← Back
CWE-79

47,455 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (47,455)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Webbigt
1Cybersoldier
Jun 17, 2026
Mar 14, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The Cybersoldier WordPress plugin before 1.7.0 does not sanitise and escape the URL settings before outputting it in an attribute, which could allow high privilege users to perform Cross-Site Scripting attacks even when...Show more
The Cybersoldier WordPress plugin before 1.7.0 does not sanitise and escape the URL settings before outputting it in an attribute, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowedShow less
1Showdoc
1Showdoc
Jun 17, 2026
Mar 14, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Stored XSS viva cshtm file upload in GitHub repository star7th/showdoc prior to v2.10.4.
1Smartertools
1Smartertrack
Jun 17, 2026
Mar 14, 2022
N/A· v4
6.1 MEDIUM· v3
3.5 LOW· v2
Stored XSS in SmarterTools SmarterTrack This issue affects: SmarterTools SmarterTrack 100.0.8019.14010.
1Smartertools
1Smartertrack
Jun 17, 2026
Mar 14, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site Scripting (XSS) vulnerability in SmarterTools SmarterTrack This issue affects: SmarterTools SmarterTrack 100.0.8019.14010.
1Showdoc
1Showdoc
Jun 17, 2026
Mar 14, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Stored XSS due to Unrestricted File Upload in GitHub repository star7th/showdoc prior to v2.10.4.
1Showdoc
1Showdoc
Jun 17, 2026
Mar 14, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Stored XSS due to Unrestricted File Upload in GitHub repository star7th/showdoc prior to v2.10.4.
1Showdoc
1Showdoc
Jun 17, 2026
Mar 14, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Stored XSS via file upload in GitHub repository star7th/showdoc prior to v2.10.4.
1B3log
1Vditor
Jun 17, 2026
Mar 14, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-site Scripting (XSS) - Stored in GitHub repository vanessa219/vditor prior to 3.8.12.
1Showdoc
1Showdoc
Jun 17, 2026
Mar 14, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Stored xss in showdoc through file upload in GitHub repository star7th/showdoc prior to 2.10.4.
1Phpliteadmin
1Phpliteadmin
Jun 17, 2026
Mar 13, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
phpLiteAdmin through 1.9.8.2 allows XSS via the index.php newRows parameter (aka num or number).
1Ponton
1X/p Messenger
Jun 17, 2026
Mar 13, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
An issue was discovered in PONTON X/P Messenger before 3.11.2. Several functions are vulnerable to reflected XSS, as demonstrated by private/index.jsp?partners/ShowNonLocalPartners.do?localID= or private/index.jsp or pri...Show more
An issue was discovered in PONTON X/P Messenger before 3.11.2. Several functions are vulnerable to reflected XSS, as demonstrated by private/index.jsp?partners/ShowNonLocalPartners.do?localID= or private/index.jsp or private/index.jsp?database/databaseTab.jsp or private/index.jsp?activation/activationMainTab.jsp or private/index.jsp?communication/serverTab.jsp or private/index.jsp?emailNotification/notificationTab.jsp.Show less
1Ponton
1X/p Messenger
Jun 17, 2026
Mar 13, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
An issue was discovered in PONTON X/P Messenger before 3.11.2. The navigation tree that is shown on the left side of every page of the web application is vulnerable to XSS: it allows injection of JavaScript into its node...Show more
An issue was discovered in PONTON X/P Messenger before 3.11.2. The navigation tree that is shown on the left side of every page of the web application is vulnerable to XSS: it allows injection of JavaScript into its nodes. Creating such nodes is only possible for users who have the role Configuration Administrator or Administrator.Show less
1Microweber
1Microweber
Jun 17, 2026
Mar 12, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
File upload filter bypass leading to stored XSS in GitHub repository microweber/microweber prior to 1.2.12.
1Microweber
1Microweber
Jun 17, 2026
Mar 12, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
XSS on dynamic_text module in GitHub repository microweber/microweber prior to 1.2.11.
1Microweber
1Microweber
Jun 17, 2026
Mar 12, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
File upload filter bypass leading to stored XSS in GitHub repository microweber/microweber prior to 1.2.12.
1Showdoc
1Showdoc
Jun 17, 2026
Mar 12, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-site Scripting (XSS) - Stored in GitHub repository star7th/showdoc prior to 2.10.2.
2Alist Project
Alistgo
2Alist
Alist
Jun 17, 2026
Mar 12, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Alist v2.1.0 and below was discovered to contain a cross-site scripting (XSS) vulnerability via /i/:data/ipa.plist.
1Alibaba
1Nacos
Jun 17, 2026
Mar 11, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A Cross Site Scripting (XSS) vulnerability exists in Nacos 2.0.3 in auth/users via the (1) pageSize and (2) pageNo parameters.
2Fedoraproject
Plugin Planet
2Contact Form X
Fedora
Jun 17, 2026
Mar 11, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Reflected Cross-Site Scripting (XSS) vulnerability affecting parameter &tab discovered in Contact Form X WordPress plugin (versions <= 2.4).
1Moodle
1Moodle
Jun 17, 2026
Mar 11, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The redirect URI in the LTI authorization endpoint required extra sanitizing to prevent reflected XSS and open redirect risks. Moodle versions 3.10 to 3.10.3, 3.9 to 3.9.6, 3.8 to 3.8.8 and earlier unsupported versions a...Show more
The redirect URI in the LTI authorization endpoint required extra sanitizing to prevent reflected XSS and open redirect risks. Moodle versions 3.10 to 3.10.3, 3.9 to 3.9.6, 3.8 to 3.8.8 and earlier unsupported versions are affected.Show less