CWE-79
47,680 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (47,680)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
OpenWrt 21.02.1 allows XSS via the Port Forwards Add Name screen. |
Netgen Tags Bundle 3.4.x before 3.4.11 and 4.0.x before 4.0.15 allows XSS in the Tags Admin interface. |
Qibosoft v7 contains a stored cross-site scripting (XSS) vulnerability in the component /admin/index.php?lfj=friendlink&action=add. |
Wiki.js is a wiki app built on Node.js. Wiki.js 2.5.263 and earlier is vulnerable to stored cross-site scripting through non-image file uploads for file types that can be viewed directly inline in the browser. By creatin...Show more |
Wiki.js is a wiki app built on node.js. Wiki.js 2.5.263 and earlier is vulnerable to stored cross-site scripting through a SVG file upload made via a custom request with a fake MIME type. By creating a crafted SVG file,...Show more |
1Ibm 3Power System Ac922 (8335 Gtc) Firmware Power System Ac922 (8335 Gtg) FirmwarePower System Ac922 (8335 Gtw) FirmwareJun 17, 2026 Dec 27, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 IBM OPENBMC OP910 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclo...Show more |
The Smart Floating / Sticky Buttons WordPress plugin before 2.5.5 does not sanitise and escape some parameter before outputting them in attributes and page, which could allow high privilege users to perform Cross-Site Sc...Show more |
1Wprssaggregator 1Wp Rss Aggregator Jun 17, 2026 Dec 27, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 The WP RSS Aggregator WordPress plugin before 4.19.3 does not sanitise and escape data before outputting it in the System Info admin dashboard, which could lead to a Stored XSS issue due to the wprss_dismiss_addon_notice...Show more |
1Wpfront 1Wpfront User Role Editor Jun 17, 2026 Dec 27, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The WPFront User Role Editor WordPress plugin before 3.2.1.11184 does not sanitise and escape the changes-saved parameter before outputting it back in the admin dashboard, leading to a Reflected Cross-Site Scripting |
1Gwolle Guestbook Project 1Gwolle Guestbook Jun 17, 2026 Dec 27, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The Gwolle Guestbook WordPress plugin before 4.2.0 does not sanitise and escape the gwolle_gb_user_email parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting issue in an admin...Show more |
1Strangerstudios 1Paid Memberships Pro Jun 17, 2026 Dec 27, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The Paid Memberships Pro WordPress plugin before 2.6.6 does not escape the s parameter before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Site Scripting |
The WordPress Download Manager WordPress plugin before 3.2.22 does not sanitise and escape Template data before outputting it in various pages (such as admin dashboard and frontend). Due to the lack of authorisation and...Show more |
1Themehunk 1Contact Form & Lead Form Elementor Builder Jun 17, 2026 Dec 27, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The Contact Form & Lead Form Elementor Builder WordPress plugin before 1.6.4 does not sanitise and escape some lead values, which could allow unauthenticated users to perform Cross-Site Scripting attacks against logged i...Show more |
The Typebot | Build beautiful conversational forms WordPress plugin before 1.4.3 does not sanitise and escape the Publish ID setting, which could allow high privilege users to perform Cross-Site Scripting attacks even wh...Show more |
The Tickera WordPress plugin before 3.4.8.3 does not properly sanitise and escape the Name fields of booked Events before outputting them in the Orders admin dashboard, which could allow unauthenticated users to perform...Show more |
1Attendance Management System Project 1Attendance Management System Jun 17, 2026 Dec 26, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Attendance Management System 1.0 is affected by a Cross Site Scripting (XSS) vulnerability. The value of the FirstRecord request parameter is copied into the value of an HTML tag attribute which is encapsulated in double...Show more |
1Livehelperchat 1Live Helper Chat Jun 17, 2026 Dec 26, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 livehelperchat is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
1Netgear 2Gs108t Firmware Gs110tp FirmwareJun 17, 2026 Dec 26, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Certain NETGEAR devices are affected by stored XSS. This affects GS108Tv2 before 5.4.2.36 and GS110TPv2 before 5.4.2.36. |
1Netgear 5Rax15 Firmware Rax200 FirmwareRax20 Firmware+2 moreJun 17, 2026 Dec 26, 2021 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 Certain NETGEAR devices are affected by stored XSS. This affects RAX200 before 1.0.5.126, RAX20 before 1.0.2.82, RAX80 before 1.0.5.126, RAX15 before 1.0.2.82, and RAX75 before 1.0.5.126. |
1Netgear 15Ac2100 Firmware Ac2400 FirmwareAc2600 Firmware+12 moreJun 17, 2026 Dec 26, 2021 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 Certain NETGEAR devices are affected by stored XSS. This affects R6120 before 1.0.0.76, R6260 before 1.1.0.78, R6850 before 1.1.0.78, R6350 before 1.1.0.78, R6330 before 1.1.0.78, R6800 before 1.2.0.76, R6700v2 before 1....Show more |