← Back
CWE-79

47,551 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (47,551)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Fortinet
1Fortimail
Jun 17, 2026
Feb 2, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiMail version 7.0.1 and 7.0.0, version 6.4.5 and below, version 6.3.7 and below, version 6.0.11 and below allows atta...Show more
A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiMail version 7.0.1 and 7.0.0, version 6.4.5 and below, version 6.3.7 and below, version 6.0.11 and below allows attacker to execute unauthorized code or commands via crafted HTTP GET requests to the FortiGuard URI protection service.Show less
1Ivanti
1Service Manager
Jun 17, 2026
Feb 1, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Ivanti Service Manager 2021.1 allows reflected XSS via the appName parameter associated with ConfigDB calls, such as in RelocateAttachments.aspx.
1Anchorcms
1Anchor Cms
Jun 17, 2026
Feb 1, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A cross-site scripting (XSS) vulnerability in the Create Post function of Anchor CMS v0.12.7 allows attackers to execute arbitrary web scripts or HTML.
1Rosariosis
1Rosariosis
Jul 9, 2026
Feb 1, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Reflected Cross-site scripting (XSS) vulnerability in RosarioSIS 8.2.1 allows attackers to inject arbitrary HTML via the search_term parameter in the modules/Scheduling/Courses.php script.
1Ylefebvre
1Link Library
Jun 17, 2026
Feb 1, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Link Library WordPress plugin before 7.2.9 does not sanitise and escape the settingscopy parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting
1Updraftplus
1Updraftplus
Jun 17, 2026
Feb 1, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The UpdraftPlus WordPress Backup Plugin WordPress plugin before 1.16.69 does not sanitise and escape the updraft_restore parameter before outputting it back in the Restore page, leading to a Reflected Cross-Site Scriptin...Show more
The UpdraftPlus WordPress Backup Plugin WordPress plugin before 1.16.69 does not sanitise and escape the updraft_restore parameter before outputting it back in the Restore page, leading to a Reflected Cross-Site ScriptingShow less
1Pluginus
1Woocommerce Products Filter
Jun 17, 2026
Feb 1, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The WOOF WordPress plugin before 1.2.6.3 does not sanitise and escape the woof_redraw_elements before outputing back in an admin page, leading to a Reflected Cross-Site Scripting
1Cf7skins
1Contact Form 7 Skins
Jun 17, 2026
Feb 1, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Skins for Contact Form 7 WordPress plugin before 2.5.1 does not sanitise and escape the tab parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting
1Asset Cleanup\
1 Page Speed Booster Project
Jun 17, 2026
Feb 1, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Asset CleanUp: Page Speed Booster WordPress plugin before 1.3.8.5 does not sanitise and escape POSted parameters sent to the wpassetcleanup_fetch_active_plugins_icons AJAX action (available to admin users), leading t...Show more
The Asset CleanUp: Page Speed Booster WordPress plugin before 1.3.8.5 does not sanitise and escape POSted parameters sent to the wpassetcleanup_fetch_active_plugins_icons AJAX action (available to admin users), leading to a Reflected Cross-Site Scripting issueShow less
1Nextscripts
1Social Networks Auto Poster
Jun 17, 2026
Feb 1, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The NextScripts: Social Networks Auto-Poster WordPress plugin before 4.3.24 does not sanitise and escape logged requests before outputting them in the related admin dashboard, leading to an Unauthenticated Stored Cross-S...Show more
The NextScripts: Social Networks Auto-Poster WordPress plugin before 4.3.24 does not sanitise and escape logged requests before outputting them in the related admin dashboard, leading to an Unauthenticated Stored Cross-Site Scripting issueShow less
1Cusmin
1Absolutely Glamorous Custom Admin
Jun 17, 2026
Feb 1, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The Custom Dashboard & Login Page WordPress plugin before 7.0 does not sanitise some of its settings, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disa...Show more
The Custom Dashboard & Login Page WordPress plugin before 7.0 does not sanitise some of its settings, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.Show less
1Asset Cleanup\
1 Page Speed Booster Project
Jun 17, 2026
Feb 1, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Asset CleanUp: Page Speed Booster WordPress plugin before 1.3.8.5 does not escape the wpacu_selected_sub_tab_area parameter before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Sit...Show more
