← Back
CWE-79

47,442 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (47,442)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Hongmen
1Parking Management System
Jun 17, 2026
Mar 24, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Multiple cross-site scripting (XSS) vulnerabilities in Parking Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via crafted payloads injected into the user name, password, and verification...Show more
Multiple cross-site scripting (XSS) vulnerabilities in Parking Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via crafted payloads injected into the user name, password, and verification code text boxes.Show less
1Pimcore
1Data Hub
Jun 17, 2026
Mar 24, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/data-hub prior to 1.2.4.
1Rengine Project
1Rengine
Jun 17, 2026
Mar 24, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A Cross Site Scripting (XSS) vulnerability exists in Yogesh Ojha reNgine v1.0 via the Scan Engine name file in the Scan Engine deletion confirmation modal box . .
1Halo
1Halo
Jun 17, 2026
Mar 24, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
In halo 1.4.14, the function point of uploading the avatar, any file can be uploaded, such as uploading an HTML file, which will cause a stored XSS vulnerability.
1Fork Cms
1Fork Cms
Jun 17, 2026
Mar 24, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-site Scripting (XSS) - Stored in GitHub repository forkcms/forkcms prior to 5.11.1.
1Passwork
1Passwork
Jun 17, 2026
Mar 23, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Passwork On-Premise Edition before 4.6.13 has multiple XSS issues.
1Yooslider
1Yoo Slider
Jun 17, 2026
Mar 23, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Stored Cross-Site Scripting (XSS) in Yoo Slider – Image Slider & Video Slider (WordPress plugin) allows attackers with contributor or higher user role to inject the malicious code.
1Money Transfer Management System Project
1Money Transfer Management System
Jun 17, 2026
Mar 23, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Money Transfer Management System Version 1.0 allows an attacker to inject JavaScript code in the URL and then trick a user into visit the link in order to execute JavaScript code.
1Ninjaforms
1Ninja Forms File Uploads
Jun 17, 2026
Mar 23, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Ninja Forms - File Uploads Extension WordPress plugin is vulnerable to reflected cross-site scripting due to missing sanitization of the files filename parameter found in the ~/includes/ajax/controllers/uploads.php f...Show more
The Ninja Forms - File Uploads Extension WordPress plugin is vulnerable to reflected cross-site scripting due to missing sanitization of the files filename parameter found in the ~/includes/ajax/controllers/uploads.php file which can be used by unauthenticated attackers to add malicious web scripts to vulnerable WordPress sites, in versions up to and including 3.3.12.Show less
1Wpamelia
1Amelia
Jun 17, 2026
Mar 23, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The Amelia WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and sanitization of the lastName parameter found in the ~/src/Application/Controller/User/Customer/AddCustomerController.php...Show more
The Amelia WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and sanitization of the lastName parameter found in the ~/src/Application/Controller/User/Customer/AddCustomerController.php file which allows attackers to inject arbitrary web scripts onto a pages that executes whenever a user accesses the booking calendar with the date the attacker has injected the malicious payload into. This affects versions up to and including 1.0.46.Show less
1Thriveweb
1Photoswipe Masonry Gallery
Jun 17, 2026
Mar 23, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The Photoswipe Masonry Gallery WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and sanitization of the thumbnail_width, thumbnail_height, max_image_width, and max_image_height paramete...Show more
The Photoswipe Masonry Gallery WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and sanitization of the thumbnail_width, thumbnail_height, max_image_width, and max_image_height parameters found in the ~/photoswipe-masonry.php file which allows authenticated attackers to inject arbitrary web scripts into galleries created by the plugin and on the PhotoSwipe Options page. This affects versions up to and including 1.2.14.Show less
1Ge
19Multilin B30 Firmware
Multilin B90 FirmwareMultilin C30 Firmware+16 more
Jun 17, 2026
Mar 23, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
GE UR firmware versions prior to version 8.1x supports web interface with read-only access. The device fails to properly validate user input, making it possible to perform cross-site scripting attacks, which may be used...Show more
GE UR firmware versions prior to version 8.1x supports web interface with read-only access. The device fails to properly validate user input, making it possible to perform cross-site scripting attacks, which may be used to send a malicious script. Also, UR Firmware web server does not perform HTML encoding of user-supplied strings.Show less
1Mcafee
1Epolicy Orchestrator
Jun 17, 2026
Mar 23, 2022
N/A· v4
4.7 MEDIUM· v3
4.3 MEDIUM· v2
A cross-site scripting (XSS) vulnerability in McAfee Enterprise ePolicy Orchestrator (ePO) prior to 5.10 Update 13 allows a remote attacker to potentially obtain access to an ePO administrator's session by convincing the...Show more
A cross-site scripting (XSS) vulnerability in McAfee Enterprise ePolicy Orchestrator (ePO) prior to 5.10 Update 13 allows a remote attacker to potentially obtain access to an ePO administrator's session by convincing the attacker to click on a carefully crafted link. This would lead to limited ability to alter some information in ePO due to the area of the User Interface the vulnerability is present in.Show less
1Mcafee
1Epolicy Orchestrator
Jun 17, 2026
Mar 23, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A reflected cross-site scripting (XSS) vulnerability in McAfee Enterprise ePolicy Orchestrator (ePO) prior to 5.10 Update 13 allows a remote attacker to potentially obtain access to an ePO administrator's session by conv...Show more
A reflected cross-site scripting (XSS) vulnerability in McAfee Enterprise ePolicy Orchestrator (ePO) prior to 5.10 Update 13 allows a remote attacker to potentially obtain access to an ePO administrator's session by convincing the attacker to click on a carefully crafted link. This would lead to limited access to sensitive information and limited ability to alter some information in ePO due to the area of the User Interface the vulnerability is present in.Show less
1Enhanced Github Project
1Enhanced Github
Jun 17, 2026
Mar 22, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A Cross Site Scripting (XSS) vulnerabililty exists in enhanced-github v5.0.11 via the file name parameter.
1Bigantsoft
1Bigant Server
Jul 9, 2026
Mar 21, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
BigAnt Software BigAnt Server v5.6.06 was discovered to contain a cross-site scripting (XSS) vulnerability.
1Wpdevart
1Pricing Table Builder
Jun 17, 2026
Mar 21, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Pricing Table Builder WordPress plugin before 1.1.5 does not sanitize and escape the postid parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting.
1Accesspressthemes
1Ap Mega Menu
Jun 17, 2026
Mar 21, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Mega Menu WordPress plugin before 3.0.8 does not sanitize and escape the _wpnonce parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting.
1Tms Outsource
1Amelia
Jun 17, 2026
Mar 21, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Amelia WordPress plugin before 1.0.47 does not sanitize and escape the code parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting.
1Ait Pro
1Bulletproof Security
Jun 17, 2026
Mar 21, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The BulletProof Security WordPress plugin before 5.8 does not sanitise and escape some of its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capabil...Show more
The BulletProof Security WordPress plugin before 5.8 does not sanitise and escape some of its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.Show less