CWE-79
47,521 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (47,521)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Fivestarplugins 1Five Star Business Profile And Schema Jun 17, 2026 Feb 21, 2022 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 The Five Star Business Profile and Schema WordPress plugin before 2.1.7 does not have any authorisation and CSRF in its bpfwp_welcome_add_contact_page and bpfwp_welcome_set_contact_information AJAX action, allowing any a...Show more |
1The Buffer Button Project 1The Buffer Button Jun 17, 2026 Feb 21, 2022 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 The Buffer Button WordPress plugin through 1.0 was vulnerable to Authenticated Stored Cross Site Scripting (XSS) within the Twitter username to mention text field. |
1Translationexchange 1Translation Exchange Jun 17, 2026 Feb 21, 2022 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 The Translation Exchange WordPress plugin through 1.0.14 was vulnerable to Authenticated Stored Cross-Site Scripting (XSS) within the Project Key text field found in the plugin's settings. |
1Feedwordpress Project 1Feedwordpress Jun 17, 2026 Feb 21, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The FeedWordPress plugin before 2022.0123 is affected by a Reflected Cross-Site Scripting (XSS) within the "visibility" parameter. |
1Sigmaplugin 1Advanced Database Cleaner Jun 17, 2026 Feb 21, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The Advanced Database Cleaner WordPress plugin before 3.0.4 does not sanitise and escape $_GET keys and values before outputting them back in attributes, leading to Reflected Cross-Site Scripting issues |
Openmct versions 1.3.0 to 1.7.7 are vulnerable against stored XSS via the “Summary Widget” element, that allows the injection of malicious JavaScript into the ‘URL’ field. This issue affects: nasa openmct 1.7.7 version a...Show more |
Openmct versions 1.3.0 to 1.7.7 are vulnerable against stored XSS via the “Condition Widget” element, that allows the injection of malicious JavaScript into the ‘URL’ field. This issue affects: nasa openmct 1.7.7 version...Show more |
Openmct versions 1.3.0 to 1.7.7 are vulnerable against stored XSS via the “Web Page” element, that allows the injection of malicious JavaScript into the ‘URL’ field. This issue affects: nasa openmct 1.7.7 version and pri...Show more |
Cross-site Scripting (XSS) - Reflected in Packagist microweber/microweber prior to 1.2.11. |
WikiDocs version 0.1.18 has multiple reflected XSS vulnerabilities on different pages. |
Cross-site Scripting (XSS) - Reflected in Packagist microweber/microweber prior to 1.2.11. |
SAS Web Report Studio 4.4 allows XSS. /SASWebReportStudio/logonAndRender.do has two parameters: saspfs_request_backlabel_list and saspfs_request_backurl_list. The first one affects the content of the button placed in the...Show more |
A Stored XSS issue exists in the admin/users user administration form in LiveConfig 2.12.2. |
1Broadcom 1Layer7 Api Management Oauth Toolkit Jun 17, 2026 Feb 18, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 A reflected cross-site scripting (XSS) vulnerability in the Symantec Layer7 API Management OAuth Toolkit (OTK) allows a remote attacker to craft a malicious URL for the OTK web UI and target OTK users with phishing attac...Show more |
ZEROF Web Server 2.0 allows /admin.back XSS. |
Prism is a syntax highlighting library. Starting with version 1.14.0 and prior to version 1.27.0, Prism's command line plugin can be used by attackers to achieve a cross-site scripting attack. The command line plugin did...Show more |
Scoold 1.47.2 is a Q&A/knowledge base platform written in Java. When writing a Q&A, the markdown editor is vulnerable to a XSS attack when using uppercase letters. |
1Cerebrate Project 1Cerebrate Jun 17, 2026 Feb 18, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in Cerebrate through 1.4. XSS could occur in the bookmarks component. |
1Cerebrate Project 1Cerebrate Jun 17, 2026 Feb 18, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in Cerebrate through 1.4. genericForm allows reflected XSS in form descriptions via a user-controlled description. |
D-Link DSL-2730E CT-20131125 devices allow XSS via the username parameter to the password page in the maintenance configuration. |