The Asset CleanUp: Page Speed Booster WordPress plugin before 1.3.8.5 does not escape the wpacu_selected_sub_tab_area parameter before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Site Scripting issueShow less
1Yellowpencil
1Visual Css Style Editor
Jun 17, 2026
Feb 1, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Visual CSS Style Editor WordPress plugin before 7.5.4 does not sanitise and escape the wyp_page_type parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting issue
1Domaincheckplugin
1Domain Check
Jun 17, 2026
Feb 1, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Domain Check WordPress plugin before 1.0.17 does not sanitise and escape the domain parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting issue
1Wpmanageninja
1Ninja Tables
Jun 17, 2026
Feb 1, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The Ninja Tables WordPress plugin before 4.1.8 does not sanitise and escape some of its table fields, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capabilit...Show more
The Ninja Tables WordPress plugin before 4.1.8 does not sanitise and escape some of its table fields, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowedShow less
1Welaunch
1Wordpress Gdpr&ccpa
Jun 17, 2026
Feb 1, 2022
N/A· v4
9.6 CRITICAL· v3
6.8 MEDIUM· v2
The check_privacy_settings AJAX action of the WordPress GDPR WordPress plugin before 1.9.26, available to both unauthenticated and authenticated users, responds with JSON data without an "application/json" content-type....Show more
The check_privacy_settings AJAX action of the WordPress GDPR WordPress plugin before 1.9.26, available to both unauthenticated and authenticated users, responds with JSON data without an "application/json" content-type. Since an HTML payload isn't properly escaped, it may be interpreted by a web browser led to this endpoint. Javascript code may be executed on a victim's browser. If the victim is an administrator with a valid session cookie, full control of the WordPress instance may be taken (AJAX calls and iframe manipulation are possible because the vulnerable endpoint is on the same domain as the admin panel - there is no same-origin restriction).Show less
1Getperfectsurvey
1Perfect Survey
Jun 17, 2026
Feb 1, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Perfect Survey WordPress plugin through 1.5.2 does not validate and escape the X-Forwarded-For header value before outputting it in the statistic page when the Anonymize IP setting of a survey is turned off, leading...Show more
The Perfect Survey WordPress plugin through 1.5.2 does not validate and escape the X-Forwarded-For header value before outputting it in the statistic page when the Anonymize IP setting of a survey is turned off, leading to a Stored Cross-Site Scripting issueShow less
1Getperfectsurvey
1Perfect Survey
Jun 17, 2026
Feb 1, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Perfect Survey WordPress plugin before 1.5.2 does not sanitise and escape multiple parameters (id and filters[session_id] of single_statistics page, type and message of importexport page) before outputting them back...Show more
The Perfect Survey WordPress plugin before 1.5.2 does not sanitise and escape multiple parameters (id and filters[session_id] of single_statistics page, type and message of importexport page) before outputting them back in pages/attributes in the admin dashboard, leading to Reflected Cross-Site Scripting issuesShow less
1Nd Learning Project
1Nd Learning
Jun 17, 2026
Feb 1, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The Learning Courses WordPress plugin before 5.0 does not sanitise and escape the Email PDT identity token settings, which could allow high privilege users to perform cross-Site Scripting attacks even when the unfiltered...Show more
The Learning Courses WordPress plugin before 5.0 does not sanitise and escape the Email PDT identity token settings, which could allow high privilege users to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowedShow less
1Benbodhi
1Svg Support
Jun 17, 2026
Feb 1, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The SVG Support WordPress plugin before 2.3.20 does not escape the "CSS Class to target" setting before outputting it in an attribute, which could allow high privilege users to perform Cross-Site Scripting attacks even w...Show more
The SVG Support WordPress plugin before 2.3.20 does not escape the "CSS Class to target" setting before outputting it in an attribute, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.Show less