CWE-79
47,426 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (47,426)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Teampass 2.1.26 allows reflected XSS via the index.php PATH_INFO. |
1Yithemes 1Woocommerce Affiliate Jun 17, 2026 Mar 28, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The WooCommerce Affiliate Plugin WordPress plugin before 4.16.4.5 does not have authorization and CSRF checks on a specific action handler, as well as does not sanitize its settings, which enables an unauthenticated atta...Show more |
The Plezi WordPress plugin before 1.0.3 has a REST endpoint allowing unauthenticated users to update the plz_configuration_tracker_enable option, which is then displayed in the admin panel without sanitisation and escapi...Show more |
1Bulk Creator Project 1Bulk Creator Jun 17, 2026 Mar 28, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The Bulk Creator WordPress plugin through 1.0.1 does not sanitize and escape the post_type parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting. |
1Bank Mellat Project 1Bank Mellat Jun 17, 2026 Mar 28, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The Bank Mellat WordPress plugin through 1.3.7 does not sanitize and escape the orderId parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting. |
The Popup Like box WordPress plugin before 3.6.1 does not sanitize and escape the ays_fb_tab parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting. |
The dTabs WordPress plugin through 1.4 does not sanitize and escape the tab parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting. |
1Deleteoldorders Project 1Delete Old Orders Jun 17, 2026 Mar 28, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The Delete Old Orders WordPress plugin through 0.2 does not sanitize and escape the date parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting. |
1Database Peek Project 1Database Peek Jun 17, 2026 Mar 28, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The Database Peek WordPress plugin through 1.2 does not sanitize and escape the match parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting. |
1Myceliumdesign 1Conference Scheduler Jun 17, 2026 Mar 28, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The Conference Scheduler WordPress plugin before 2.4.3 does not sanitize and escape the tab parameter before outputting back in an admin page, leading to a Reflected Cross-Site Scripting. |
1Mapping Multiple Urls Redirect Same Page Project 1Mapping Multiple Urls Redirect Same Page Jun 17, 2026 Mar 28, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The Mapping Multiple URLs Redirect Same Page WordPress plugin through 5.8 does not sanitize and escape the mmursp_id parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting. |
1Codedropz 1Drag And Drop Multiple File Upload Contact Form 7 Jun 17, 2026 Mar 28, 2022 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 The Drag and Drop Multiple File Upload WordPress plugin before 1.3.6.3 allows SVG files to be uploaded by default via the dnd_codedropz_upload AJAX action, which could lead to Stored Cross-Site Scripting issue |
1Wpclever 1Wpc Smart Wishlist For Woocommerce Jun 17, 2026 Mar 28, 2022 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 The WPC Smart Wishlist for WooCommerce WordPress plugin before 2.9.4 does not sanitise and escape the key parameter before outputting it back in the wishlist_quickview AJAX action's response (available to any authenticat...Show more |
1Humananatomyillustrations 1Interactive Medical Drawing Of Human Body Jun 17, 2026 Mar 28, 2022 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 The Interactive Medical Drawing of Human Body WordPress plugin before 2.6 does not sanitise and escape the Link field, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html c...Show more |
1Inpsyde 1Akismet Privacy Policies Jun 17, 2026 Mar 28, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The WordPress plugin through 2.0.1 does not sanitise and escape the translation parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting |
The Pz-LinkCard WordPress plugin through 2.4.4.4 does not sanitise and escape multiple parameters before outputting them back in admin dashboard pages, leading to Reflected Cross-Site Scripting issues |
1Heateor 1Sassy Social Share Jun 17, 2026 Mar 28, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The Social Sharing Plugin WordPress plugin before 3.3.40 does not escape the viewed post URL before outputting it back in onclick attributes when the "Enable 'More' icon" option is enabled (which is the default setting),...Show more |
Leanote 2.7.0 is vulnerable to Cross Site Scripting (XSS) in the markdown type note. This leads to remote code execution with payload : <video src=x onerror=(function(){require('child_process').exec('calc');})();> |
There is a Cross Site Scripting (XSS) vulnerability in SpotPage_login.php of Spotweb 1.5.1 and below, which allows remote attackers to inject arbitrary web script or HTML via the data[performredirect] parameter. |
OX App Suite through 7.10.5 allows XSS via uuencoding in a multipart/alternative message. |