← Back
CWE-79

47,472 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (47,472)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Accesspressthemes
1Ap Custom Testimonial
Jun 17, 2026
Feb 28, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Testimonial WordPress Plugin WordPress plugin before 1.4.7 does not sanitise and escape the id parameter before outputting it back in an attribute, leading to a Reflected cross-Site Scripting
1Crazy Bone Project
1Crazy Bone
Jun 17, 2026
Feb 28, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Crazy Bone WordPress plugin through 0.6.0 does not sanitise and escape the username submitted via the login from when displaying them back in the log dashboard, leading to an unauthenticated Stored Cross-Site scripti...Show more
The Crazy Bone WordPress plugin through 0.6.0 does not sanitise and escape the username submitted via the login from when displaying them back in the log dashboard, leading to an unauthenticated Stored Cross-Site scriptingShow less
1Smackcoders
1Import All Pages, Post Types, Products, Orders, And Users As Xml & Csv
Jun 17, 2026
Feb 28, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The Easy Drag And drop All Import : WP Ultimate CSV Importer WordPress plugin before 6.4.3 does not sanitise and escaped imported comments, which could allow high privilege users to import malicious ones (either intentio...Show more
The Easy Drag And drop All Import : WP Ultimate CSV Importer WordPress plugin before 6.4.3 does not sanitise and escaped imported comments, which could allow high privilege users to import malicious ones (either intentionnaly or not) and lead to Stored Cross-Site Scripting issuesShow less
1Wprssaggregator
1Wp Rss Aggregator
Jun 17, 2026
Feb 28, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The WP RSS Aggregator WordPress plugin before 4.20 does not sanitise and escape the id parameter in the wprss_fetch_items_row_action AJAX action before outputting it back in the response, leading to a Reflected Cross-Sit...Show more
The WP RSS Aggregator WordPress plugin before 4.20 does not sanitise and escape the id parameter in the wprss_fetch_items_row_action AJAX action before outputting it back in the response, leading to a Reflected Cross-Site ScriptingShow less
1Wp Accessibility Helper Project
1Wp Accessibility Helper
Jun 17, 2026
Feb 28, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The WP Accessibility Helper (WAH) WordPress plugin before 0.6.0.7 does not sanitise and escape the wahi parameter before outputting back its base64 decode value in the page, leading to a Reflected Cross-Site Scripting is...Show more
The WP Accessibility Helper (WAH) WordPress plugin before 0.6.0.7 does not sanitise and escape the wahi parameter before outputting back its base64 decode value in the page, leading to a Reflected Cross-Site Scripting issueShow less
1Maxfoundry
1Wp Paginate
Jun 17, 2026
Feb 28, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The WP-Paginate WordPress plugin before 2.1.4 does not sanitise and escape its preset settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html is disallo...Show more
The WP-Paginate WordPress plugin before 2.1.4 does not sanitise and escape its preset settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowedShow less
1I Plugins
1Whmcs Bridge
Jun 17, 2026
Feb 28, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The WHMCS Bridge WordPress plugin before 6.4b does not sanitise and escape the error parameter before outputting it back in admin dashboard, leading to a Reflected Cross-Site Scripting
1Wp User Project
1Wp User
Jun 17, 2026
Feb 28, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The WP User WordPress plugin before 7.0 does not sanitise and escape some parameters in pages where the [wp_user] shortcode is used, leading to Reflected Cross-Site Scripting issues
1Wpvivid
1Migration, Backup, Staging
Jun 17, 2026
Feb 28, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Migration, Backup, Staging WordPress plugin before 0.9.69 does not have authorisation when adding remote storages, and does not sanitise as well as escape a parameter from such unauthenticated requests before outputt...Show more
The Migration, Backup, Staging WordPress plugin before 0.9.69 does not have authorisation when adding remote storages, and does not sanitise as well as escape a parameter from such unauthenticated requests before outputting it in admin page, leading to a Stored Cross-Site Scripting issueShow less
1Magnigenie
1Wp Responsive Menu
Jun 17, 2026
