← Back
CWE-79

47,546 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (47,546)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Really Simple Plugins
1Complianz
Jun 17, 2026
Feb 14, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Complianz WordPress plugin before 6.0.0 does not escape the s parameter before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Site Scripting
1Ideabox
1Powerpack For Beaver Builder
Jun 17, 2026
Feb 14, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The PowerPack Lite for Beaver Builder WordPress plugin before 1.2.9.3 does not sanitise and escape the tab parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting
2Wp Photo Album Plus Project
Wppa
2Wp Photo Album Plus
Wp Photo Album Plus
Jun 17, 2026
Feb 14, 2022
N/A· v4
6.4 MEDIUM· v3
3.5 LOW· v2
The WP Photo Album Plus WordPress plugin before 8.0.10 was vulnerable to Stored Cross-Site Scripting (XSS). Error log content was handled improperly, therefore any user, even unauthenticated, could cause arbitrary javasc...Show more
The WP Photo Album Plus WordPress plugin before 8.0.10 was vulnerable to Stored Cross-Site Scripting (XSS). Error log content was handled improperly, therefore any user, even unauthenticated, could cause arbitrary javascript to be executed in the admin panel.Show less
1Accesspressthemes
1Form Store To Db
Jun 17, 2026
Feb 14, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Form Store to DB WordPress plugin before 1.1.1 does not sanitise and escape parameter keys before outputting it back in the created entry, allowing unauthenticated attacker to perform Cross-Site Scripting attacks aga...Show more
The Form Store to DB WordPress plugin before 1.1.1 does not sanitise and escape parameter keys before outputting it back in the created entry, allowing unauthenticated attacker to perform Cross-Site Scripting attacks against adminShow less
1Wpchill
1Remove Footer Credit
Jun 17, 2026
Feb 14, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The Remove Footer Credit WordPress plugin before 1.0.11 does properly sanitise its settings, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed.
1Lenderd
1Mortgage Calculators Wp
Jun 17, 2026
Feb 14, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The Mortgage Calculators WP WordPress plugin before 1.56 does not implement any sanitisation on the color setting of the background of a calculator, which could allow high privilege users to perform Stored Cross-Site Scr...Show more
The Mortgage Calculators WP WordPress plugin before 1.56 does not implement any sanitisation on the color setting of the background of a calculator, which could allow high privilege users to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.Show less
1Brevo
1Newsletter, Smtp, Email Marketing And Subscribe
Jun 17, 2026
Feb 14, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue WordPress plugin before 3.1.31 does not escape the lang and pid parameter before outputting them back in attributes, leading to Reflected Cross-Site...Show more
The Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue WordPress plugin before 3.1.31 does not escape the lang and pid parameter before outputting them back in attributes, leading to Reflected Cross-Site Scripting issuesShow less
1Samsung
1Smarttagplugin
Jun 17, 2026
Feb 11, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Improper input validation vulnerability in SmartTagPlugin prior to version 1.2.15-6 allows privileged attackers to trigger a XSS on a victim's devices.
1Elastic
1Kibana
Jun 17, 2026
Feb 11, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
An XSS vulnerability was found in Kibana index patterns. Using this vulnerability, an authenticated user with permissions to create index patterns can inject malicious javascript into the index pattern which could execut...Show more
An XSS vulnerability was found in Kibana index patterns. Using this vulnerability, an authenticated user with permissions to create index patterns can inject malicious javascript into the index pattern which could execute against other usersShow less
1Tcman
1Gim
Jun 17, 2026
Feb 11, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The m_txtNom y m_txtCognoms parameters in TCMAN GIM v8.01 allow an attacker to perform persistent XSS attacks. This vulnerability could be used to carry out a number of browser-based attacks including browser hijacking o...Show more
The m_txtNom y m_txtCognoms parameters in TCMAN GIM v8.01 allow an attacker to perform persistent XSS attacks. This vulnerability could be used to carry out a number of browser-based attacks including browser hijacking or theft of sensitive data.Show less
1Wocu Monitoring
1Wocu Monitoring
Jun 17, 2026
Feb 11, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
A stored cross site scripting have been identified at the comments in the report creation due to an obsolote version of tinymce editor. In order to exploit this vulnerability, the attackers needs an account with enough p...Show more
A stored cross site scripting have been identified at the comments in the report creation due to an obsolote version of tinymce editor. In order to exploit this vulnerability, the attackers needs an account with enough privileges to view and edit reports.Show less
1Projeqtor
1Projeqtor
Jun 17, 2026
Feb 11, 2022
N/A· v4
9.9 CRITICAL· v3
3.5 LOW· v2
A Cross Site Scripting (XSS) vulnerability exists in Projeqtor 9.3.1 via /projeqtor/tool/saveAttachment.php, which allows an attacker to upload a SVG file containing malicious JavaScript code.
