPress plugin before 3.6.8 does not sanitise and escape Form Fields titles and description, which could allow high privilege user such as admin to perform Criss-Site Scripting attacks even when unf...Show more |
The UpdraftPlus WordPress Backup Plugin WordPress plugin before 1.22.9 does not sanitise and escape the updraft_interval parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting (...Show more |
1Insights From Google Pagespeed Project 1Insights From Google Pagespeed Jun 17, 2026 Apr 4, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The Insights from Google PageSpeed WordPress plugin before 4.0.4 does not sanitise and escape various parameters before outputting them back in attributes in the plugin's settings dashboard, leading to Reflected Cross-Si...Show more |
1Rumble Mail Server Project 1Rumble Mail Server Jun 17, 2026 Apr 4, 2022 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 A Cross Site Scripting (XSS) vulnerability exists in Rumble Mail Server 0.51.3135 via the username parameter. |
1Rumble Mail Server Project 1Rumble Mail Server Jun 17, 2026 Apr 4, 2022 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 Cross Site Scripting (XSS) vulnerability exists in Rumble Mail Server 0.51.3135 via the servername parameter. |
1Rumble Mail Server Project 1Rumble Mail Server Jun 17, 2026 Apr 4, 2022 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 A Cross Site Scripting (XSS) vulnerability exists in Rumble Mail Server 0.51.3135 via the (1) domain and (2) path parameters. |
1Dropdown Menu Widget Project 1Dropdown Menu Widget Jun 17, 2026 Apr 4, 2022 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 The Dropdown Menu Widget WordPress plugin through 1.9.7 does not have authorisation and CSRF checks when saving its settings, allowing low privilege users such as subscriber to update them. Due to the lack of sanitisatio...Show more |
The KingComposer WordPress plugin through 2.9.6 does not have authorisation, CSRF and sanitisation/escaping when creating profile, allowing any authenticated users to create arbitrary ones, with Cross-Site Scripting payl...Show more |
1Ecommerce Website Project 1Ecommerce Website Jun 17, 2026 Apr 4, 2022 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 A cross-site scripting (XSS) vulnerability in /public/admin/index.php?add_user at Ecommerce-Website v1.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the username text f...Show more |
1Public Knowledge Project 1Open Journal Systems Jun 17, 2026 Apr 4, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 PKP Vendor Open Journal System v2.4.8 to v3.3.8 allows attackers to perform reflected cross-site scripting (XSS) attacks via crafted HTTP headers. |