CWE-79
47,683 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (47,683)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Socomec 1Remote View Pro Firmware Jun 17, 2026 Dec 15, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 An issue was discovered in Socomec REMOTE VIEW PRO 2.0.41.4. Improper validation of input into the username field makes it possible to place a stored XSS payload. This is executed if an administrator views the System Eve...Show more |
snipe-it is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
Owncast is an open source, self-hosted live video streaming and chat server. In affected versions inline scripts are executed when Javascript is parsed via a paste action. This issue is patched in 0.0.9 by blocking unsaf...Show more |
Cross-site scripting (XSS) vulnerability in /application/controller/admin/theme.php in LimeSurvey 3.6.2+180406 allows remote attackers to inject arbitrary web script or HTML via the changes_cp parameter to the index.php/...Show more |
An issue was discovered in UiPath App Studio 21.4.4. There is a persistent XSS vulnerability in the file-upload functionality for uploading icons when attempting to create new Apps. An attacker with minimal privileges in...Show more |
A Cross Site Scripting (XSS) vulnerability exists in Piwigo 11.5.0 via the system album name and description of the location. |
1Variation Swatches For Woocommerce Project 1Variation Swatches For Woocommerce Jun 17, 2026 Dec 14, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 The Variation Swatches for WooCommerce WordPress plugin is vulnerable to Stored Cross-Site Scripting via several parameters found in the ~/includes/class-menu-page.php file which allows attackers to inject arbitrary web...Show more |
A security vulnerability has been discovered in the SAP Knowledge Warehouse - versions 7.30, 7.31, 7.40, 7.50. The usage of one SAP KW component within a Web browser enables unauthorized attackers to conduct XSS attacks,...Show more |
1Sap 1Businessobjects Business Intelligence Platform Jun 17, 2026 Dec 14, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 SAP BusinessObjects Business Intelligence Platform (Web Intelligence) - version 420, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. This allows a low privilege...Show more |
The Fathom Analytics WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and escaping via the $site_id parameter found in the ~/fathom-analytics.php file which allowed attac...Show more |
1Duogeek 1Duofaq Responsive Flat Simple Faq Jun 17, 2026 Dec 14, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The duoFAQ - Responsive, Flat, Simple FAQ WordPess plugin is vulnerable to Reflected Cross-Site Scripting via the msg parameter found in the ~/duogeek/duogeek-panel.php file which allows attackers to inject arbitrary web...Show more |
1H5p Css Editor Project 1H5p Css Editor Jun 17, 2026 Dec 14, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The H5P CSS Editor WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the h5p-css-file parameter found in the ~/h5p-css-editor.php file which allows attackers to inject arbitrary web scripts, in version...Show more |
1Magic Post Voice Project 1Magic Post Voice Jun 17, 2026 Dec 14, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The Magic Post Voice WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the ids parameter found in the ~/inc/admin/main.php file which allows attackers to inject arbitrary web scripts, in versions up to...Show more |
1Wanderlust Webdesign 1Woo Enviopack Jun 17, 2026 Dec 14, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The WooCommerce EnvioPack WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the dataid parameter found in the ~/includes/functions.php file which allows attackers to inject arbitrary web scripts, in ve...Show more |
1Duogeek 1Simple Image Gallery Jun 17, 2026 Dec 14, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The Simple Image Gallery WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the msg parameter found in the ~/simple-image-gallery.php file which allows attackers to inject arbitrary web scripts, in vers...Show more |
1Link List Manager Project 1Link List Manager Jun 17, 2026 Dec 14, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The link-list-manager WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the category parameter found in the ~/llm.php file which allows attackers to inject arbitrary web scripts, in versions up to and...Show more |
The Real WYSIWYG WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to the use of PHP_SELF in the ~/real-wysiwyg.php file which allows attackers to inject arbitrary web scripts, in versions up to and in...Show more |
1Dpsoft 1Parsian Bank Gateway For Woocommerce Jun 17, 2026 Dec 14, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The Parsian Bank Gateway for Woocommerce WordPress plugin is vulnerable to Reflected Cross-Site Scripting via and parameter due to a var_dump() on $_POST variables found in the ~/vendor/dpsoft/parsian-payment/sample/roll...Show more |
1Woo Myghpay Payment Gateway Project 1Woo Myghpay Payment Gateway Jun 17, 2026 Dec 14, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The WooCommerce myghpay Payment Gateway WordPess plugin is vulnerable to Reflected Cross-Site Scripting via the clientref parameter found in the ~/processresponse.php file which allows attackers to inject arbitrary web s...Show more |
1Htaccess Redirect Project 1Htaccess Redirect Jun 17, 2026 Dec 14, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The .htaccess Redirect WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the link parameter found in the ~/htaccess-redirect.php file which allows attackers to inject arbitrary web scripts, in versions...Show more |