CWE-79
47,455 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (47,455)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1I13websolution 1Team Circle Image Slider With Lightbox Jun 17, 2026 Mar 14, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The Team Circle Image Slider With Lightbox WordPress plugin before 1.0.16 does not sanitize and escape the order_pos parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting. |
1Edmonsoft 1Countdown, Coming Soon, Maintenance Countdown & Clock Jun 17, 2026 Mar 14, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The Countdown, Coming Soon, Maintenance WordPress plugin before 2.2.9 does not sanitize and escape the post parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting. |
1Obtaininfotech 1Multisite Content Copier/updater Jun 17, 2026 Mar 14, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The WordPress Multisite Content Copier/Updater WordPress plugin before 2.1.2 does not sanitise and escape the s parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting issue in th...Show more |
The Flexi WordPress plugin before 4.20 does not sanitise and escape various parameters before outputting them back in some pages such as the user dashboard, leading to a Reflected Cross-Site Scripting |
1Berocket 1Advanced Product Labels For Woocommerce Jun 17, 2026 Mar 14, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The Advanced Product Labels for WooCommerce WordPress plugin before 1.2.3.7 does not sanitise and escape the tax_color_set_type parameter before outputting it back in the berocket_apl_color_listener AJAX action's respons...Show more |
1Jeweltheme 1Master Addons For Elementor Jun 17, 2026 Mar 14, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The Master Addons for Elementor WordPress plugin before 1.8.5 does not sanitise and escape the error_message parameter before outputting it back in the response of the jltma_restrict_content AJAX action, available to una...Show more |
1Ohiowebtech 1Wp Voting Contest Jun 17, 2026 Mar 14, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The WP Voting Contest WordPress plugin before 3.0 does not sanitise and escape the post_id parameter before outputting it back in the response via the wpvc_social_share_icons AJAX action (available to both unauthenticate...Show more |
1Contact Form Submissions Project 1Contact Form Submissions Jun 17, 2026 Mar 14, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The Contact Form Submissions WordPress plugin before 1.7.3 does not sanitise and escape additional fields in contact form requests before outputting them in the related submission. As a result, unauthenticated attacker c...Show more |
1Bwp Google Xml Sitemaps Project 1Bwp Google Xml Sitemaps Jun 17, 2026 Mar 14, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The Better WordPress Google XML Sitemaps WordPress plugin through 1.4.1 does not sanitise and escape its logs when outputting them in the admin dashboard, which could allow unauthenticated users to perform Stored Cross-S...Show more |
1Ari Soft 1Ari Fancy Lightbox Jun 17, 2026 Mar 14, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The ARI Fancy Lightbox WordPress plugin before 1.3.9 does not sanitise and escape the msg parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting |
1Cookieinformation 1Wp Gdpr Compliance Jun 17, 2026 Mar 14, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The Cookie Information | Free GDPR Consent Solution WordPress plugin before 2.0.8 does not escape user data before outputting it back in attributes in the admin dashboard, leading to a Reflected Cross-Site Scripting issu...Show more |
Zenario CMS 9.0.54156 is vulnerable to Cross Site Scripting (XSS) via upload file to *.SVG. An attacker can send malicious files to victims and steals victim's cookie leads to account takeover. The person viewing the ima...Show more |
The Patreon WordPress plugin before 1.8.2 does not sanitise and escape the field "Custom Patreon Page name", which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html ca...Show more |
1Molie Instructure Canvas Linking Tool Project 1Molie Instructure Canvas Linking Tool Jun 17, 2026 Mar 14, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The MOLIE WordPress plugin through 0.5 does not escape the course_id parameter before outputting it back in the admin dashboard, leading to a Reflected Cross-Site Scripting issue |
1Wki 1Idpay For Contact Form 7 Jun 17, 2026 Mar 14, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The IDPay for Contact Form 7 WordPress plugin through 2.1.2 does not sanitise and escape the idpay_error parameter before outputting it back in the page leading to a Reflected Cross-Site Scripting |
1Html5 Responsive Faq Project 1Html5 Responsive Faq Jun 17, 2026 Mar 14, 2022 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 The HTML5 Responsive FAQ WordPress plugin through 2.8.5 does not properly sanitise and escape some of its settings, which could allow a high privilege users to perform Cross-Site Scripting attacks even when the unfiltere...Show more |
1Childtheme Generator 1Child Theme Generator Jun 17, 2026 Mar 14, 2022 N/A· v4 6.4 MEDIUM· v3 3.5 LOW· v2 The Child Theme Generator WordPress plugin through 2.2.7 does not sanitise escape the parade parameter before outputting it back, leading to a Reflected Cross-Site Scripting in the admin dashboard |
1Mekshq 1Meks Easy Photo Feed Widget Jun 17, 2026 Mar 14, 2022 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 The Meks Easy Photo Feed Widget WordPress plugin before 1.2.4 does not have capability and CSRF checks in the meks_save_business_selected_account AJAX action, available to any authenticated user, and does not escape some...Show more |
1Woocommerce 1Persian Woocommerce Jun 17, 2026 Mar 14, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The Persian Woocommerce WordPress plugin through 5.8.0 does not escape the s parameter before outputting it back in an attribute in the admin dashboard, which could lead to a Reflected Cross-Site Scripting issue |
The Add Subtitle WordPress plugin through 1.1.0 does not sanitise or escape the sub-title field (available only with classic editor) when output in the page, which could allow users with a role as low as contributor to p...Show more |