CWE-79
47,551 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (47,551)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Crmperks 1Contact Form Entries Jun 17, 2026 Jan 24, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The Contact Form Entries WordPress plugin before 1.2.4 does not sanitise and escape various parameters, such as form_id, status, end_date, order, orderby and search before outputting them back in the admin page |
1Wpaffiliatemanager 1Affiliates Manager Jun 17, 2026 Jan 24, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The Affiliates Manager WordPress plugin before 2.9.0 does not validate, sanitise and escape the IP address of requests logged by the click tracking feature, allowing unauthenticated attackers to perform Cross-Site Script...Show more |
1Villatheme 1Orders Tracking For Woocommerce Jun 17, 2026 Jan 24, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The Orders Tracking for WooCommerce WordPress plugin before 1.1.10 does not sanitise and escape the file_url before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting |
1Mobileeventsmanager 1Mobile Events Manager Jun 17, 2026 Jan 24, 2022 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 The Mobile Events Manager WordPress plugin before 1.4.4 does not sanitise and escape various of its settings, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability...Show more |
1Revmakx 1Backup And Staging By Wp Time Capsule Jun 17, 2026 Jan 24, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The Backup and Staging by WP Time Capsule WordPress plugin before 1.22.7 does not sanitise and escape the error parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting |
1Oxilab 1Image Hover Effects Ultimate Jun 17, 2026 Jan 24, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The Image Hover Effects Ultimate (Image Gallery, Effects, Lightbox, Comparison or Magnifier) WordPress plugin before 9.7.1 does not escape the effects parameter before outputting it back in an attribute in an admin page,...Show more |
The Tutor LMS WordPress plugin before 1.9.12 does not escape the search parameter before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Site Scripting |
The myCred WordPress plugin before 2.4 does not sanitise and escape the search query before outputting it back in the history dashboard page, leading to a Reflected Cross-Site Scripting issue |
1Codesnippets 1Code Snippets Jun 17, 2026 Jan 24, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The Code Snippets WordPress plugin before 2.14.3 does not escape the snippets-safe-mode parameter before outputting it back in attributes, leading to a Reflected Cross-Site Scripting issue |
1Yikesinc 1Easy Forms For Mailchimp Jun 17, 2026 Jan 24, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The Easy Forms for Mailchimp WordPress plugin before 6.8.6 does not sanitise and escape the field_name and field_type parameters before outputting them back in attributes, leading to Reflected Cross-Site Scripting issues |
The Smart SEO Tool WordPress plugin before 3.0.6 does not sanitise and escape the search parameter before outputting it back in an attribute when the TDK optimisation setting is enabled, leading to a Reflected Cross-Site...Show more |
1Adtribes 1Product Feed Pro For Woocommerce Jun 17, 2026 Jan 24, 2022 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 The Product Feed PRO for WooCommerce WordPress plugin before 11.0.7 does not have authorisation and CSRF check in some of its AJAX actions, allowing any authenticated users to call then, which could lead to Stored Cross-...Show more |
1Fivestarplugins 1Five Star Restaurant Reservations Jun 17, 2026 Jan 24, 2022 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 The Five Star Restaurant Reservations WordPress plugin before 2.4.8 does not have capability and CSRF checks in the rtb_welcome_set_schedule AJAX action, allowing any authenticated users to call it. Due to the lack of sa...Show more |
1Brevo 1Newsletter, Smtp, Email Marketing And Subscribe Jun 17, 2026 Jan 24, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue WordPress plugin before 3.1.25 does not escape the sib-statistics-date parameter before outputting it back in an attribute, leading to a Reflected C...Show more |
1Tipsandtricks Hq 1Simple Download Monitor Jun 17, 2026 Jan 24, 2022 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 The Simple Download Monitor WordPress plugin before 3.9.11 could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attack via 1) "color" or "css_class" argument of sdm_download shortcod...Show more |
The UpdraftPlus WordPress Backup Plugin WordPress plugin before 1.6.59 does not sanitise its updraft_service settings, allowing high privilege users to set malicious JavaScript payload in it and leading to a Stored Cross...Show more |
AppCMS 2.0.101 has a XSS injection vulnerability in \templates\m\inc_head.php |
Cross-site Scripting (XSS) - Stored in GitHub repository vanessa219/vditor prior to 1.0.34. |
Cross-site Scripting (XSS) - Stored in GitHub repository star7th/showdoc prior to 2.10.2. |
An issue was discovered in phpMyAdmin 5.1 before 5.1.2. An attacker can inject malicious code into aspects of the setup script, which can allow XSS or HTML injection. |