← Back
CWE-79

47,450 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (47,450)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Price Table Project
1Price Table
Jun 17, 2026
Mar 18, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Authenticated (contributor of higher user role) Stored Cross-Site Scripting (XSS) vulnerability discovered in WordPress Price Table plugin (versions <= 0.2.2).
1Maxfoundry
1Maxgalleria
Jun 17, 2026
Mar 18, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Authenticated (author or higher user role) Stored Cross-Site Scripting (XSS) vulnerability discovered in MaxGalleria WordPress plugin (versions 6.2.5).
1Mattermost
1Mattermost
Jun 17, 2026
Mar 18, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Mattermost 6.3.0 and earlier fails to properly sanitize the HTML content in the email invitation sent to guest users, which allows registered users with special permissions to invite guest users to inject unescaped HTML...Show more
Mattermost 6.3.0 and earlier fails to properly sanitize the HTML content in the email invitation sent to guest users, which allows registered users with special permissions to invite guest users to inject unescaped HTML content in the email invitations.Show less
1Wp Downloadmanager Project
1Wp Downloadmanager
Jun 17, 2026
Mar 18, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Auth. (admin+) Reflected Cross-Site Scripting (XSS) vulnerability discovered in WP-DownloadManager plugin <= 1.68.6 versions.
1Ampforwp
1Accelerated Mobile Pages
Jun 17, 2026
Mar 18, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Multiple Authenticated (admin user role) Persistent Cross-Site Scripting (XSS) vulnerabilities discovered in AMP for WP – Accelerated Mobile Pages WordPress plugin (versions <= 1.0.77.32).
1Ampforwp
1Accelerated Mobile Pages
Jun 17, 2026
Mar 18, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability discovered in AMP for WP – Accelerated Mobile Pages plugin <= 1.0.77.31 versions.
1Rapid7
1Nexpose
Jun 17, 2026
Mar 17, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Rapid7 Nexpose versions 6.6.129 and earlier suffer from a reflected cross site scripting vulnerability, within the shared scan configuration component of the tool. With this vulnerability an attacker could pass literal v...Show more
Rapid7 Nexpose versions 6.6.129 and earlier suffer from a reflected cross site scripting vulnerability, within the shared scan configuration component of the tool. With this vulnerability an attacker could pass literal values as the test credentials, providing the opportunity for a potential XSS attack. This issue is fixed in Rapid7 Nexpose version 6.6.130.Show less
1Sonatype
1Nexus Repository Manager
Jun 17, 2026
Mar 17, 2022
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
Sonatype Nexus Repository Manager 3.36.0 allows HTML Injection.
1Post Loader Project
1Post Loader
Jun 17, 2026
Mar 17, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The package post-loader from 0.0.0 are vulnerable to Arbitrary Code Execution which uses a markdown parser in an unsafe way so that any javascript code inside the markdown input files gets evaluated and executed.
1Slims
1Senayan Library Management System
Jun 17, 2026
Mar 17, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Slims9 Bulian 9.4.2 is affected by Cross Site Scripting (XSS) in /admin/modules/system/custom_field.php.
1Online Project Time Management System Project
1Online Project Time Management System
Jun 17, 2026
Mar 16, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A stored cross-site scripting (XSS) vulnerability in /ptms/?page=user of Online Project Time Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the user n...Show more
A stored cross-site scripting (XSS) vulnerability in /ptms/?page=user of Online Project Time Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the user name field.Show less
4Ckeditor
DrupalFedoraproject+1 more
9Application Express
CkeditorCommerce Merchandising+6 more
Jun 17, 2026
Mar 16, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A vulnerability has been discovered in the core HTML processing module and may affect all plugins used by CKEditor 4 prior to version 4.18.0. The vuln...Show more
CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A vulnerability has been discovered in the core HTML processing module and may affect all plugins used by CKEditor 4 prior to version 4.18.0. The vulnerability allows someone to inject malformed HTML bypassing content sanitization, which could result in executing JavaScript code. This problem has been patched in version 4.18.0. There are currently no known workarounds.Show less
1Btiteam
1Xbtit
Jun 17, 2026
Mar 16, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A cross-site scripting vulnerability is present in Xbtit 3.1. The stored XSS vulnerability occurs because /ajaxchat/sendChatData.php does not properly validate the value of the "n" (POST) parameter. Through this vulnerab...Show more
A cross-site scripting vulnerability is present in Xbtit 3.1. The stored XSS vulnerability occurs because /ajaxchat/sendChatData.php does not properly validate the value of the "n" (POST) parameter. Through this vulnerability, an attacker is capable to execute malicious JavaScript code.Show less
2Fedoraproject
Paypal
2Braintree/sanitize Url
Fedora
Jun 17, 2026
Mar 16, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The package @braintree/sanitize-url before 6.0.0 are vulnerable to Cross-site Scripting (XSS) due to improper sanitization in sanitizeUrl function.
1X2engine
1X2crm
Jun 17, 2026
Mar 16, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A Cross-Site Scripting (XSS) attack can cause arbitrary code (javascript) to run in a user’s browser while the browser is connected to a trusted website. As the vehicle for the attack, the application targets the users a...Show more
A Cross-Site Scripting (XSS) attack can cause arbitrary code (javascript) to run in a user’s browser while the browser is connected to a trusted website. As the vehicle for the attack, the application targets the users and not the application itself. Additionally, the XSS payload is executed when the user attempts to access any page of the CRM.Show less
1Hestiacp
1Control Panel
Jun 17, 2026
Mar 16, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Reflected Cross-site Scripting (XSS) Vulnerability in GitHub repository hestiacp/hestiacp prior to 1.5.11.
1Maccms
1Maccms
Jun 17, 2026
Mar 16, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
There is a stored Cross Site Scripting (XSS) vulnerability in maccms v10 through adding videos. XSS code can be inserted at parameter positions including name and remarks.
1Archivista
1Archivistabox
Jun 17, 2026
Mar 16, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site Scripting (XSS) vulnerability in ArchivistaBox webclient allows an attacker to craft a malicious link, executing JavaScript in the context of a victim's browser. This issue affects all ArchivistaBox versions p...Show more
Cross-site Scripting (XSS) vulnerability in ArchivistaBox webclient allows an attacker to craft a malicious link, executing JavaScript in the context of a victim's browser. This issue affects all ArchivistaBox versions prior to 2022/I.Show less
1Pimcore
1Pimcore
Jun 17, 2026
Mar 16, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.4.0.
1Pimcore
1Pimcore
Jun 17, 2026
Mar 16, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.4.0.