← Back
CWE-79

47,440 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (47,440)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Dtabs Project
1Dtabs
Jun 17, 2026
Mar 28, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The dTabs WordPress plugin through 1.4 does not sanitize and escape the tab parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting.
1Deleteoldorders Project
1Delete Old Orders
Jun 17, 2026
Mar 28, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Delete Old Orders WordPress plugin through 0.2 does not sanitize and escape the date parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting.
1Database Peek Project
1Database Peek
Jun 17, 2026
Mar 28, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Database Peek WordPress plugin through 1.2 does not sanitize and escape the match parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting.
1Myceliumdesign
1Conference Scheduler
Jun 17, 2026
Mar 28, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Conference Scheduler WordPress plugin before 2.4.3 does not sanitize and escape the tab parameter before outputting back in an admin page, leading to a Reflected Cross-Site Scripting.
1Mapping Multiple Urls Redirect Same Page Project
1Mapping Multiple Urls Redirect Same Page
Jun 17, 2026
Mar 28, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Mapping Multiple URLs Redirect Same Page WordPress plugin through 5.8 does not sanitize and escape the mmursp_id parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting.
1Codedropz
1Drag And Drop Multiple File Upload Contact Form 7
Jun 17, 2026
Mar 28, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The Drag and Drop Multiple File Upload WordPress plugin before 1.3.6.3 allows SVG files to be uploaded by default via the dnd_codedropz_upload AJAX action, which could lead to Stored Cross-Site Scripting issue
1Wpclever
1Wpc Smart Wishlist For Woocommerce
Jun 17, 2026
Mar 28, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The WPC Smart Wishlist for WooCommerce WordPress plugin before 2.9.4 does not sanitise and escape the key parameter before outputting it back in the wishlist_quickview AJAX action's response (available to any authenticat...Show more
The WPC Smart Wishlist for WooCommerce WordPress plugin before 2.9.4 does not sanitise and escape the key parameter before outputting it back in the wishlist_quickview AJAX action's response (available to any authenticated user), leading to a Reflected Cross-Site ScriptingShow less
1Humananatomyillustrations
1Interactive Medical Drawing Of Human Body
Jun 17, 2026
Mar 28, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The Interactive Medical Drawing of Human Body WordPress plugin before 2.6 does not sanitise and escape the Link field, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html c...Show more
The Interactive Medical Drawing of Human Body WordPress plugin before 2.6 does not sanitise and escape the Link field, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.Show less
1Inpsyde
1Akismet Privacy Policies
Jun 17, 2026
Mar 28, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The WordPress plugin through 2.0.1 does not sanitise and escape the translation parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting
1Popozure
1Pz Linkcard
Jun 17, 2026
Mar 28, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Pz-LinkCard WordPress plugin through 2.4.4.4 does not sanitise and escape multiple parameters before outputting them back in admin dashboard pages, leading to Reflected Cross-Site Scripting issues
1Heateor
1Sassy Social Share
Jun 17, 2026
Mar 28, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Social Sharing Plugin WordPress plugin before 3.3.40 does not escape the viewed post URL before outputting it back in onclick attributes when the "Enable 'More' icon" option is enabled (which is the default setting),...Show more
The Social Sharing Plugin WordPress plugin before 3.3.40 does not escape the viewed post URL before outputting it back in onclick attributes when the "Enable 'More' icon" option is enabled (which is the default setting), leading to a Reflected Cross-Site Scripting issue.Show less
1Leanote
1Leanote
Jun 17, 2026
Mar 28, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Leanote 2.7.0 is vulnerable to Cross Site Scripting (XSS) in the markdown type note. This leads to remote code execution with payload : <video src=x onerror=(function(){require('child_process').exec('calc');})();>
1Spotweb Project
1Spotweb
Jun 17, 2026
Mar 28, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
There is a Cross Site Scripting (XSS) vulnerability in SpotPage_login.php of Spotweb 1.5.1 and below, which allows remote attackers to inject arbitrary web script or HTML via the data[performredirect] parameter.
1Open Xchange
1Ox App Suite
Jun 17, 2026
Mar 28, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
OX App Suite through 7.10.5 allows XSS via uuencoding in a multipart/alternative message.
1Open Xchange
1Ox App Suite
Jun 17, 2026
Mar 28, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
OX App Suite through 7.10.5 allows XSS via a trailing control character such as the SCRIPT\t substring.
1Open Xchange
1Ox App Suite
Jun 17, 2026
Mar 28, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
OX App Suite through 7.10.5 allows XSS via the class attribute of an element in an HTML e-mail signature.
1Open Xchange
1Ox App Suite
Jun 17, 2026
Mar 28, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
OX App Suite through 7.10.5 allows XSS via NIFF (Notation Interchange File Format) data.
1Open Xchange
1Ox App Suite
Jun 17, 2026
Mar 28, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
OX App Suite through 7.10.5 allows XSS via an HTML 5 element such as AUDIO.
1Open Xchange
1Ox App Suite
Jun 17, 2026
Mar 28, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
OX App Suite through 7.10.5 allows XSS via an unknown system message in Chat.
1Clash Project
1Clash
Jun 17, 2026
Mar 28, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Clash for Windows v0.19.8 was discovered to allow arbitrary code execution via a crafted payload injected into the Proxies name column.