CWE-79
47,551 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (47,551)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiMail version 7.0.1 and 7.0.0, version 6.4.5 and below, version 6.3.7 and below, version 6.0.11 and below allows atta...Show more |
Ivanti Service Manager 2021.1 allows reflected XSS via the appName parameter associated with ConfigDB calls, such as in RelocateAttachments.aspx. |
A cross-site scripting (XSS) vulnerability in the Create Post function of Anchor CMS v0.12.7 allows attackers to execute arbitrary web scripts or HTML. |
Reflected Cross-site scripting (XSS) vulnerability in RosarioSIS 8.2.1 allows attackers to inject arbitrary HTML via the search_term parameter in the modules/Scheduling/Courses.php script. |
The Link Library WordPress plugin before 7.2.9 does not sanitise and escape the settingscopy parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting |
The UpdraftPlus WordPress Backup Plugin WordPress plugin before 1.16.69 does not sanitise and escape the updraft_restore parameter before outputting it back in the Restore page, leading to a Reflected Cross-Site Scriptin...Show more |
1Pluginus 1Woocommerce Products Filter Jun 17, 2026 Feb 1, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The WOOF WordPress plugin before 1.2.6.3 does not sanitise and escape the woof_redraw_elements before outputing back in an admin page, leading to a Reflected Cross-Site Scripting |
1Cf7skins 1Contact Form 7 Skins Jun 17, 2026 Feb 1, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The Skins for Contact Form 7 WordPress plugin before 2.5.1 does not sanitise and escape the tab parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting |
1Asset Cleanup\ 1 Page Speed Booster Project Jun 17, 2026 Feb 1, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The Asset CleanUp: Page Speed Booster WordPress plugin before 1.3.8.5 does not sanitise and escape POSted parameters sent to the wpassetcleanup_fetch_active_plugins_icons AJAX action (available to admin users), leading t...Show more |
1Nextscripts 1Social Networks Auto Poster Jun 17, 2026 Feb 1, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The NextScripts: Social Networks Auto-Poster WordPress plugin before 4.3.24 does not sanitise and escape logged requests before outputting them in the related admin dashboard, leading to an Unauthenticated Stored Cross-S...Show more |
1Cusmin 1Absolutely Glamorous Custom Admin Jun 17, 2026 Feb 1, 2022 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 The Custom Dashboard & Login Page WordPress plugin before 7.0 does not sanitise some of its settings, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disa...Show more |
1Asset Cleanup\ 1 Page Speed Booster Project Jun 17, 2026 Feb 1, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The Asset CleanUp: Page Speed Booster WordPress plugin before 1.3.8.5 does not escape the wpacu_selected_sub_tab_area parameter before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Sit...Show more |
1Yellowpencil 1Visual Css Style Editor Jun 17, 2026 Feb 1, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The Visual CSS Style Editor WordPress plugin before 7.5.4 does not sanitise and escape the wyp_page_type parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting issue |
1Domaincheckplugin 1Domain Check Jun 17, 2026 Feb 1, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The Domain Check WordPress plugin before 1.0.17 does not sanitise and escape the domain parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting issue |
The Ninja Tables WordPress plugin before 4.1.8 does not sanitise and escape some of its table fields, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capabilit...Show more |
1Welaunch 1Wordpress Gdpr&ccpa Jun 17, 2026 Feb 1, 2022 N/A· v4 9.6 CRITICAL· v3 6.8 MEDIUM· v2 The check_privacy_settings AJAX action of the WordPress GDPR WordPress plugin before 1.9.26, available to both unauthenticated and authenticated users, responds with JSON data without an "application/json" content-type....Show more |
1Getperfectsurvey 1Perfect Survey Jun 17, 2026 Feb 1, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The Perfect Survey WordPress plugin through 1.5.2 does not validate and escape the X-Forwarded-For header value before outputting it in the statistic page when the Anonymize IP setting of a survey is turned off, leading...Show more |
1Getperfectsurvey 1Perfect Survey Jun 17, 2026 Feb 1, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The Perfect Survey WordPress plugin before 1.5.2 does not sanitise and escape multiple parameters (id and filters[session_id] of single_statistics page, type and message of importexport page) before outputting them back...Show more |
1Nd Learning Project 1Nd Learning Jun 17, 2026 Feb 1, 2022 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 The Learning Courses WordPress plugin before 5.0 does not sanitise and escape the Email PDT identity token settings, which could allow high privilege users to perform cross-Site Scripting attacks even when the unfiltered...Show more |
The SVG Support WordPress plugin before 2.3.20 does not escape the "CSS Class to target" setting before outputting it in an attribute, which could allow high privilege users to perform Cross-Site Scripting attacks even w...Show more |