← Back
CWE-79

47,680 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (47,680)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Wpeverest
1Everest Forms
Jun 17, 2026
Dec 21, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Contact Form, Drag and Drop Form Builder for WordPress plugin before 1.8.0 does not escape the status parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting issue
1Shapedplugin
1Logo Carousel
Jun 17, 2026
Dec 21, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The Logo Carousel WordPress plugin before 3.4.2 does not validate and escape the "Logo Margin" carousel option, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks
1Themeboy
1Sportspress
Jun 17, 2026
Dec 21, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The SportsPress WordPress plugin before 2.7.9 does not sanitise and escape its match_day parameter before outputting back in the Events backend page, leading to a Reflected Cross-Site Scripting issue
1Requarks
1Wiki.js
Jun 17, 2026
Dec 20, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Wiki.js is a wiki app built on Node.js. Wiki.js versions 2.5.257 and earlier are vulnerable to stored cross-site scripting through a SVG file upload. By creating a crafted SVG file, a malicious Wiki.js user may stage a s...Show more
Wiki.js is a wiki app built on Node.js. Wiki.js versions 2.5.257 and earlier are vulnerable to stored cross-site scripting through a SVG file upload. By creating a crafted SVG file, a malicious Wiki.js user may stage a stored cross-site scripting attack. This allows the attacker to execute malicious JavaScript when the SVG is viewed directly by other users. Scripts do not execute when loaded inside a page via normal `<img>` tags. Commit 5d3e81496fba1f0fbd64eeb855f30f69a9040718 fixes this vulnerability by adding an optional (enabled by default) SVG sanitization step to all file uploads that match the SVG mime type. As a workaround, disable file upload for all non-trusted users. Wiki.js version 2.5.260 is the first production version to contain a patch. Version 2.5.258 is the first development build to contain a patch and is available only as a Docker image as requarks/wiki:canary-2.5.258.Show less
1Tarteaucitron.js Cookies Legislation & Gdpr Project
1Tarteaucitron.js Cookies Legislation & Gdpr
Jun 17, 2026
Dec 20, 2021
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Multiple Stored Authenticated Cross-Site Scripting (XSS) vulnerabilities were discovered in tarteaucitron.js – Cookies legislation & GDPR WordPress plugin (versions <= 1.6).
1Tarteaucitron.js Cookies Legislation & Gdpr Project
1Tarteaucitron.js Cookies Legislation & Gdpr
Jun 17, 2026
Dec 20, 2021
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Cross-Site Request Forgery (CSRF) vulnerability leading to Cross-Site Scripting (XSS) discovered in tarteaucitron.js – Cookies legislation & GDPR WordPress plugin (versions <= 1.5.4), vulnerable parameters "tarteaucitron...Show more
Cross-Site Request Forgery (CSRF) vulnerability leading to Cross-Site Scripting (XSS) discovered in tarteaucitron.js – Cookies legislation & GDPR WordPress plugin (versions <= 1.5.4), vulnerable parameters "tarteaucitronEmail" and "tarteaucitronPass".Show less
1Iorder Project
1Iorder
Jun 17, 2026
Dec 20, 2021
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
An HTML Injection Vulnerability in iOrder 1.0 allows the remote attacker to execute Malicious HTML codes via the signup form
1Iorder Project
1Iorder
Jun 17, 2026
Dec 20, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Multiple Stored XSS Vulnerabilities in the Source Code of iOrder 1.0 allow remote attackers to execute arbitrary code via signup form in the Name and Phone number field.
1Iresturant Project
1Iresturant
Jun 17, 2026
Dec 20, 2021
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
RCE in Add Review Function in iResturant 1.0 Allows remote attacker to execute commands remotely
1Iresturant Project
1Iresturant
Jun 17, 2026
Dec 20, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Stored XSS in Signup Form in iResturant 1.0 Allows Remote Attacker to Inject Arbitrary code via NAME and ADDRESS field
1Opmantek
1Open Audit
Jun 17, 2026
Dec 20, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Opmantek Open-AudIT Community 4.2.0 (Fixed in 4.3.0) is affected by a Cross Site Scripting (XSS) vulnerability. If a bad value is passed to the routine via a URL, malicious JavaScript code can be executed in the victim's...Show more
Opmantek Open-AudIT Community 4.2.0 (Fixed in 4.3.0) is affected by a Cross Site Scripting (XSS) vulnerability. If a bad value is passed to the routine via a URL, malicious JavaScript code can be executed in the victim's browser.Show less
1Gurock
1Testrail
Jun 17, 2026
Dec 20, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Gurock TestRail before 7.2.4 mishandles HTML escaping.
1Chinasea
1Qb Smart Service Robot
Jun 17, 2026
Dec 20, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Chain Sea ai chatbot backend has improper filtering of special characters in URL parameters, which allows a remote attacker to perform JavaScript injection for XSS (reflected Cross-site scripting) attack without authenti...Show more
Chain Sea ai chatbot backend has improper filtering of special characters in URL parameters, which allows a remote attacker to perform JavaScript injection for XSS (reflected Cross-site scripting) attack without authentication.Show less
1Ibm
2Business Automation Workflow
Business Process Manager
Jun 17, 2026
Dec 17, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM Business Automation Workflow 18.0, 19.0, 20,0 and 21.0 and IBM Business Process Manager 8.5 and 8.6 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the We...Show more
IBM Business Automation Workflow 18.0, 19.0, 20,0 and 21.0 and IBM Business Process Manager 8.5 and 8.6 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 209165.Show less
1Convos
1Convos
Jun 17, 2026
Dec 17, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A Stored Cross Site Scripting (XSS) issue exists in Convos-Chat before 6.32.
1Livehelperchat
1Live Helper Chat
Jun 17, 2026
Dec 17, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
livehelperchat is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
1Wechat Php Sdk Project
1Wechat Php Sdk
Jun 17, 2026
Dec 17, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Wechat-php-sdk v1.10.2 is affected by a Cross Site Scripting (XSS) vulnerability in Wechat.php.
1Phpgurukul
1Bus Pass Management System
Jun 17, 2026
Dec 16, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
In Bus Pass Management System v1.0, parameters 'pagedes' and `About Us` are affected with a Stored Cross-site scripting vulnerability.
1Galette
1Galette
Jun 17, 2026
Dec 16, 2021
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Galette is a membership management web application built for non profit organizations and released under GPLv3. Versions prior to 0.9.6 are subject to stored cross site scripting attacks via the preferences footer. The p...Show more
Galette is a membership management web application built for non profit organizations and released under GPLv3. Versions prior to 0.9.6 are subject to stored cross site scripting attacks via the preferences footer. The preference footer can only be altered by a site admin. This issue has been resolved in the 0.9.6 release and all users are advised to upgrade. There are no known workarounds.Show less
1Vehicle Service Management System Project
1Vehicle Service Management System
Jun 17, 2026
Dec 16, 2021
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Cross Site Scripting (XSS) vulnerability exists in Sourcecodester Vehicle Service Management System 1.0 via the Owner fullname parameter in a Send Service Request in vehicle_service.