CWE-79
47,551 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (47,551)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Smashballoon 1Smash Balloon Social Post Feed Jun 17, 2026 Jan 17, 2022 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 The Smash Balloon Social Post Feed WordPress plugin before 4.1.1 was affected by a reflected XSS in custom-facebook-feed in cff-top admin page. |
1Wpbookingsystem 1Wp Booking System Jun 17, 2026 Jan 17, 2022 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 The WP Booking System WordPress plugin before 2.0.15 was affected by a reflected xss in wp-booking-system on the wpbs-calendars admin page. |
1Webnus 1Modern Events Calendar Lite Jun 17, 2026 Jan 17, 2022 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 The Modern Events Calendar Lite WordPress plugin before 6.2.0 alloed any logged-in user, even a subscriber user, may add a category whose parameters are incorrectly escaped in the admin panel, leading to stored XSS. |
1Theeventscalendar 1Eventcalendar Jun 17, 2026 Jan 17, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The EventCalendar WordPress plugin before 1.1.51 does not escape some user input before outputting it back in attributes, leading to Reflected Cross-SIte Scripting issues |
1Seur Oficial Project 1Seur Oficial Jun 17, 2026 Jan 17, 2022 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 The SEUR Oficial WordPress plugin before 1.7.0 does not sanitize and escape some of its settings allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowe...Show more |
1Navz 1Acf Photo Gallery Field Jun 17, 2026 Jan 17, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The ACF Photo Gallery Field WordPress plugin before 1.7.5 does not sanitise and escape the post parameter in the includes/acf_photo_gallery_metabox_edit.php file before outputing back in an attribute, leading to a Reflec...Show more |
chaskiq is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
chaskiq is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
1Expresstech 1Quiz And Survey Master Jun 17, 2026 Jan 17, 2022 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 Stored cross-site scripting vulnerability in Quiz And Survey Master versions prior to 7.3.7 allows a remote authenticated attacker to inject an arbitrary script via an website that uses Quiz And Survey Master. |
1Expresstech 1Quiz And Survey Master Jun 17, 2026 Jan 17, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Reflected cross-site scripting vulnerability in Quiz And Survey Master versions prior to 7.3.7 allows a remote attacker to inject an arbitrary script via unspecified vectors. |
calibre-web is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
A stored cross site scripting (XSS) vulnerability in Checkmk 1.6.0x prior to 1.6.0p19 allows an authenticated remote attacker to inject arbitrary JavaScript via a javascript: URL in a view title. |
1Sap 1Enterprise Threat Detection Jun 17, 2026 Jan 14, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 SAP Enterprise Threat Detection (ETD) - version 2.0, does not sufficiently encode user-controlled inputs which may lead to an unauthorized attacker possibly exploit XSS vulnerability. The UIs in ETD are using SAP UI5 sta...Show more |
1Microfocus 1Arcsight Enterprise Security Manager Jun 17, 2026 Jan 14, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Potential vulnerabilities have been identified in Micro Focus ArcSight Enterprise Security Manager, affecting versions 7.4.x and 7.5.x. The vulnerabilities could be remotely exploited resulting in Cross-Site Scripting (X...Show more |
1Microfocus 1Arcsight Enterprise Security Manager Jun 17, 2026 Jan 14, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Potential vulnerabilities have been identified in Micro Focus ArcSight Enterprise Security Manager, affecting versions 7.4.x and 7.5.x. The vulnerabilities could be remotely exploited resulting in Cross-Site Scripting (X...Show more |
Authenticated Reflected Cross-Site Scripting (XSS) vulnerability discovered in WordPress plugin Download Monitor (versions <= 4.4.6). |
Cross-site Scripting (XSS) vulnerability in the search functionality of AlCoda NetBiblio WebOPAC allows an unauthenticated user to craft a reflected Cross-Site Scripting attack. This issue affects: AlCoda NetBiblio WebOP...Show more |
Multiple vulnerabilities in the web-based management interface of Cisco Security Manager could allow an unauthenticated, remote attacker to conduct cross-site scripting attacks against a user of the interface. These vuln...Show more |
Multiple vulnerabilities in the web-based management interface of Cisco Security Manager could allow an unauthenticated, remote attacker to conduct cross-site scripting attacks against a user of the interface. These vuln...Show more |
Multiple vulnerabilities in the web-based management interface of Cisco Security Manager could allow an unauthenticated, remote attacker to conduct cross-site scripting attacks against a user of the interface. These vuln...Show more |