← Back
CWE-79

47,450 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (47,450)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Pimcore
1Pimcore
Jun 17, 2026
Mar 15, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.4.0.
1Pimcore
1Pimcore
Jun 17, 2026
Mar 15, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.4.0.
1Showdoc
1Showdoc
Jun 17, 2026
Mar 15, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
File Upload Restriction Bypass leading to Stored XSS Vulnerability in GitHub repository star7th/showdoc prior to 2.10.4.
1Showdoc
1Showdoc
Jun 17, 2026
Mar 15, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Stored XSS viva axd and cshtml file upload in star7th/showdoc in GitHub repository star7th/showdoc prior to v2.10.4.
1Sylius
1Sylius
Jun 17, 2026
Mar 14, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Sylius is an open source eCommerce platform. In versions prior to 1.9.10, 1.10.11, and 1.11.2, it is possible to upload an SVG file containing cross-site scripting (XSS) code in the admin panel. In order to perform a XSS...Show more
Sylius is an open source eCommerce platform. In versions prior to 1.9.10, 1.10.11, and 1.11.2, it is possible to upload an SVG file containing cross-site scripting (XSS) code in the admin panel. In order to perform a XSS attack, the file itself has to be open in a new card or loaded outside of the IMG tag. The problem applies both to the files opened on the admin panel and shop pages. The issue is fixed in versions 1.9.10, 1.10.11, and 1.11.2. As a workaround, require a library that adds on-upload file sanitization and overwrite the service before writing the file to the filesystem. The GitHub Security Advisory contains more specific information about the workaround.Show less
1Ibm
1Spectrum Copy Data Management
Jun 17, 2026
Mar 14, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM Spectrum Copy Data Management 2.2.0.0 through 2.2.14.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality...Show more
IBM Spectrum Copy Data Management 2.2.0.0 through 2.2.14.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 214534.Show less
1Showdoc
1Showdoc
Jun 17, 2026
Mar 14, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Stored XSS viva .webma file upload in GitHub repository star7th/showdoc prior to 2.10.4.
1Showdoc
1Showdoc
Jun 17, 2026
Mar 14, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Stored XSS viva .properties file upload in GitHub repository star7th/showdoc prior to 2.10.4.
1Gd Mylist Project
1Gd Mylist
Jun 17, 2026
Mar 14, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The GD Mylist WordPress plugin through 1.1.1 does not sanitise and escape some of its settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability...Show more
The GD Mylist WordPress plugin through 1.1.1 does not sanitise and escape some of its settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowedShow less
1Unboxinteractive
1Petfinder Listings
Jun 17, 2026
Mar 14, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The Petfinder Listings WordPress plugin through 1.0.18 does not escape its settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallo...Show more
The Petfinder Listings WordPress plugin through 1.0.18 does not escape its settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowedShow less
1Seo 301 Meta Project
1Seo 301 Meta
Jun 17, 2026
Mar 14, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The SEO 301 Meta WordPress plugin through 1.9.1 does not escape its Request and Destination settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capa...Show more
The SEO 301 Meta WordPress plugin through 1.9.1 does not escape its Request and Destination settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowedShow less
1Chrsinteractive
1Simple Tracking
Jun 17, 2026
Mar 14, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The Simple Tracking WordPress plugin before 1.7 does not sanitise and escape its settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is d...Show more
The Simple Tracking WordPress plugin before 1.7 does not sanitise and escape its settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowedShow less
1Wp Home Page Menu Project
1Wp Home Page Menu
Jun 17, 2026
Mar 14, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The WP Home Page Menu WordPress plugin before 3.1 does not sanitise and escape its settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is...Show more
The WP Home Page Menu WordPress plugin before 3.1 does not sanitise and escape its settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowedShow less
1Kunze Medien
1Kunze Law
Jun 17, 2026
Mar 14, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The Kunze Law WordPress plugin before 2.1 does not escape its 'E-Mail Error "From" Address' settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capa...Show more
The Kunze Law WordPress plugin before 2.1 does not escape its 'E-Mail Error "From" Address' settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowedShow less
1Sync Qcloud Cos Project
1Sync Qcloud Cos
Jun 17, 2026
Mar 14, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The Sync QCloud COS WordPress plugin before 2.0.1 does not escape some of its settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disa...Show more
The Sync QCloud COS WordPress plugin before 2.0.1 does not escape some of its settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowedShow less
1I13websolution
1Team Circle Image Slider With Lightbox
Jun 17, 2026
Mar 14, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Team Circle Image Slider With Lightbox WordPress plugin before 1.0.16 does not sanitize and escape the order_pos parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting.
1Edmonsoft
1Countdown, Coming Soon, Maintenance Countdown & Clock
Jun 17, 2026
Mar 14, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Countdown, Coming Soon, Maintenance WordPress plugin before 2.2.9 does not sanitize and escape the post parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting.
1Obtaininfotech
1Multisite Content Copier/updater
Jun 17, 2026
Mar 14, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The WordPress Multisite Content Copier/Updater WordPress plugin before 2.1.2 does not sanitise and escape the s parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting issue in th...Show more
The WordPress Multisite Content Copier/Updater WordPress plugin before 2.1.2 does not sanitise and escape the s parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting issue in the network dashboardShow less
1Odude
1Flexi
Jun 17, 2026
Mar 14, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Flexi WordPress plugin before 4.20 does not sanitise and escape various parameters before outputting them back in some pages such as the user dashboard, leading to a Reflected Cross-Site Scripting
1Berocket
1Advanced Product Labels For Woocommerce
Jun 17, 2026
Mar 14, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Advanced Product Labels for WooCommerce WordPress plugin before 1.2.3.7 does not sanitise and escape the tax_color_set_type parameter before outputting it back in the berocket_apl_color_listener AJAX action's respons...Show more
The Advanced Product Labels for WooCommerce WordPress plugin before 1.2.3.7 does not sanitise and escape the tax_color_set_type parameter before outputting it back in the berocket_apl_color_listener AJAX action's response, leading to a Reflected Cross-Site ScriptingShow less