← Back
CWE-79

47,426 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (47,426)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Teampass
1Teampass
Jun 17, 2026
Mar 28, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Teampass 2.1.26 allows reflected XSS via the index.php PATH_INFO.
1Yithemes
1Woocommerce Affiliate
Jun 17, 2026
Mar 28, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The WooCommerce Affiliate Plugin WordPress plugin before 4.16.4.5 does not have authorization and CSRF checks on a specific action handler, as well as does not sanitize its settings, which enables an unauthenticated atta...Show more
The WooCommerce Affiliate Plugin WordPress plugin before 4.16.4.5 does not have authorization and CSRF checks on a specific action handler, as well as does not sanitize its settings, which enables an unauthenticated attacker to inject malicious XSS payloads into the settings page of the plugin.Show less
1Plezi
1Plezi
Jun 17, 2026
Mar 28, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Plezi WordPress plugin before 1.0.3 has a REST endpoint allowing unauthenticated users to update the plz_configuration_tracker_enable option, which is then displayed in the admin panel without sanitisation and escapi...Show more
The Plezi WordPress plugin before 1.0.3 has a REST endpoint allowing unauthenticated users to update the plz_configuration_tracker_enable option, which is then displayed in the admin panel without sanitisation and escaping, leading to a Stored Cross-Site Scripting issueShow less
1Bulk Creator Project
1Bulk Creator
Jun 17, 2026
Mar 28, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Bulk Creator WordPress plugin through 1.0.1 does not sanitize and escape the post_type parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting.
1Bank Mellat Project
1Bank Mellat
Jun 17, 2026
Mar 28, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Bank Mellat WordPress plugin through 1.3.7 does not sanitize and escape the orderId parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting.
1Ays Pro
1Popup Like Box
Jun 17, 2026
Mar 28, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Popup Like box WordPress plugin before 3.6.1 does not sanitize and escape the ays_fb_tab parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting.
1Dtabs Project
1Dtabs
Jun 17, 2026
Mar 28, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The dTabs WordPress plugin through 1.4 does not sanitize and escape the tab parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting.
1Deleteoldorders Project
1Delete Old Orders
Jun 17, 2026
Mar 28, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Delete Old Orders WordPress plugin through 0.2 does not sanitize and escape the date parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting.
1Database Peek Project
1Database Peek
Jun 17, 2026
Mar 28, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Database Peek WordPress plugin through 1.2 does not sanitize and escape the match parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting.
1Myceliumdesign
1Conference Scheduler
Jun 17, 2026
Mar 28, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Conference Scheduler WordPress plugin before 2.4.3 does not sanitize and escape the tab parameter before outputting back in an admin page, leading to a Reflected Cross-Site Scripting.
1Mapping Multiple Urls Redirect Same Page Project
1Mapping Multiple Urls Redirect Same Page
Jun 17, 2026
Mar 28, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Mapping Multiple URLs Redirect Same Page WordPress plugin through 5.8 does not sanitize and escape the mmursp_id parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting.
1Codedropz
1Drag And Drop Multiple File Upload Contact Form 7
Jun 17, 2026
Mar 28, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The Drag and Drop Multiple File Upload WordPress plugin before 1.3.6.3 allows SVG files to be uploaded by default via the dnd_codedropz_upload AJAX action, which could lead to Stored Cross-Site Scripting issue
1Wpclever
1Wpc Smart Wishlist For Woocommerce
Jun 17, 2026
Mar 28, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The WPC Smart Wishlist for WooCommerce WordPress plugin before 2.9.4 does not sanitise and escape the key parameter before outputting it back in the wishlist_quickview AJAX action's response (available to any authenticat...Show more
The WPC Smart Wishlist for WooCommerce WordPress plugin before 2.9.4 does not sanitise and escape the key parameter before outputting it back in the wishlist_quickview AJAX action's response (available to any authenticated user), leading to a Reflected Cross-Site ScriptingShow less
1Humananatomyillustrations
1Interactive Medical Drawing Of Human Body
Jun 17, 2026
Mar 28, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The Interactive Medical Drawing of Human Body WordPress plugin before 2.6 does not sanitise and escape the Link field, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html c...Show more
The Interactive Medical Drawing of Human Body WordPress plugin before 2.6 does not sanitise and escape the Link field, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.Show less
1Inpsyde
1Akismet Privacy Policies
Jun 17, 2026
Mar 28, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The WordPress plugin through 2.0.1 does not sanitise and escape the translation parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting
1Popozure
1Pz Linkcard
Jun 17, 2026
Mar 28, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Pz-LinkCard WordPress plugin through 2.4.4.4 does not sanitise and escape multiple parameters before outputting them back in admin dashboard pages, leading to Reflected Cross-Site Scripting issues
1Heateor
1Sassy Social Share
Jun 17, 2026
Mar 28, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Social Sharing Plugin WordPress plugin before 3.3.40 does not escape the viewed post URL before outputting it back in onclick attributes when the "Enable 'More' icon" option is enabled (which is the default setting),...Show more
The Social Sharing Plugin WordPress plugin before 3.3.40 does not escape the viewed post URL before outputting it back in onclick attributes when the "Enable 'More' icon" option is enabled (which is the default setting), leading to a Reflected Cross-Site Scripting issue.Show less
1Leanote
1Leanote
Jun 17, 2026
Mar 28, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Leanote 2.7.0 is vulnerable to Cross Site Scripting (XSS) in the markdown type note. This leads to remote code execution with payload : <video src=x onerror=(function(){require('child_process').exec('calc');})();>
1Spotweb Project
1Spotweb
Jun 17, 2026
Mar 28, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
There is a Cross Site Scripting (XSS) vulnerability in SpotPage_login.php of Spotweb 1.5.1 and below, which allows remote attackers to inject arbitrary web script or HTML via the data[performredirect] parameter.
1Open Xchange
1Ox App Suite
Jun 17, 2026
Mar 28, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
OX App Suite through 7.10.5 allows XSS via uuencoding in a multipart/alternative message.