← Back
CWE-79

47,551 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (47,551)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Chatwoot
1Chatwoot
Jun 17, 2026
Feb 9, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site Scripting (XSS) - Stored in GitHub repository chatwoot/chatwoot prior to 2.2.0.
1Chatwoot
1Chatwoot
Jun 17, 2026
Feb 9, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site Scripting (XSS) - Stored in GitHub repository chatwoot/chatwoot prior to 2.2.0.
1Std42
1Elfinder
Jun 17, 2026
Feb 8, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Studio 42 elFinder through 2.1.31 allows XSS via an SVG document.
1Gitea
1Gitea
Jun 17, 2026
Feb 8, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross Site Scripting (XSS) vulnerability exists in Gitea before 1.5.1 via the repository settings inside the external wiki/issue tracker URL field.
3Fedoraproject
GrafanaNetapp
3E Series Performance Analyzer
FedoraGrafana
Jun 17, 2026
Feb 8, 2022
N/A· v4
5.4 MEDIUM· v3
2.1 LOW· v2
Grafana is an open-source platform for monitoring and observability. In affected versions an attacker could serve HTML content thru the Grafana datasource or plugin proxy and trick a user to visit this HTML page using a...Show more
Grafana is an open-source platform for monitoring and observability. In affected versions an attacker could serve HTML content thru the Grafana datasource or plugin proxy and trick a user to visit this HTML page using a specially crafted link and execute a Cross-site Scripting (XSS) attack. The attacker could either compromise an existing datasource for a specific Grafana instance or either set up its own public service and instruct anyone to set it up in their Grafana instance. To be impacted, all of the following must be applicable. For the data source proxy: A Grafana HTTP-based datasource configured with Server as Access Mode and a URL set, the attacker has to be in control of the HTTP server serving the URL of above datasource, and a specially crafted link pointing at the attacker controlled data source must be clicked on by an authenticated user. For the plugin proxy: A Grafana HTTP-based app plugin configured and enabled with a URL set, the attacker has to be in control of the HTTP server serving the URL of above app, and a specially crafted link pointing at the attacker controlled plugin must be clocked on by an authenticated user. For the backend plugin resource: An attacker must be able to navigate an authenticated user to a compromised plugin through a crafted link. Users are advised to update to a patched version. There are no known workarounds for this vulnerability.Show less
1Pimcore
1Pimcore
Jun 17, 2026
Feb 8, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-site Scripting (XSS) - Reflected in Packagist pimcore/pimcore prior to 10.3.1.
1Pimcore
1Pimcore
Jun 17, 2026
Feb 8, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-site Scripting (XSS) - Stored in Packagist pimcore/pimcore prior to 10.3.1.
1Dounokouno
1Transmitmail
Jun 17, 2026
Feb 8, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting vulnerability in TransmitMail 2.5.0 to 2.6.1 allows a remote unauthenticated attacker to inject an arbitrary script via unspecified vectors.
1Econosys System
1Php Mailform
Jun 17, 2026
Feb 8, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Reflected cross-site scripting vulnerability in the checkbox of php_mailform versions prior to Version 1.40 allows a remote unauthenticated attacker to inject an arbitrary script via unspecified vectors.
1Econosys System
1Php Mailform
Jun 17, 2026
Feb 8, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Reflected cross-site scripting vulnerability in the attached file name of php_mailform versions prior to Version 1.40 allows a remote unauthenticated attacker to inject an arbitrary script via unspecified vectors.
1Elecom
1Wrc 300febk R Firmware
Jun 17, 2026
Feb 8, 2022
N/A· v4
5.2 MEDIUM· v3
2.9 LOW· v2
Cross-site scripting vulnerability in ELECOM LAN router WRC-300FEBK-R firmware v1.13 and earlier allows an attacker on the adjacent network to inject an arbitrary script via unspecified vectors.
1Csv+ Project
1Csv+
Jun 17, 2026
Feb 8, 2022
N/A· v4
9.6 CRITICAL· v3
6.8 MEDIUM· v2
Cross-site scripting vulnerability in CSV+ prior to 0.8.1 allows a remote unauthenticated attacker to inject an arbitrary script or an arbitrary OS command via a specially crafted CSV file that contains HTML a tag.
