CWE-79
47,472 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (47,472)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Accesspressthemes 1Ap Custom Testimonial Jun 17, 2026 Feb 28, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The Testimonial WordPress Plugin WordPress plugin before 1.4.7 does not sanitise and escape the id parameter before outputting it back in an attribute, leading to a Reflected cross-Site Scripting |
1Crazy Bone Project 1Crazy Bone Jun 17, 2026 Feb 28, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The Crazy Bone WordPress plugin through 0.6.0 does not sanitise and escape the username submitted via the login from when displaying them back in the log dashboard, leading to an unauthenticated Stored Cross-Site scripti...Show more |
1Smackcoders 1Import All Pages, Post Types, Products, Orders, And Users As Xml & Csv Jun 17, 2026 Feb 28, 2022 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 The Easy Drag And drop All Import : WP Ultimate CSV Importer WordPress plugin before 6.4.3 does not sanitise and escaped imported comments, which could allow high privilege users to import malicious ones (either intentio...Show more |
1Wprssaggregator 1Wp Rss Aggregator Jun 17, 2026 Feb 28, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The WP RSS Aggregator WordPress plugin before 4.20 does not sanitise and escape the id parameter in the wprss_fetch_items_row_action AJAX action before outputting it back in the response, leading to a Reflected Cross-Sit...Show more |
1Wp Accessibility Helper Project 1Wp Accessibility Helper Jun 17, 2026 Feb 28, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The WP Accessibility Helper (WAH) WordPress plugin before 0.6.0.7 does not sanitise and escape the wahi parameter before outputting back its base64 decode value in the page, leading to a Reflected Cross-Site Scripting is...Show more |
The WP-Paginate WordPress plugin before 2.1.4 does not sanitise and escape its preset settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html is disallo...Show more |
The WHMCS Bridge WordPress plugin before 6.4b does not sanitise and escape the error parameter before outputting it back in admin dashboard, leading to a Reflected Cross-Site Scripting |
The WP User WordPress plugin before 7.0 does not sanitise and escape some parameters in pages where the [wp_user] shortcode is used, leading to Reflected Cross-Site Scripting issues |
1Wpvivid 1Migration, Backup, Staging Jun 17, 2026 Feb 28, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The Migration, Backup, Staging WordPress plugin before 0.9.69 does not have authorisation when adding remote storages, and does not sanitise as well as escape a parameter from such unauthenticated requests before outputt...Show more |
1Magnigenie 1Wp Responsive Menu Jun 17, 2026 Feb 28, 2022 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 The WP Responsive Menu WordPress plugin before 3.1.7.1 does not have capability and CSRF checks in the wpr_live_update AJAX action, as well as do not sanitise and escape some of the data submitted. As a result, any authe...Show more |
The Dynamic Widgets WordPress plugin through 1.5.16 does not escape the prefix parameter before outputting it back in an attribute when using the term_tree AJAX action (available to any authenticated users), leading to a...Show more |
The StatCounter WordPress plugin before 2.0.7 does not sanitise and escape the Project ID and Secure Code settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_...Show more |
The GRAND FlaGallery WordPress plugin through 6.1.2 does not sanitise and escape some of its gallery settings, which could allow high privilege users to perform Cross-Site scripting attacks even when the unfiltered_html...Show more |
The Security Audit WordPress plugin through 1.0.0 does not sanitise and escape the Data Id setting, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability...Show more |
1Editable Table Project 1Editable Table Jun 17, 2026 Feb 28, 2022 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 The EditableTable WordPress plugin through 0.1.4 does not sanitise and escape any of the Table and Column fields, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_ht...Show more |
The 15Zine WordPress theme before 3.3.0 does not sanitise and escape the cbi parameter before outputing it back in the response via the cb_s_a AJAX action, leading to a Reflected Cross-Site Scripting |
Affected versions of Atlassian Jira Server and Data Center allow remote attackers with Roadmaps Administrator permissions to inject arbitrary HTML or JavaScript via a Stored Cross-Site Scripting (SXSS) vulnerability in t...Show more |
Cross-site Scripting (XSS) - Stored in GitHub repository librenms/librenms prior to 22.2.2. |
Tricentis qTest before 10.4 allows stored XSS by an authenticated attacker. |
Cross-site Scripting (XSS) - Reflected in GitHub repository microweber/microweber prior to 1.2.11. |