← Back
CWE-79

47,425 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (47,425)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Web Settler
1Testimonial Slider
Jun 17, 2026
Apr 4, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Authenticated (editor or higher user role) Cross-Site Scripting (XSS) vulnerability in Web-Settler Testimonial Slider – Free Testimonials Slider Plugin (WordPress plugin) via parameters mpsp_posts_bg_color, mpsp_posts_de...Show more
Authenticated (editor or higher user role) Cross-Site Scripting (XSS) vulnerability in Web-Settler Testimonial Slider – Free Testimonials Slider Plugin (WordPress plugin) via parameters mpsp_posts_bg_color, mpsp_posts_description_color, mpsp_slide_nav_button_color.Show less
1Wedevs
1Wp Project Manager
Jun 17, 2026
Apr 4, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Authenticated (subscriber or higher user role if allowed to access projects) Stored Cross-Site Scripting (XSS) vulnerability in weDevs WP Project Manager plugin <= 2.4.13 versions.
1Rangerstudio
1Directus
Jun 17, 2026
Apr 4, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Directus is a real-time API and App dashboard for managing SQL database content. Prior to version 9.7.0, unauthorized JavaScript (JS) can be executed by inserting an iframe into the rich text html interface that links to...Show more
Directus is a real-time API and App dashboard for managing SQL database content. Prior to version 9.7.0, unauthorized JavaScript (JS) can be executed by inserting an iframe into the rich text html interface that links to a file uploaded HTML file that loads another uploaded JS file in its script tag. This satisfies the regular content security policy header, which in turn allows the file to run any arbitrary JS. This issue was resolved in version 9.7.0. As a workaround, disable the live embed in the what-you-see-is-what-you-get by adding `{ "media_live_embeds": false }` to the _Options Overrides_ option of the Rich Text HTML interface.Show less
1Nootheme
1Jobmonster
Jun 17, 2026
Apr 4, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In the Noo JobMonster WordPress theme before 4.5.2.9 JobMonster there is a XSS vulnerability as the input for the search form is provided through unsanitized GET requests.
1Eyecix
1Careerfy
Jun 17, 2026
Apr 4, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
There is a XSS vulnerability in Careerfy.
1Eyecix
1Jobsearch Wp Job Board
Jun 17, 2026
Apr 4, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
There is a Cross-Site Scripting vulnerability in the JobSearch WP JobSearch WordPress plugin before 1.5.1.
1Apusthemes
1Careerup
Jun 17, 2026
Apr 4, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
There are unauthenticated reflected Cross-Site Scripting (XSS) vulnerabilities in CareerUp Careerup WordPress theme before 2.3.1, via the filter parameters.
1Wztechno
1Wyzi
Jun 17, 2026
Apr 4, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Wyzi Theme was affected by reflected XSS vulnerabilities in the business search feature
1Mark Posts Project
1Mark Posts
Jun 17, 2026
Apr 4, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The Mark Posts WordPress plugin before 2.0.1 does not escape new markers, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
1Ad Inserter Project
1Ad Inserter
Jun 17, 2026
Apr 4, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Ad Inserter Free and Pro WordPress plugins before 2.7.12 do not sanitise and escape the REQUEST_URI before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting in browsers which do not enc...Show more
The Ad Inserter Free and Pro WordPress plugins before 2.7.12 do not sanitise and escape the REQUEST_URI before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting in browsers which do not encode charactersShow less
1Cozmoslabs
1Profile Builder
Jun 17, 2026
Apr 4, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The Profile Builder WordPress plugin before 3.6.8 does not sanitise and escape Form Fields titles and description, which could allow high privilege user such as admin to perform Criss-Site Scripting attacks even when unf...Show more
The Profile Builder WordPress plugin before 3.6.8 does not sanitise and escape Form Fields titles and description, which could allow high privilege user such as admin to perform Criss-Site Scripting attacks even when unfiltered_html is disallowedShow less
1Updraftplus
1Updraftplus
Jun 17, 2026
Apr 4, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The UpdraftPlus WordPress Backup Plugin WordPress plugin before 1.22.9 does not sanitise and escape the updraft_interval parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting (...Show more
The UpdraftPlus WordPress Backup Plugin WordPress plugin before 1.22.9 does not sanitise and escape the updraft_interval parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting (XSS) vulnerability.Show less
1Insights From Google Pagespeed Project
1Insights From Google Pagespeed
Jun 17, 2026
Apr 4, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Insights from Google PageSpeed WordPress plugin before 4.0.4 does not sanitise and escape various parameters before outputting them back in attributes in the plugin's settings dashboard, leading to Reflected Cross-Si...Show more
The Insights from Google PageSpeed WordPress plugin before 4.0.4 does not sanitise and escape various parameters before outputting them back in attributes in the plugin's settings dashboard, leading to Reflected Cross-Site ScriptingShow less
1Rumble Mail Server Project
1Rumble Mail Server
Jun 17, 2026
Apr 4, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A Cross Site Scripting (XSS) vulnerability exists in Rumble Mail Server 0.51.3135 via the username parameter.
1Rumble Mail Server Project
1Rumble Mail Server
Jun 17, 2026
Apr 4, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross Site Scripting (XSS) vulnerability exists in Rumble Mail Server 0.51.3135 via the servername parameter.
1Rumble Mail Server Project
1Rumble Mail Server
Jun 17, 2026
Apr 4, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A Cross Site Scripting (XSS) vulnerability exists in Rumble Mail Server 0.51.3135 via the (1) domain and (2) path parameters.
1Dropdown Menu Widget Project
1Dropdown Menu Widget
Jun 17, 2026
Apr 4, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The Dropdown Menu Widget WordPress plugin through 1.9.7 does not have authorisation and CSRF checks when saving its settings, allowing low privilege users such as subscriber to update them. Due to the lack of sanitisatio...Show more
The Dropdown Menu Widget WordPress plugin through 1.9.7 does not have authorisation and CSRF checks when saving its settings, allowing low privilege users such as subscriber to update them. Due to the lack of sanitisation and escaping, it could also lead to Stored Cross-Site Scripting issuesShow less
1King Theme
1Kingcomposer
Jun 17, 2026
Apr 4, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The KingComposer WordPress plugin through 2.9.6 does not have authorisation, CSRF and sanitisation/escaping when creating profile, allowing any authenticated users to create arbitrary ones, with Cross-Site Scripting payl...Show more
The KingComposer WordPress plugin through 2.9.6 does not have authorisation, CSRF and sanitisation/escaping when creating profile, allowing any authenticated users to create arbitrary ones, with Cross-Site Scripting payloads in themShow less
1Ecommerce Website Project
1Ecommerce Website
Jun 17, 2026
Apr 4, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
A cross-site scripting (XSS) vulnerability in /public/admin/index.php?add_user at Ecommerce-Website v1.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the username text f...Show more
A cross-site scripting (XSS) vulnerability in /public/admin/index.php?add_user at Ecommerce-Website v1.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the username text field.Show less
1Public Knowledge Project
1Open Journal Systems
Jun 17, 2026
Apr 4, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
PKP Vendor Open Journal System v2.4.8 to v3.3.8 allows attackers to perform reflected cross-site scripting (XSS) attacks via crafted HTTP headers.