1Canon
342204f
2204n2206if+31 more
Jun 17, 2026
Feb 8, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Cross-site scripting vulnerability in Canon laser printers and small office multifunctional printers (LBP162L/LBP162, MF4890dw, MF269dw/MF265dw/MF264dw/MF262dw, MF249dw/MF245dw/MF244dw/MF242dw/MF232w, and MF229dw/MF224dw...Show more
Cross-site scripting vulnerability in Canon laser printers and small office multifunctional printers (LBP162L/LBP162, MF4890dw, MF269dw/MF265dw/MF264dw/MF262dw, MF249dw/MF245dw/MF244dw/MF242dw/MF232w, and MF229dw/MF224dw/MF222dw sold in Japan, imageCLASS MF Series (MF113W/MF212W/MF217W/MF227DW/MF229DW, MF232W/MF244DW/MF247DW/MF249DW, MF264DW/MF267DW/MF269DW/MF269DW VP, and MF4570DN/MF4570DW/MF4770N/MF4880DW/MF4890DW) and imageCLASS LBP Series (LBP113W/LBP151DW/LBP162DW ) sold in the US, and iSENSYS (LBP162DW, LBP113W, LBP151DW, MF269dw, MF267dw, MF264dw, MF113w, MF249dw, MF247dw, MF244dw, MF237w, MF232w, MF229dw, MF217w, MF212w, MF4780w, and MF4890dw) and imageRUNNER (2206IF, 2204N, and 2204F) sold in Europe) allows remote attackers to inject an arbitrary script via unspecified vectors.Show less
1Microweber
1Microweber
Jun 17, 2026
Feb 8, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-site Scripting (XSS) - Stored in Packagist microweber/microweber prior to 1.2.11.
1Quickbox
1Quickbox
Jun 17, 2026
Feb 7, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
QuickBox Pro v2.4.8 contains a cross-site scripting (XSS) vulnerability at "adminuseredit.php?usertoedit=XSS", as the user supplied input for the value of this parameter is not properly sanitized.
1Visser
1Store Exporter For Woocommerce
Jun 17, 2026
Feb 7, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The WooCommerce Stored Exporter WordPress plugin before 2.7.1 was affected by a Reflected Cross-Site Scripting (XSS) vulnerability in the woo_ce admin page.
1Premio
1Mystickyelements
Jun 17, 2026
Feb 7, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The All-in-one Floating Contact Form, Call, Chat, and 50+ Social Icon Tabs WordPress plugin before 2.0.4 was vulnerable to reflected XSS on the my-sticky-elements-leads admin page.
1Wpeka
1Wplegalpages
Jun 17, 2026
Feb 7, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The Privacy Policy Generator, Terms & Conditions Generator WordPress Plugin : WPLegalPages WordPress plugin before 2.7.1 does not check for authorisation and has a flawed CSRF logic when saving its settings, allowing any...Show more
The Privacy Policy Generator, Terms & Conditions Generator WordPress Plugin : WPLegalPages WordPress plugin before 2.7.1 does not check for authorisation and has a flawed CSRF logic when saving its settings, allowing any authenticated users, such as subscriber, to update them. Furthermore, due to the lack of sanitisation and escaping, it could lead to Stored Cross-Site ScriptingShow less
1Ivorysearch
1Ivory Search
Jun 17, 2026
Feb 7, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The Ivory Search WordPress plugin before 5.4.1 does not escape some of the Form settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallo...Show more
The Ivory Search WordPress plugin before 5.4.1 does not escape some of the Form settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.Show less
1Gtranslate
1Translate Wordpress With Gtranslate
Jun 17, 2026
Feb 7, 2022
N/A· v4
4.7 MEDIUM· v3
2.6 LOW· v2
The Translate WordPress with GTranslate WordPress plugin before 2.9.7 does not sanitise and escape the body parameter in the url_addon/gtranslate-email.php file before outputting it back in the page, leading to a Reflect...Show more
The Translate WordPress with GTranslate WordPress plugin before 2.9.7 does not sanitise and escape the body parameter in the url_addon/gtranslate-email.php file before outputting it back in the page, leading to a Reflected Cross-Site Scripting issue. Note: exploitation of the issue requires knowledge of the NONCE_SALT and NONCE_KEYShow less