CWE-79
47,551 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (47,551)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Visser 1Store Toolkit For Woocommerce Jun 17, 2026 Feb 7, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The Store Toolkit for WooCommerce WordPress plugin before 2.3.2 does not sanitise and escape the tab parameter before outputting it back in an admin page in an error message, leading to a Reflected Cross-Site Scripting |
1Cluevo 1Learning Management System Jun 17, 2026 Feb 7, 2022 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 The CLUEVO LMS, E-Learning Platform WordPress plugin before 1.8.1 does not sanitise and escape Course's module, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html...Show more |
The SupportCandy WordPress plugin before 2.2.7 does not validate and escape the page attribute of its shortcode, which could allow users with a role as low as Contributor to perform Cross-Site Scripting attacks |
The SupportCandy WordPress plugin before 2.2.7 does not sanitise and escape the query string before outputting it back in pages with the [wpsc_create_ticket] shortcode embed, leading to a Reflected Cross-Site Scripting i...Show more |
OTRS administrators can configure dynamic field and inject malicious JavaScript code in the error message of the regular expression check. When used in the agent interface, malicious code might be exectued in the browser...Show more |
1Synology 1Diskstation Manager Jun 17, 2026 Feb 7, 2022 N/A· v4 5.4 MEDIUM· v3 4.0 MEDIUM· v2 Improper neutralization of special elements in output used by a downstream component ('Injection') vulnerability in work flow management in Synology DiskStation Manager (DSM) before 7.0.1-42218-2 allows remote authentica...Show more |
1Livehelperchat 1Live Helper Chat Jun 17, 2026 Feb 6, 2022 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 Cross-site Scripting (XSS) - Stored in Packagist remdex/livehelperchat prior to 3.93v. |
1Beanstalk Console Project 1Beanstalk Console Jun 17, 2026 Feb 5, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Cross-site Scripting (XSS) - Reflected in Packagist ptrofimov/beanstalk_console prior to 1.7.12. |
Cross-site Scripting (XSS) - DOM in NPM karma prior to 6.3.14. |
1Yet Another Stars Rating Project 1Yet Another Stars Rating Jun 17, 2026 Feb 4, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Cross-Site Scripting (XSS) vulnerability discovered in Yasr – Yet Another Stars Rating WordPress plugin (versions <= 2.9.9), vulnerable at parameter 'source'. |
1Schneider Electric 1Ecostruxure Power Monitoring Expert Jun 17, 2026 Feb 4, 2022 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 A CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists that could allow an authenticated attacker to view data, change settings, or impact availability of the...Show more |
Unrestricted Upload of File with Dangerous Type in Packagist jsdecena/laracom prior to v2.0.9. |
1Embed Swagger Project 1Embed Swagger Jun 17, 2026 Feb 4, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The Embed Swagger WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to insufficient escaping/sanitization and validation via the url parameter found in the ~/swagger-iframe.php file which allows attack...Show more |
The Fotobook WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to insufficient escaping and the use of $_SERVER['PHP_SELF'] found in the ~/options-fotobook.php file which allows attackers to inject arb...Show more |
1Codemiq 1Wordpress Email Template Designer Jun 17, 2026 Feb 4, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The WP HTML Mail WordPress plugin is vulnerable to unauthorized access which allows unauthenticated attackers to retrieve and modify theme settings due to a missing capability check on the /themesettings REST-API endpoin...Show more |
XWiki is a generic wiki platform offering runtime services for applications built on top of it. When using default XWiki configuration, it's possible for an attacker to upload an SVG containing a script executed when exe...Show more |
A Cross Site Scripting (XSS) vulnerability exists in Codex before 1.4.0 via Notebook/Page name field, which allows malicious users to execute arbitrary code via a crafted http code in a .json file. |
Multiple cross-site scripting (XSS) vulnerabilities in the component outcomes_addProcess.php of Gibbon CMS v22.0.01 allow attackers to execute arbitrary web scripts or HTML via a crafted payload insterted into the name,...Show more |
3Debian DjangoprojectFedoraproject3Debian Linux DjangoFedoraJun 17, 2026 Feb 3, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The {% debug %} template tag in Django 2.2 before 2.2.27, 3.2 before 3.2.12, and 4.0 before 4.0.2 does not properly encode the current context. This may lead to XSS. |
PrinterLogic Web Stack versions 19.1.1.13 SP9 and below are vulnerable to multiple reflected cross site scripting vulnerabilities. Attacker controlled input is reflected back in the page without sanitization. |