← Back
CWE-79

47,680 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (47,680)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Openwrt
1Openwrt
Jun 17, 2026
Dec 27, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
OpenWrt 21.02.1 allows XSS via the Port Forwards Add Name screen.
1Netgen
1Tags Bundle
Jun 17, 2026
Dec 27, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Netgen Tags Bundle 3.4.x before 3.4.11 and 4.0.x before 4.0.15 allows XSS in the Tags Admin interface.
1Qibosoft
1Qibosoft
Jun 17, 2026
Dec 27, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Qibosoft v7 contains a stored cross-site scripting (XSS) vulnerability in the component /admin/index.php?lfj=friendlink&action=add.
1Requarks
1Wiki.js
Jun 17, 2026
Dec 27, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Wiki.js is a wiki app built on Node.js. Wiki.js 2.5.263 and earlier is vulnerable to stored cross-site scripting through non-image file uploads for file types that can be viewed directly inline in the browser. By creatin...Show more
Wiki.js is a wiki app built on Node.js. Wiki.js 2.5.263 and earlier is vulnerable to stored cross-site scripting through non-image file uploads for file types that can be viewed directly inline in the browser. By creating a malicious file which can execute inline JS when viewed in the browser (e.g. XML files), a malicious Wiki.js user may stage a stored cross-site scripting attack. This allows the attacker to execute malicious JavaScript when the file is viewed directly by other users. The file must be opened directly by the user and will not trigger directly in a normal Wiki.js page. A patch in version 2.5.264 fixes this vulnerability by adding an optional (enabled by default) force download flag to all non-image file types, preventing the file from being viewed inline in the browser. As a workaround, disable file upload for all non-trusted users. --- Thanks to @Haxatron for reporting this vulnerability. Initially reported via https://huntr.dev/bounties/266bff09-00d9-43ca-a4bb-bb540642811f/Show less
1Requarks
1Wiki.js
Jun 17, 2026
Dec 27, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Wiki.js is a wiki app built on node.js. Wiki.js 2.5.263 and earlier is vulnerable to stored cross-site scripting through a SVG file upload made via a custom request with a fake MIME type. By creating a crafted SVG file,...Show more
Wiki.js is a wiki app built on node.js. Wiki.js 2.5.263 and earlier is vulnerable to stored cross-site scripting through a SVG file upload made via a custom request with a fake MIME type. By creating a crafted SVG file, a malicious Wiki.js user may stage a stored cross-site scripting attack. This allows the attacker to execute malicious JavaScript when the SVG is viewed directly by other users. Scripts do not execute when loaded inside a page via normal `<img>` tags. The malicious SVG can only be uploaded by crafting a custom request to the server with a fake MIME type. A patch in version 2.5.264 fixes this vulnerability by adding an additional file extension verification check to the optional (enabled by default) SVG sanitization step to all file uploads that match the SVG mime type. As a workaround, disable file upload for all non-trusted users.Show less
1Ibm
3Power System Ac922 (8335 Gtc) Firmware
Power System Ac922 (8335 Gtg) FirmwarePower System Ac922 (8335 Gtw) Firmware
Jun 17, 2026
Dec 27, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
IBM OPENBMC OP910 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclo...Show more
IBM OPENBMC OP910 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 212049.Show less
1Buttonizer
1Buttonizer
Jun 17, 2026
Dec 27, 2021
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The Smart Floating / Sticky Buttons WordPress plugin before 2.5.5 does not sanitise and escape some parameter before outputting them in attributes and page, which could allow high privilege users to perform Cross-Site Sc...Show more
The Smart Floating / Sticky Buttons WordPress plugin before 2.5.5 does not sanitise and escape some parameter before outputting them in attributes and page, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.Show less
1Wprssaggregator
1Wp Rss Aggregator
Jun 17, 2026
Dec 27, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The WP RSS Aggregator WordPress plugin before 4.19.3 does not sanitise and escape data before outputting it in the System Info admin dashboard, which could lead to a Stored XSS issue due to the wprss_dismiss_addon_notice...Show more
The WP RSS Aggregator WordPress plugin before 4.19.3 does not sanitise and escape data before outputting it in the System Info admin dashboard, which could lead to a Stored XSS issue due to the wprss_dismiss_addon_notice AJAX action missing authorisation and CSRF checks, allowing any authenticated users, such as subscriber to call it and set a malicious payload in the addon parameter.Show less
1Wpfront
1Wpfront User Role Editor
Jun 17, 2026
Dec 27, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The WPFront User Role Editor WordPress plugin before 3.2.1.11184 does not sanitise and escape the changes-saved parameter before outputting it back in the admin dashboard, leading to a Reflected Cross-Site Scripting
1Gwolle Guestbook Project
1Gwolle Guestbook
Jun 17, 2026
