CWE-79
47,455 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (47,455)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The Cybersoldier WordPress plugin before 1.7.0 does not sanitise and escape the URL settings before outputting it in an attribute, which could allow high privilege users to perform Cross-Site Scripting attacks even when...Show more |
Stored XSS viva cshtm file upload in GitHub repository star7th/showdoc prior to v2.10.4. |
Stored XSS in SmarterTools SmarterTrack This issue affects: SmarterTools SmarterTrack 100.0.8019.14010. |
Cross-site Scripting (XSS) vulnerability in SmarterTools SmarterTrack This issue affects: SmarterTools SmarterTrack 100.0.8019.14010. |
Stored XSS due to Unrestricted File Upload in GitHub repository star7th/showdoc prior to v2.10.4. |
Stored XSS due to Unrestricted File Upload in GitHub repository star7th/showdoc prior to v2.10.4. |
Stored XSS via file upload in GitHub repository star7th/showdoc prior to v2.10.4. |
Cross-site Scripting (XSS) - Stored in GitHub repository vanessa219/vditor prior to 3.8.12. |
Stored xss in showdoc through file upload in GitHub repository star7th/showdoc prior to 2.10.4. |
phpLiteAdmin through 1.9.8.2 allows XSS via the index.php newRows parameter (aka num or number). |
An issue was discovered in PONTON X/P Messenger before 3.11.2. Several functions are vulnerable to reflected XSS, as demonstrated by private/index.jsp?partners/ShowNonLocalPartners.do?localID= or private/index.jsp or pri...Show more |
An issue was discovered in PONTON X/P Messenger before 3.11.2. The navigation tree that is shown on the left side of every page of the web application is vulnerable to XSS: it allows injection of JavaScript into its node...Show more |
File upload filter bypass leading to stored XSS in GitHub repository microweber/microweber prior to 1.2.12. |
XSS on dynamic_text module in GitHub repository microweber/microweber prior to 1.2.11. |
File upload filter bypass leading to stored XSS in GitHub repository microweber/microweber prior to 1.2.12. |
Cross-site Scripting (XSS) - Stored in GitHub repository star7th/showdoc prior to 2.10.2. |
2Alist Project Alistgo2Alist AlistJun 17, 2026 Mar 12, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Alist v2.1.0 and below was discovered to contain a cross-site scripting (XSS) vulnerability via /i/:data/ipa.plist. |
A Cross Site Scripting (XSS) vulnerability exists in Nacos 2.0.3 in auth/users via the (1) pageSize and (2) pageNo parameters. |
2Fedoraproject Plugin Planet2Contact Form X FedoraJun 17, 2026 Mar 11, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Reflected Cross-Site Scripting (XSS) vulnerability affecting parameter &tab discovered in Contact Form X WordPress plugin (versions <= 2.4). |
The redirect URI in the LTI authorization endpoint required extra sanitizing to prevent reflected XSS and open redirect risks. Moodle versions 3.10 to 3.10.3, 3.9 to 3.9.6, 3.8 to 3.8.8 and earlier unsupported versions a...Show more |