CWE-79
47,440 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (47,440)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The dTabs WordPress plugin through 1.4 does not sanitize and escape the tab parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting. |
1Deleteoldorders Project 1Delete Old Orders Jun 17, 2026 Mar 28, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The Delete Old Orders WordPress plugin through 0.2 does not sanitize and escape the date parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting. |
1Database Peek Project 1Database Peek Jun 17, 2026 Mar 28, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The Database Peek WordPress plugin through 1.2 does not sanitize and escape the match parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting. |
1Myceliumdesign 1Conference Scheduler Jun 17, 2026 Mar 28, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The Conference Scheduler WordPress plugin before 2.4.3 does not sanitize and escape the tab parameter before outputting back in an admin page, leading to a Reflected Cross-Site Scripting. |
1Mapping Multiple Urls Redirect Same Page Project 1Mapping Multiple Urls Redirect Same Page Jun 17, 2026 Mar 28, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The Mapping Multiple URLs Redirect Same Page WordPress plugin through 5.8 does not sanitize and escape the mmursp_id parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting. |
1Codedropz 1Drag And Drop Multiple File Upload Contact Form 7 Jun 17, 2026 Mar 28, 2022 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 The Drag and Drop Multiple File Upload WordPress plugin before 1.3.6.3 allows SVG files to be uploaded by default via the dnd_codedropz_upload AJAX action, which could lead to Stored Cross-Site Scripting issue |
1Wpclever 1Wpc Smart Wishlist For Woocommerce Jun 17, 2026 Mar 28, 2022 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 The WPC Smart Wishlist for WooCommerce WordPress plugin before 2.9.4 does not sanitise and escape the key parameter before outputting it back in the wishlist_quickview AJAX action's response (available to any authenticat...Show more |
1Humananatomyillustrations 1Interactive Medical Drawing Of Human Body Jun 17, 2026 Mar 28, 2022 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 The Interactive Medical Drawing of Human Body WordPress plugin before 2.6 does not sanitise and escape the Link field, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html c...Show more |
1Inpsyde 1Akismet Privacy Policies Jun 17, 2026 Mar 28, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The WordPress plugin through 2.0.1 does not sanitise and escape the translation parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting |
The Pz-LinkCard WordPress plugin through 2.4.4.4 does not sanitise and escape multiple parameters before outputting them back in admin dashboard pages, leading to Reflected Cross-Site Scripting issues |
1Heateor 1Sassy Social Share Jun 17, 2026 Mar 28, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The Social Sharing Plugin WordPress plugin before 3.3.40 does not escape the viewed post URL before outputting it back in onclick attributes when the "Enable 'More' icon" option is enabled (which is the default setting),...Show more |
Leanote 2.7.0 is vulnerable to Cross Site Scripting (XSS) in the markdown type note. This leads to remote code execution with payload : <video src=x onerror=(function(){require('child_process').exec('calc');})();> |
There is a Cross Site Scripting (XSS) vulnerability in SpotPage_login.php of Spotweb 1.5.1 and below, which allows remote attackers to inject arbitrary web script or HTML via the data[performredirect] parameter. |
OX App Suite through 7.10.5 allows XSS via uuencoding in a multipart/alternative message. |
OX App Suite through 7.10.5 allows XSS via a trailing control character such as the SCRIPT\t substring. |
OX App Suite through 7.10.5 allows XSS via the class attribute of an element in an HTML e-mail signature. |
OX App Suite through 7.10.5 allows XSS via NIFF (Notation Interchange File Format) data. |
OX App Suite through 7.10.5 allows XSS via an HTML 5 element such as AUDIO. |
OX App Suite through 7.10.5 allows XSS via an unknown system message in Chat. |
Clash for Windows v0.19.8 was discovered to allow arbitrary code execution via a crafted payload injected into the Proxies name column. |