Dec 27, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Gwolle Guestbook WordPress plugin before 4.2.0 does not sanitise and escape the gwolle_gb_user_email parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting issue in an admin...Show more
The Gwolle Guestbook WordPress plugin before 4.2.0 does not sanitise and escape the gwolle_gb_user_email parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting issue in an admin pageShow less
1Strangerstudios
1Paid Memberships Pro
Jun 17, 2026
Dec 27, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Paid Memberships Pro WordPress plugin before 2.6.6 does not escape the s parameter before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Site Scripting
1W3eden
1Download Manager
Jun 17, 2026
Dec 27, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The WordPress Download Manager WordPress plugin before 3.2.22 does not sanitise and escape Template data before outputting it in various pages (such as admin dashboard and frontend). Due to the lack of authorisation and...Show more
The WordPress Download Manager WordPress plugin before 3.2.22 does not sanitise and escape Template data before outputting it in various pages (such as admin dashboard and frontend). Due to the lack of authorisation and CSRF checks in the wpdm_save_template AJAX action, any authenticated users such as subscriber is able to call it and perform Cross-Site Scripting attacksShow less
1Themehunk
1Contact Form & Lead Form Elementor Builder
Jun 17, 2026
Dec 27, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Contact Form & Lead Form Elementor Builder WordPress plugin before 1.6.4 does not sanitise and escape some lead values, which could allow unauthenticated users to perform Cross-Site Scripting attacks against logged i...Show more
The Contact Form & Lead Form Elementor Builder WordPress plugin before 1.6.4 does not sanitise and escape some lead values, which could allow unauthenticated users to perform Cross-Site Scripting attacks against logged in admin viewing the inserted LeadsShow less
1Typebot
1Typebot
Jun 17, 2026
Dec 27, 2021
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The Typebot | Build beautiful conversational forms WordPress plugin before 1.4.3 does not sanitise and escape the Publish ID setting, which could allow high privilege users to perform Cross-Site Scripting attacks even wh...Show more
The Typebot | Build beautiful conversational forms WordPress plugin before 1.4.3 does not sanitise and escape the Publish ID setting, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.Show less
1Tickera
1Tickera
Jun 17, 2026
Dec 27, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Tickera WordPress plugin before 3.4.8.3 does not properly sanitise and escape the Name fields of booked Events before outputting them in the Orders admin dashboard, which could allow unauthenticated users to perform...Show more
The Tickera WordPress plugin before 3.4.8.3 does not properly sanitise and escape the Name fields of booked Events before outputting them in the Orders admin dashboard, which could allow unauthenticated users to perform Cross-Site Scripting attacks against admins.Show less
1Attendance Management System Project
1Attendance Management System
Jun 17, 2026
Dec 26, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Attendance Management System 1.0 is affected by a Cross Site Scripting (XSS) vulnerability. The value of the FirstRecord request parameter is copied into the value of an HTML tag attribute which is encapsulated in double...Show more
Attendance Management System 1.0 is affected by a Cross Site Scripting (XSS) vulnerability. The value of the FirstRecord request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The attacker can access the system, by using the XSS-reflected method, and then can store information by injecting the admin account on this system.Show less
1Livehelperchat
1Live Helper Chat
Jun 17, 2026
Dec 26, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
livehelperchat is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
1Netgear
2Gs108t Firmware
Gs110tp Firmware
Jun 17, 2026
Dec 26, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Certain NETGEAR devices are affected by stored XSS. This affects GS108Tv2 before 5.4.2.36 and GS110TPv2 before 5.4.2.36.
1Netgear
5Rax15 Firmware
Rax200 FirmwareRax20 Firmware+2 more
Jun 17, 2026
Dec 26, 2021
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Certain NETGEAR devices are affected by stored XSS. This affects RAX200 before 1.0.5.126, RAX20 before 1.0.2.82, RAX80 before 1.0.5.126, RAX15 before 1.0.2.82, and RAX75 before 1.0.5.126.
1Netgear
15Ac2100 Firmware
Ac2400 FirmwareAc2600 Firmware+12 more
Jun 17, 2026
Dec 26, 2021
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Certain NETGEAR devices are affected by stored XSS. This affects R6120 before 1.0.0.76, R6260 before 1.1.0.78, R6850 before 1.1.0.78, R6350 before 1.1.0.78, R6330 before 1.1.0.78, R6800 before 1.2.0.76, R6700v2 before 1....Show more
Certain NETGEAR devices are affected by stored XSS. This affects R6120 before 1.0.0.76, R6260 before 1.1.0.78, R6850 before 1.1.0.78, R6350 before 1.1.0.78, R6330 before 1.1.0.78, R6800 before 1.2.0.76, R6700v2 before 1.2.0.76, R6900v2 before 1.2.0.76, R7200 before 1.2.0.76, R7350 before 1.2.0.76, R7400 before 1.2.0.76, R7450 before 1.2.0.76, AC2100 before 1.2.0.76, AC2400 before 1.2.0.76, and AC2600 before 1.2.0.76.Show less