← Back
CWE-79

47,521 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (47,521)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Appleple
1A Blog Cms
Jun 17, 2026
Feb 24, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting vulnerability in a-blog cms Ver.2.8.x series versions prior to Ver.2.8.75, Ver.2.9.x series versions prior to Ver.2.9.40, Ver.2.10.x series versions prior to Ver.2.10.44, Ver.2.11.x series versions p...Show more
Cross-site scripting vulnerability in a-blog cms Ver.2.8.x series versions prior to Ver.2.8.75, Ver.2.9.x series versions prior to Ver.2.9.40, Ver.2.10.x series versions prior to Ver.2.10.44, Ver.2.11.x series versions prior to Ver.2.11.42, and Ver.3.0.x series versions prior to Ver.3.0.1 allows a remote authenticated attacker to inject an arbitrary script via unspecified vectors. This vulnerability is different from CVE-2022-23916.Show less
1Appleple
1A Blog Cms
Jun 17, 2026
Feb 24, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting vulnerability in a-blog cms Ver.2.8.x series versions prior to Ver.2.8.75, Ver.2.9.x series versions prior to Ver.2.9.40, Ver.2.10.x series versions prior to Ver.2.10.44, Ver.2.11.x series versions p...Show more
Cross-site scripting vulnerability in a-blog cms Ver.2.8.x series versions prior to Ver.2.8.75, Ver.2.9.x series versions prior to Ver.2.9.40, Ver.2.10.x series versions prior to Ver.2.10.44, Ver.2.11.x series versions prior to Ver.2.11.42, and Ver.3.0.x series versions prior to Ver.3.0.1 allows a remote authenticated attacker to inject an arbitrary script via unspecified vectors. This vulnerability is different from CVE-2022-24374.Show less
1Bloofox
1Bloofoxcms
Jun 17, 2026
Feb 24, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Multiple Cross Site Scripting (XSS) vulnerabilities exists in bloofoxCMS 0.5.2.1 - 0.5.1 via the (1) file parameter and (2) type parameter in an edit action in index.php.
1Thedaylightstudio
1Fuel Cms
Jun 17, 2026
Feb 24, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A Cross Site Scripting (XSS) vulnerability exists in FUEL-CMS 1.5.1 in the Assets page via an SVG file.
1Rosariosis
1Rosariosis
Jun 17, 2026
Feb 24, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A Cross Site Scripting (XSS) vulnerability exists in RosarioSIS before 4.3 via the SanitizeMarkDown function in ProgramFunctions/MarkDownHTML.fnc.php.
1Rosariosis
1Rosariosis
Jun 17, 2026
Feb 24, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A Cross Site Scripting (XSS) vulnerability exists in RosarioSIS before 7.6.1 via the xss_clean function in classes/Security.php, which allows remote malicious users to inject arbitrary JavaScript or HTML. An example of a...Show more
A Cross Site Scripting (XSS) vulnerability exists in RosarioSIS before 7.6.1 via the xss_clean function in classes/Security.php, which allows remote malicious users to inject arbitrary JavaScript or HTML. An example of affected components are all Markdown input fields.Show less
1Intelliants
1Subrion Cms
Jun 17, 2026
Feb 24, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
A Cross Site Scripting (XSS) vulnerability exits in Subrion CMS through 4.2.1 in the Create Page functionality of the admin Account via a SGV file.
1Atlassian
1Jira Service Management
Jun 17, 2026
Feb 24, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Affected versions of Atlassian Jira Service Management Server and Data Center allow attackers with administrator privileges to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability in the "Ob...Show more
Affected versions of Atlassian Jira Service Management Server and Data Center allow attackers with administrator privileges to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability in the "Object Schema" field of /secure/admin/InsightDefaultCustomFieldConfig.jspa. The affected versions are before version 4.21.0.Show less
1Fortinet
2Fortios
Fortiproxy
Jun 17, 2026
Feb 24, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Failure to sanitize input in the SSL VPN web portal of FortiOS 5.2.10 through 5.2.15, 5.4.0 through 5.4.13, 5.6.0 through 5.6.14, 6.0.0 through 6.0.12, 6.2.0 through 6.2.7, 6.4.0 through 6.4.4; and FortiProxy 1.2.0 throu...Show more
Failure to sanitize input in the SSL VPN web portal of FortiOS 5.2.10 through 5.2.15, 5.4.0 through 5.4.13, 5.6.0 through 5.6.14, 6.0.0 through 6.0.12, 6.2.0 through 6.2.7, 6.4.0 through 6.4.4; and FortiProxy 1.2.0 through 1.2.9, 2.0.0 through 2.0.1 may allow a remote unauthenticated attacker to perform a reflected Cross-site Scripting (XSS) attack by sending a request to the error page with malicious GET parameters.Show less
1Microweber
1Microweber
Jun 17, 2026
Feb 23, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-site Scripting (XSS) - Reflected in GitHub repository microweber/microweber prior to 1.3.