1Drupal
1Entity Embed
Jun 17, 2026
Feb 11, 2022
N/A· v4
6.1 MEDIUM· v3
2.6 LOW· v2
The Entity Embed module provides a filter to allow embedding entities in content fields. In certain circumstances, the filter could allow an unprivileged user to inject HTML into a page when it is accessed by a trusted u...Show more
The Entity Embed module provides a filter to allow embedding entities in content fields. In certain circumstances, the filter could allow an unprivileged user to inject HTML into a page when it is accessed by a trusted user with permission to embed entities. In some cases, this could lead to cross-site scripting.Show less
1Drupal
1Drupal
Jun 17, 2026
Feb 11, 2022
N/A· v4
6.1 MEDIUM· v3
2.6 LOW· v2
Cross-site Scripting (XSS) vulnerability in Drupal core's sanitization API fails to properly filter cross-site scripting under certain circumstances. This issue affects: Drupal Core 9.1.x versions prior to 9.1.7; 9.0.x v...Show more
Cross-site Scripting (XSS) vulnerability in Drupal core's sanitization API fails to properly filter cross-site scripting under certain circumstances. This issue affects: Drupal Core 9.1.x versions prior to 9.1.7; 9.0.x versions prior to 9.0.12; 8.9.x versions prior to 8.9.14; 7.x versions prior to 7.80.Show less
1Drupal
1Drupal
Jun 17, 2026
Feb 11, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site Scripting (XSS) vulnerability in ckeditor of Drupal Core allows attacker to inject XSS. This issue affects: Drupal Core 8.8.x versions prior to 8.8.10.; 8.9.x versions prior to 8.9.6; 9.0.x versions prior to 9...Show more
Cross-site Scripting (XSS) vulnerability in ckeditor of Drupal Core allows attacker to inject XSS. This issue affects: Drupal Core 8.8.x versions prior to 8.8.10.; 8.9.x versions prior to 8.9.6; 9.0.x versions prior to 9.0.6.Show less
1Drupal
1Drupal
Jun 17, 2026
Feb 11, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Access Bypass vulnerability in Drupal Core allows for an attacker to leverage the way that HTML is rendered for affected forms in order to exploit the vulnerability. This issue affects: Drupal Core 8.8.x versions prior t...Show more
Access Bypass vulnerability in Drupal Core allows for an attacker to leverage the way that HTML is rendered for affected forms in order to exploit the vulnerability. This issue affects: Drupal Core 8.8.x versions prior to 8.8.10; 8.9.x versions prior to 8.9.6; 9.0.x versions prior to 9.0.6.Show less
1Factorfx
1Ocs Inventory
Jul 9, 2026
Feb 11, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
OCS Inventory 2.9.1 is affected by Cross Site Scripting (XSS). To exploit the vulnerability, the attacker needs to manipulate the name of some device on your computer, such as a printer, replacing the device name with so...Show more
OCS Inventory 2.9.1 is affected by Cross Site Scripting (XSS). To exploit the vulnerability, the attacker needs to manipulate the name of some device on your computer, such as a printer, replacing the device name with some malicious code that allows the execution of Stored Cross-site Scripting (XSS).Show less
11234n
1Minicms
Jun 17, 2026
Feb 10, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
MiniCMS v1.11 was discovered to contain a cross-site scripting (XSS) vulnerability via /mc-admin/page-edit.php.
1Taogogo
1Taocms
Jun 17, 2026
Feb 10, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Taocms v3.0.2 was discovered to contain a cross-site scripting (XSS) vulnerability via the Management Column component.
1Xerox
1Xmpie Ustore
Jul 9, 2026
Feb 10, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
A persistent cross-site scripting (XSS) vulnerability exists on two input fields within the administrative panel when editing users in the XMPie UStore application on version 12.3.7244.0.