← Back
CWE-79

47,683 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (47,683)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Yetiforce
1Yetiforce Customer Relationship Management
Jun 17, 2026
Dec 14, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
yetiforcecrm is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
1Abantecart
1Abantecart
Jun 17, 2026
Dec 14, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
An issue was discovered in AbanteCart before 1.3.2. Any low-privileged user with file-upload permissions can upload a malicious SVG document that contains an XSS payload.
1Abantecart
1Abantecart
Jun 17, 2026
Dec 14, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in AbanteCart before 1.3.2. It allows DOM Based XSS.
1Gnuboard
1Gnuboard5
Jun 17, 2026
Dec 14, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
gnuboard5 is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
1Zzcms
1Zzcms
Jun 17, 2026
Dec 13, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross Site Scripting (XSS) vulnerability exists in zzcms 2019 XSS via a modify action in user/adv.php.
1Collabora
1Online
Jun 17, 2026
Dec 13, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Collabora Online is a collaborative online office suite based on LibreOffice technology. In affected versions a reflected XSS vulnerability was found in Collabora Online. An attacker could inject unescaped HTML into a va...Show more
Collabora Online is a collaborative online office suite based on LibreOffice technology. In affected versions a reflected XSS vulnerability was found in Collabora Online. An attacker could inject unescaped HTML into a variable as they created the Collabora Online iframe, and execute scripts inside the context of the Collabora Online iframe. This would give access to a small set of user settings stored in the browser, as well as the session's authentication token which was also passed in at iframe creation time. Users should upgrade to Collabora Online 6.4.16 or higher or Collabora Online 4.2.20 or higher. Collabora Online Development Edition 21.11 is not affected.Show less
5Debian
FedoraprojectLxml+2 more
11Communications Cloud Native Core Binding Support Function
Communications Cloud Native Core Network Exposure FunctionCommunications Cloud Native Core Policy+8 more
Jun 17, 2026
Dec 13, 2021
N/A· v4
7.1 HIGH· v3
6.8 MEDIUM· v2
lxml is a library for processing XML and HTML in the Python language. Prior to version 4.6.5, the HTML Cleaner in lxml.html lets certain crafted script content pass through, as well as script content in SVG files embedde...Show more
lxml is a library for processing XML and HTML in the Python language. Prior to version 4.6.5, the HTML Cleaner in lxml.html lets certain crafted script content pass through, as well as script content in SVG files embedded using data URIs. Users that employ the HTML cleaner in a security relevant context should upgrade to lxml 4.6.5 to receive a patch. There are no known workarounds available.Show less
1Gitlab
1Gitlab
Jun 17, 2026
Dec 13, 2021
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.6 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. GitLab was vulnerable to...Show more
An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.6 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. GitLab was vulnerable to HTML Injection through the Swagger UI feature.Show less
1Wpcloudplugins
1Lets Box
Jun 17, 2026
Dec 13, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Insufficient Input Validation in the search functionality of Wordpress plugin Lets-Box prior to 1.15.3 allows unauthenticated user to craft a reflected Cross-Site Scripting attack.
1Wpcloudplugins
1Share One Drive
Jun 17, 2026
Dec 13, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Insufficient Input Validation in the search functionality of Wordpress plugin Share-one-Drive prior to 1.15.3 allows unauthenticated user to craft a reflected Cross-Site Scripting attack.
1Wpcloudplugins
1Out Of The Box
Jun 17, 2026
Dec 13, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Insufficient Input Validation in the search functionality of Wordpress plugin Out-of-the-Box prior to 1.20.3 allows unauthenticated user to craft a reflected Cross-Site Scripting attack.
1Wpcloudplugins
1Use Your Drive
Jun 17, 2026
Dec 13, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Insufficient Input Validation in the search functionality of Wordpress plugin Use-Your-Drive prior to 1.18.3 allows unauthenticated user to craft a reflected Cross-Site Scripting attack.
1Fatcatapps
1Pixel Cat
Jun 17, 2026
Dec 13, 2021
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The Pixel Cat WordPress plugin before 2.6.3 does not escape some of its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed
1Profilepress
1User Registration, Login Form, User Profile & Membership
Jun 17, 2026
Dec 13, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The User Registration, Login Form, User Profile & Membership WordPress plugin before 3.2.3 does not escape the data parameter of the pp_get_forms_by_builder_type AJAX action before outputting it back in an attribute, lea...Show more
The User Registration, Login Form, User Profile & Membership WordPress plugin before 3.2.3 does not escape the data parameter of the pp_get_forms_by_builder_type AJAX action before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting issueShow less
1Profilepress
1User Registration, Login Form, User Profile & Membership
Jun 17, 2026
Dec 13, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The User Registration, Login Form, User Profile & Membership WordPress plugin before 3.2.3 does not sanitise and escape the ppress_cc_data parameter before outputting it back in an attribute of an admin dashboard page, l...Show more
The User Registration, Login Form, User Profile & Membership WordPress plugin before 3.2.3 does not sanitise and escape the ppress_cc_data parameter before outputting it back in an attribute of an admin dashboard page, leading to a Reflected Cross-Site Scripting issueShow less
1Cm Wp
1Auto Featured Image
Jun 17, 2026
Dec 13, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Auto Featured Image (Auto Post Thumbnail) WordPress plugin before 3.9.3 does not sanitise and escape the post_id parameter before outputting back in an admin page within a JS block, leading to a Reflected Cross-Site...Show more
The Auto Featured Image (Auto Post Thumbnail) WordPress plugin before 3.9.3 does not sanitise and escape the post_id parameter before outputting back in an admin page within a JS block, leading to a Reflected Cross-Site Scripting issue.Show less
1Webnus
1Modern Events Calendar Lite
Jun 17, 2026
Dec 13, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Modern Events Calendar Lite WordPress plugin before 6.1.5 does not sanitise and escape the current_month_divider parameter of its mec_list_load_more AJAX call (available to both unauthenticated and authenticated user...Show more
The Modern Events Calendar Lite WordPress plugin before 6.1.5 does not sanitise and escape the current_month_divider parameter of its mec_list_load_more AJAX call (available to both unauthenticated and authenticated users) before outputting it back in the response, leading to a Reflected Cross-Site Scripting issueShow less
1Calderaforms
1Caldera Forms
Jun 17, 2026
Dec 13, 2021
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The Caldera Forms WordPress plugin before 1.9.5 does not sanitise and escape the Form Name before outputting it in attributes, which could allow high privilege users to perform Cross-Site Scripting attacks even when the...Show more
The Caldera Forms WordPress plugin before 1.9.5 does not sanitise and escape the Form Name before outputting it in attributes, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.Show less
1Get Custom Field Values Project
1Get Custom Field Values
Jun 17, 2026
Dec 13, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The Get Custom Field Values WordPress plugin before 4.0.1 does not escape custom fields before outputting them in the page, which could allow users with a role as low as contributor to perform Cross-Site Scripting attack...Show more
The Get Custom Field Values WordPress plugin before 4.0.1 does not escape custom fields before outputting them in the page, which could allow users with a role as low as contributor to perform Cross-Site Scripting attacksShow less
1Display Post Metadata Project
1Display Post Metadata
Jun 17, 2026
Dec 13, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The Display Post Metadata WordPress plugin before 1.5.0 adds a shortcode to print out custom fields, however their content is not sanitised or escaped which could allow users with a role as low as Contributor to perform...Show more
The Display Post Metadata WordPress plugin before 1.5.0 adds a shortcode to print out custom fields, however their content is not sanitised or escaped which could allow users with a role as low as Contributor to perform Cross-Site Scripting attacksShow less