1Checkmk
1Checkmk
Jun 17, 2026
Feb 21, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Checkmk <=2.0.0p19 contains a Cross Site Scripting (XSS) vulnerability. While creating or editing a user attribute, the Help Text is subject to HTML injection, which can be triggered for editing a user.
1Ays Pro
1Survey Maker
Jun 17, 2026
Feb 21, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability discovered in Survey Maker WordPress plugin (versions <= 2.0.6).
2Ad Inserter Pro Project
Ad Inserter Project
2Ad Inserter
Ad Inserter Pro
Jun 17, 2026
Feb 21, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Ad Inserter WordPress plugin before 2.7.10, Ad Inserter Pro WordPress plugin before 2.7.10 do not sanitise and escape the html_element_selection parameter before outputting it back in the page, leading to a Reflected...Show more
The Ad Inserter WordPress plugin before 2.7.10, Ad Inserter Pro WordPress plugin before 2.7.10 do not sanitise and escape the html_element_selection parameter before outputting it back in the page, leading to a Reflected Cross-Site ScriptingShow less
1Givewp
1Givewp
Jun 17, 2026
Feb 21, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The GiveWP WordPress plugin before 2.17.3 does not escape the json parameter before outputting it back in an attribute in the Import admin dashboard, leading to a Reflected Cross-Site Scripting
1Pluginus
1Woocs
Jun 17, 2026
Feb 21, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The WOOCS WordPress plugin before 1.3.7.5 does not sanitise and escape the woocs_in_order_currency parameter of the woocs_get_products_price_html AJAX action (available to both unauthenticated and authenticated users) be...Show more
The WOOCS WordPress plugin before 1.3.7.5 does not sanitise and escape the woocs_in_order_currency parameter of the woocs_get_products_price_html AJAX action (available to both unauthenticated and authenticated users) before outputting it back in the response, leading to a Reflected Cross-Site ScriptingShow less
1Getshieldsecurity
1Shield Security
Jun 17, 2026
Feb 21, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The Shield Security WordPress plugin before 13.0.6 does not sanitise and escape admin notes, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed.
1Machothemes
1Image Photo Gallery Final Tiles Grid
Jun 17, 2026
Feb 21, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The Image Photo Gallery Final Tiles Grid WordPress plugin before 3.5.3 does not sanitise and escape the Description field when editing a gallery, allowing users with a role as low as contributor to perform Cross-Site Scr...Show more
The Image Photo Gallery Final Tiles Grid WordPress plugin before 3.5.3 does not sanitise and escape the Description field when editing a gallery, allowing users with a role as low as contributor to perform Cross-Site Scripting attacks against other users having access to the gallery dashboardShow less
1Anti Malware Security And Brute Force Firewall Project
1Anti Malware Security And Brute Force Firewall
Jun 17, 2026
Feb 21, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The Anti-Malware Security and Brute-Force Firewall WordPress plugin before 4.20.94 does not sanitise and escape the POST data before outputting it back in attributes of an admin page, leading to a Reflected Cross-Site sc...Show more
The Anti-Malware Security and Brute-Force Firewall WordPress plugin before 4.20.94 does not sanitise and escape the POST data before outputting it back in attributes of an admin page, leading to a Reflected Cross-Site scripting. Due to the presence of specific parameter value, available to admin users, this can only be exploited by an admin against another admin user.Show less
1Givewp
1Givewp
Jun 17, 2026
Feb 21, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The GiveWP WordPress plugin before 2.17.3 does not escape the s parameter before outputting it back in an attribute in the Donation Forms dashboard, leading to a Reflected Cross-Site Scripting
1Givewp
1Givewp
Jun 17, 2026
Feb 21, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The GiveWP WordPress plugin before 2.17.3 does not sanitise and escape the form_id parameter before outputting it back in the response of an unauthenticated request via the give_checkout_login AJAX action, leading to a R...Show more
The GiveWP WordPress plugin before 2.17.3 does not sanitise and escape the form_id parameter before outputting it back in the response of an unauthenticated request via the give_checkout_login AJAX action, leading to a Reflected Cross-Site ScriptingShow less