← Back
CWE-79

47,551 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (47,551)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Visser
1Store Toolkit For Woocommerce
Jun 17, 2026
Feb 7, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Store Toolkit for WooCommerce WordPress plugin before 2.3.2 does not sanitise and escape the tab parameter before outputting it back in an admin page in an error message, leading to a Reflected Cross-Site Scripting
1Cluevo
1Learning Management System
Jun 17, 2026
Feb 7, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The CLUEVO LMS, E-Learning Platform WordPress plugin before 1.8.1 does not sanitise and escape Course's module, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html...Show more
The CLUEVO LMS, E-Learning Platform WordPress plugin before 1.8.1 does not sanitise and escape Course's module, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowedShow less
1Supportcandy
1Supportcandy
Jun 17, 2026
Feb 7, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The SupportCandy WordPress plugin before 2.2.7 does not validate and escape the page attribute of its shortcode, which could allow users with a role as low as Contributor to perform Cross-Site Scripting attacks
1Supportcandy
1Supportcandy
Jun 17, 2026
Feb 7, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The SupportCandy WordPress plugin before 2.2.7 does not sanitise and escape the query string before outputting it back in pages with the [wpsc_create_ticket] shortcode embed, leading to a Reflected Cross-Site Scripting i...Show more
The SupportCandy WordPress plugin before 2.2.7 does not sanitise and escape the query string before outputting it back in pages with the [wpsc_create_ticket] shortcode embed, leading to a Reflected Cross-Site Scripting issueShow less
1Otrs
1Otrs
Jun 17, 2026
Feb 7, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
OTRS administrators can configure dynamic field and inject malicious JavaScript code in the error message of the regular expression check. When used in the agent interface, malicious code might be exectued in the browser...Show more
OTRS administrators can configure dynamic field and inject malicious JavaScript code in the error message of the regular expression check. When used in the agent interface, malicious code might be exectued in the browser. This issue affects: OTRS AG OTRS 7.0.x version: 7.0.31 and prior versions.Show less
1Synology
1Diskstation Manager
Jun 17, 2026
Feb 7, 2022
N/A· v4
5.4 MEDIUM· v3
4.0 MEDIUM· v2
Improper neutralization of special elements in output used by a downstream component ('Injection') vulnerability in work flow management in Synology DiskStation Manager (DSM) before 7.0.1-42218-2 allows remote authentica...Show more
Improper neutralization of special elements in output used by a downstream component ('Injection') vulnerability in work flow management in Synology DiskStation Manager (DSM) before 7.0.1-42218-2 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.Show less
1Livehelperchat
1Live Helper Chat
Jun 17, 2026
Feb 6, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-site Scripting (XSS) - Stored in Packagist remdex/livehelperchat prior to 3.93v.
1Beanstalk Console Project
1Beanstalk Console
Jun 17, 2026
Feb 5, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site Scripting (XSS) - Reflected in Packagist ptrofimov/beanstalk_console prior to 1.7.12.
1Karma Project
1Karma
Jun 17, 2026
Feb 5, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site Scripting (XSS) - DOM in NPM karma prior to 6.3.14.
1Yet Another Stars Rating Project
1Yet Another Stars Rating
Jun 17, 2026
Feb 4, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-Site Scripting (XSS) vulnerability discovered in Yasr – Yet Another Stars Rating WordPress plugin (versions <= 2.9.9), vulnerable at parameter 'source'.
1Schneider Electric
1Ecostruxure Power Monitoring Expert
Jun 17, 2026
Feb 4, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists that could allow an authenticated attacker to view data, change settings, or impact availability of the...Show more
A CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists that could allow an authenticated attacker to view data, change settings, or impact availability of the software when the user visits a page containing the injected payload. Affected Product: EcoStruxure Power Monitoring Expert (Versions 2020 and prior)Show less
1Laracom Project
1Laracom
Jun 17, 2026
Feb 4, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Unrestricted Upload of File with Dangerous Type in Packagist jsdecena/laracom prior to v2.0.9.
1Embed Swagger Project
1Embed Swagger
Jun 17, 2026
Feb 4, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Embed Swagger WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to insufficient escaping/sanitization and validation via the url parameter found in the ~/swagger-iframe.php file which allows attack...Show more
The Embed Swagger WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to insufficient escaping/sanitization and validation via the url parameter found in the ~/swagger-iframe.php file which allows attackers to inject arbitrary web scripts onto the page, in versions up to and including 1.0.0.Show less
1Fotobook Project
1Fotobook
Jun 17, 2026
Feb 4, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Fotobook WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to insufficient escaping and the use of $_SERVER['PHP_SELF'] found in the ~/options-fotobook.php file which allows attackers to inject arb...Show more
The Fotobook WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to insufficient escaping and the use of $_SERVER['PHP_SELF'] found in the ~/options-fotobook.php file which allows attackers to inject arbitrary web scripts onto the page, in versions up to and including 3.2.3.Show less
1Codemiq
1Wordpress Email Template Designer
Jun 17, 2026
Feb 4, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The WP HTML Mail WordPress plugin is vulnerable to unauthorized access which allows unauthenticated attackers to retrieve and modify theme settings due to a missing capability check on the /themesettings REST-API endpoin...Show more
The WP HTML Mail WordPress plugin is vulnerable to unauthorized access which allows unauthenticated attackers to retrieve and modify theme settings due to a missing capability check on the /themesettings REST-API endpoint found in the ~/includes/class-template-designer.php file, in versions up to and including 3.0.9. This makes it possible for attackers with no privileges to execute the endpoint and add malicious JavaScript to a vulnerable WordPress site.Show less
1Xwiki
1Xwiki
Jun 17, 2026
Feb 4, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
XWiki is a generic wiki platform offering runtime services for applications built on top of it. When using default XWiki configuration, it's possible for an attacker to upload an SVG containing a script executed when exe...Show more
XWiki is a generic wiki platform offering runtime services for applications built on top of it. When using default XWiki configuration, it's possible for an attacker to upload an SVG containing a script executed when executing the download action on the file. This problem has been patched so that the default configuration doesn't allow to display the SVG files in the browser. Users are advised to update or to disallow uploads of SVG files.Show less
1Codexnotes
1Codex
Jun 17, 2026
Feb 4, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A Cross Site Scripting (XSS) vulnerability exists in Codex before 1.4.0 via Notebook/Page name field, which allows malicious users to execute arbitrary code via a crafted http code in a .json file.
1Gibbonedu
1Gibbon
Jun 17, 2026
Feb 3, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Multiple cross-site scripting (XSS) vulnerabilities in the component outcomes_addProcess.php of Gibbon CMS v22.0.01 allow attackers to execute arbitrary web scripts or HTML via a crafted payload insterted into the name,...Show more
Multiple cross-site scripting (XSS) vulnerabilities in the component outcomes_addProcess.php of Gibbon CMS v22.0.01 allow attackers to execute arbitrary web scripts or HTML via a crafted payload insterted into the name, category, description parameters.Show less
3Debian
DjangoprojectFedoraproject
3Debian Linux
DjangoFedora
Jun 17, 2026
Feb 3, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The {% debug %} template tag in Django 2.2 before 2.2.27, 3.2 before 3.2.12, and 4.0 before 4.0.2 does not properly encode the current context. This may lead to XSS.
1Printerlogic
1Web Stack
Jul 9, 2026
Feb 2, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
PrinterLogic Web Stack versions 19.1.1.13 SP9 and below are vulnerable to multiple reflected cross site scripting vulnerabilities. Attacker controlled input is reflected back in the page without sanitization.