← Back
CWE-79

47,455 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (47,455)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Codepeople
1Wp Time Slots Booking Form
Jun 17, 2026
Mar 7, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The WP Time Slots Booking Form WordPress plugin before 1.1.63 does not sanitise and escape Calendar names, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is...Show more
The WP Time Slots Booking Form WordPress plugin before 1.1.63 does not sanitise and escape Calendar names, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.Show less
1Wpbrigade
1Loginpress
Jun 17, 2026
Mar 7, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The LoginPress | Custom Login Page Customizer WordPress plugin before 1.5.12 does not escape the redirect-page parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting
1Yop Poll
1Yop Poll
Jun 17, 2026
Mar 7, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The YOP Poll WordPress plugin before 6.3.5 does not sanitise and escape some of the settings (available to users with a role as low as author) before outputting them, leading to a Stored Cross-Site Scripting issue
1Obtaininfotech
1Multisite Content Copier/updater
Jun 17, 2026
Mar 7, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The WordPress Multisite Content Copier/Updater WordPress plugin before 2.1.0 does not sanitise and escape the wmcc_content_type, wmcc_source_blog and wmcc_record_per_page parameters before outputting them back in attribu...Show more
The WordPress Multisite Content Copier/Updater WordPress plugin before 2.1.0 does not sanitise and escape the wmcc_content_type, wmcc_source_blog and wmcc_record_per_page parameters before outputting them back in attributes, leading to Reflected Cross-Site Scripting issuesShow less
1Obtaininfotech
1Multisite User Sync/unsync
Jun 17, 2026
Mar 7, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The WordPress Multisite User Sync/Unsync WordPress plugin before 2.1.2 does not sanitise and escape the wmus_source_blog and wmus_record_per_page parameters before outputting them back in attributes, leading to Reflected...Show more
The WordPress Multisite User Sync/Unsync WordPress plugin before 2.1.2 does not sanitise and escape the wmus_source_blog and wmus_record_per_page parameters before outputting them back in attributes, leading to Reflected Cross-Site Scripting issuesShow less
1Iptanus
2Wordpress File Upload
Wordpress File Upload Pro
Jun 17, 2026
Mar 7, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The WordPress File Upload WordPress plugin before 4.16.3, wordpress-file-upload-pro WordPress plugin before 4.16.3 does not escape some of its shortcode argument, which could allow users with a role as low as Contributor...Show more
The WordPress File Upload WordPress plugin before 4.16.3, wordpress-file-upload-pro WordPress plugin before 4.16.3 does not escape some of its shortcode argument, which could allow users with a role as low as Contributor to perform Cross-Site Scripting attacksShow less
1Tinywebgallery
1Advanced Iframe
Jun 17, 2026
Mar 7, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Advanced iFrame WordPress plugin before 2022 does not sanitise and escape the ai_config_id parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting issue
1Custom Content Shortcode Project
1Custom Content Shortcode
Jun 17, 2026
Mar 7, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The Custom Content Shortcode WordPress plugin before 4.0.2 does not escape custom fields before outputting them, which could allow Contributor+ (v < 4.0.1) or Admin+ (v < 4.0.2) users to perform Cross-Site Scripting atta...Show more
The Custom Content Shortcode WordPress plugin before 4.0.2 does not escape custom fields before outputting them, which could allow Contributor+ (v < 4.0.1) or Admin+ (v < 4.0.2) users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed. Please note that such attack is still possible by admin+ in single site blogs by default (but won't be when the unfiltered_html is disallowed)Show less
1Nicdark
1Cost Calculator
Jun 17, 2026
Mar 7, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The Cost Calculator WordPress plugin before 1.6 allows users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks via the Description fields of a Cost Calculator > Price Settings (which gets i...Show more
The Cost Calculator WordPress plugin before 1.6 allows users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks via the Description fields of a Cost Calculator > Price Settings (which gets injected on the edit page as well as any page that embeds the calculator using the shortcode), as well as the Text Preview field of a Project (injected on the edit project page)Show less
1Wp Eventmanager
1Wp Event Manager
Jun 17, 2026