Feb 28, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The WP Responsive Menu WordPress plugin before 3.1.7.1 does not have capability and CSRF checks in the wpr_live_update AJAX action, as well as do not sanitise and escape some of the data submitted. As a result, any authe...Show more
The WP Responsive Menu WordPress plugin before 3.1.7.1 does not have capability and CSRF checks in the wpr_live_update AJAX action, as well as do not sanitise and escape some of the data submitted. As a result, any authenticated, such as subscriber could update the plugin's settings and perform Cross-Site Scripting attacks against all visitor and users on the frontendShow less
1Bootstrapped
1Dynamic Widgets
Jun 17, 2026
Feb 28, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The Dynamic Widgets WordPress plugin through 1.5.16 does not escape the prefix parameter before outputting it back in an attribute when using the term_tree AJAX action (available to any authenticated users), leading to a...Show more
The Dynamic Widgets WordPress plugin through 1.5.16 does not escape the prefix parameter before outputting it back in an attribute when using the term_tree AJAX action (available to any authenticated users), leading to a Reflected Cross-Site Scripting issueShow less
1Statcounter
1Statcounter
Jun 17, 2026
Feb 28, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The StatCounter WordPress plugin before 2.0.7 does not sanitise and escape the Project ID and Secure Code settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_...Show more
The StatCounter WordPress plugin before 2.0.7 does not sanitise and escape the Project ID and Secure Code settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowedShow less
1Codeasily
1Grand Flagallery
Jun 17, 2026
Feb 28, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The GRAND FlaGallery WordPress plugin through 6.1.2 does not sanitise and escape some of its gallery settings, which could allow high privilege users to perform Cross-Site scripting attacks even when the unfiltered_html...Show more
The GRAND FlaGallery WordPress plugin through 6.1.2 does not sanitise and escape some of its gallery settings, which could allow high privilege users to perform Cross-Site scripting attacks even when the unfiltered_html capability is disallowed.Show less
1Securemoz
1Security Audit
Jun 17, 2026
Feb 28, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The Security Audit WordPress plugin through 1.0.0 does not sanitise and escape the Data Id setting, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability...Show more
The Security Audit WordPress plugin through 1.0.0 does not sanitise and escape the Data Id setting, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.Show less
1Editable Table Project
1Editable Table
Jun 17, 2026
Feb 28, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The EditableTable WordPress plugin through 0.1.4 does not sanitise and escape any of the Table and Column fields, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_ht...Show more
The EditableTable WordPress plugin through 0.1.4 does not sanitise and escape any of the Table and Column fields, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowedShow less
1Codetipi
115zine
Jun 17, 2026
Feb 28, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The 15Zine WordPress theme before 3.3.0 does not sanitise and escape the cbi parameter before outputing it back in the response via the cb_s_a AJAX action, leading to a Reflected Cross-Site Scripting
1Atlassian
2Data Center
Jira
Jun 17, 2026
Feb 28, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Affected versions of Atlassian Jira Server and Data Center allow remote attackers with Roadmaps Administrator permissions to inject arbitrary HTML or JavaScript via a Stored Cross-Site Scripting (SXSS) vulnerability in t...Show more
Affected versions of Atlassian Jira Server and Data Center allow remote attackers with Roadmaps Administrator permissions to inject arbitrary HTML or JavaScript via a Stored Cross-Site Scripting (SXSS) vulnerability in the /rest/jpo/1.0/hierarchyConfiguration endpoint. The affected versions are before version 8.20.3.Show less
1Librenms
1Librenms
Jun 17, 2026
Feb 27, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Cross-site Scripting (XSS) - Stored in GitHub repository librenms/librenms prior to 22.2.2.
1Tricentis
1Qtest
Jun 17, 2026
Feb 26, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Tricentis qTest before 10.4 allows stored XSS by an authenticated attacker.
1Microweber
1Microweber
Jun 17, 2026
Feb 26, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-site Scripting (XSS) - Reflected in GitHub repository microweber/microweber prior to 1.2.11.