CWE-79
47,683 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (47,683)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Yetiforce 1Yetiforce Customer Relationship Management Jun 17, 2026 Dec 14, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 yetiforcecrm is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
An issue was discovered in AbanteCart before 1.3.2. Any low-privileged user with file-upload permissions can upload a malicious SVG document that contains an XSS payload. |
An issue was discovered in AbanteCart before 1.3.2. It allows DOM Based XSS. |
gnuboard5 is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
Cross Site Scripting (XSS) vulnerability exists in zzcms 2019 XSS via a modify action in user/adv.php. |
Collabora Online is a collaborative online office suite based on LibreOffice technology. In affected versions a reflected XSS vulnerability was found in Collabora Online. An attacker could inject unescaped HTML into a va...Show more |
5Debian FedoraprojectLxml+2 more11Communications Cloud Native Core Binding Support Function Communications Cloud Native Core Network Exposure FunctionCommunications Cloud Native Core Policy+8 moreJun 17, 2026 Dec 13, 2021 N/A· v4 7.1 HIGH· v3 6.8 MEDIUM· v2 lxml is a library for processing XML and HTML in the Python language. Prior to version 4.6.5, the HTML Cleaner in lxml.html lets certain crafted script content pass through, as well as script content in SVG files embedde...Show more |
An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.6 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. GitLab was vulnerable to...Show more |
Insufficient Input Validation in the search functionality of Wordpress plugin Lets-Box prior to 1.15.3 allows unauthenticated user to craft a reflected Cross-Site Scripting attack. |
1Wpcloudplugins 1Share One Drive Jun 17, 2026 Dec 13, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Insufficient Input Validation in the search functionality of Wordpress plugin Share-one-Drive prior to 1.15.3 allows unauthenticated user to craft a reflected Cross-Site Scripting attack. |
1Wpcloudplugins 1Out Of The Box Jun 17, 2026 Dec 13, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Insufficient Input Validation in the search functionality of Wordpress plugin Out-of-the-Box prior to 1.20.3 allows unauthenticated user to craft a reflected Cross-Site Scripting attack. |
1Wpcloudplugins 1Use Your Drive Jun 17, 2026 Dec 13, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Insufficient Input Validation in the search functionality of Wordpress plugin Use-Your-Drive prior to 1.18.3 allows unauthenticated user to craft a reflected Cross-Site Scripting attack. |
The Pixel Cat WordPress plugin before 2.6.3 does not escape some of its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed |
1Profilepress 1User Registration, Login Form, User Profile & Membership Jun 17, 2026 Dec 13, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The User Registration, Login Form, User Profile & Membership WordPress plugin before 3.2.3 does not escape the data parameter of the pp_get_forms_by_builder_type AJAX action before outputting it back in an attribute, lea...Show more |
1Profilepress 1User Registration, Login Form, User Profile & Membership Jun 17, 2026 Dec 13, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The User Registration, Login Form, User Profile & Membership WordPress plugin before 3.2.3 does not sanitise and escape the ppress_cc_data parameter before outputting it back in an attribute of an admin dashboard page, l...Show more |
The Auto Featured Image (Auto Post Thumbnail) WordPress plugin before 3.9.3 does not sanitise and escape the post_id parameter before outputting back in an admin page within a JS block, leading to a Reflected Cross-Site...Show more |
1Webnus 1Modern Events Calendar Lite Jun 17, 2026 Dec 13, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The Modern Events Calendar Lite WordPress plugin before 6.1.5 does not sanitise and escape the current_month_divider parameter of its mec_list_load_more AJAX call (available to both unauthenticated and authenticated user...Show more |
The Caldera Forms WordPress plugin before 1.9.5 does not sanitise and escape the Form Name before outputting it in attributes, which could allow high privilege users to perform Cross-Site Scripting attacks even when the...Show more |
1Get Custom Field Values Project 1Get Custom Field Values Jun 17, 2026 Dec 13, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 The Get Custom Field Values WordPress plugin before 4.0.1 does not escape custom fields before outputting them in the page, which could allow users with a role as low as contributor to perform Cross-Site Scripting attack...Show more |
1Display Post Metadata Project 1Display Post Metadata Jun 17, 2026 Dec 13, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 The Display Post Metadata WordPress plugin before 1.5.0 adds a shortcode to print out custom fields, however their content is not sanitised or escaped which could allow users with a role as low as Contributor to perform...Show more |