Mar 7, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The WP Event Manager WordPress plugin before 3.1.23 does not escape some of its Field Editor settings when outputting them, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_h...Show more
The WP Event Manager WordPress plugin before 3.1.23 does not escape some of its Field Editor settings when outputting them, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowedShow less
1F Secure
1Safe
Jun 17, 2026
Mar 6, 2022
N/A· v4
9.6 CRITICAL· v3
4.3 MEDIUM· v2
A vulnerability affecting F-Secure SAFE browser protection was discovered improper URL handling can be triggered to cause universal cross-site scripting through browsing protection in a SAFE web browser. User interaction...Show more
A vulnerability affecting F-Secure SAFE browser protection was discovered improper URL handling can be triggered to cause universal cross-site scripting through browsing protection in a SAFE web browser. User interaction is required prior to exploitation. A successful exploitation may lead to arbitrary code execution.Show less
1F Secure
1Safe
Jun 17, 2026
Mar 6, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A vulnerability affecting F-Secure SAFE browser was discovered whereby browsers loads images automatically this vulnerability can be exploited remotely by an attacker to execute the JavaScript can be used to trigger univ...Show more
A vulnerability affecting F-Secure SAFE browser was discovered whereby browsers loads images automatically this vulnerability can be exploited remotely by an attacker to execute the JavaScript can be used to trigger universal cross-site scripting through the browser. User interaction is required prior to exploitation, such as entering a malicious website to trigger the vulnerability.Show less
1Marktext
1Marktext
Jun 17, 2026
Mar 5, 2022
N/A· v4
9.6 CRITICAL· v3
6.8 MEDIUM· v2
Mark Text v0.16.3 was discovered to contain a DOM-based cross-site scripting (XSS) vulnerability which allows attackers to perform remote code execution (RCE) via injecting a crafted payload into /lib/contentState/pasteC...Show more
Mark Text v0.16.3 was discovered to contain a DOM-based cross-site scripting (XSS) vulnerability which allows attackers to perform remote code execution (RCE) via injecting a crafted payload into /lib/contentState/pasteCtrl.js.Show less
1Veritas
1Infoscale Operations Manager
Jun 17, 2026
Mar 4, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
An issue was discovered in Veritas InfoScale Operations Manager (VIOM) before 7.4.2 Patch 600 and 8.x before 8.0.0 Patch 100. A reflected cross-site scripting (XSS) vulnerability in admin/cgi-bin/listdir.pl allows authen...Show more
An issue was discovered in Veritas InfoScale Operations Manager (VIOM) before 7.4.2 Patch 600 and 8.x before 8.0.0 Patch 100. A reflected cross-site scripting (XSS) vulnerability in admin/cgi-bin/listdir.pl allows authenticated remote administrators to inject arbitrary web script or HTML into an HTTP GET parameter (which reflect the user input without sanitization).Show less
1Netgear
1Wac120 Ac Firmware
Jun 17, 2026
Mar 4, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Unauthenticated cross-site scripting (XSS) in Netgear WAC120 AC Access Point may lead to mulitple attacks like session hijacking even clipboard hijacking.
1Cedargate
1Ez Net Portal
Jun 17, 2026
Mar 4, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Cedar Gate EZ-NET portal 6.5.5 6.8.0 Internet portal has a call to display messages to users which does not properly sanitize data sent in through a URL parameter. This leads to a Reflected Cross-Site Scripting vulne...Show more
The Cedar Gate EZ-NET portal 6.5.5 6.8.0 Internet portal has a call to display messages to users which does not properly sanitize data sent in through a URL parameter. This leads to a Reflected Cross-Site Scripting vulnerability. NOTE: the vendor disputes this because the ado.im reference has "no clear steps of reproduction."Show less
1Alfresco
1Alfresco
Jun 17, 2026
Mar 4, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross Site Scripting (XSS) vulnerability exists in Alfresco Alfresco Community Edition v5.2.0 via the action parameter in the alfresco/s/admin/admin-nodebrowser API. Fixed in v6.2
1Intelliants
1Subrion Cms
Jul 9, 2026
Mar 4, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Multilple Cross Site Scripting (XSS) vulnerability exists in Intelliants Subrion CMS v4.2.1 in the Configuration panel.
1Intelliants
1Subrion Cms
Jul 9, 2026
Mar 4, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross Site Scripting (XSS) vulnerability exists in Subrion CMS 4.2.1 via the q parameter in the Kickstart template.
1Pimcore
1Pimcore
Jun 17, 2026
Mar 4, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.3.3.