CWE-79
47,687 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (47,687)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Webnus 1Modern Events Calendar Lite Jun 17, 2026 Dec 13, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The Modern Events Calendar Lite WordPress plugin before 6.1.5 does not sanitise and escape the current_month_divider parameter of its mec_list_load_more AJAX call (available to both unauthenticated and authenticated user...Show more |
The Caldera Forms WordPress plugin before 1.9.5 does not sanitise and escape the Form Name before outputting it in attributes, which could allow high privilege users to perform Cross-Site Scripting attacks even when the...Show more |
1Get Custom Field Values Project 1Get Custom Field Values Jun 17, 2026 Dec 13, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 The Get Custom Field Values WordPress plugin before 4.0.1 does not escape custom fields before outputting them in the page, which could allow users with a role as low as contributor to perform Cross-Site Scripting attack...Show more |
1Display Post Metadata Project 1Display Post Metadata Jun 17, 2026 Dec 13, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 The Display Post Metadata WordPress plugin before 1.5.0 adds a shortcode to print out custom fields, however their content is not sanitised or escaped which could allow users with a role as low as Contributor to perform...Show more |
1Ultimate Nofollow Project 1Ultimate Nofollow Jun 17, 2026 Dec 13, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 The Ultimate NoFollow WordPress plugin through 1.4.8 does not sanitise and escape the href attribute of its shortcodes, allowing users with a role as low as contributor to perform Cross-Site Scripting attacks |
The Shiny Buttons WordPress plugin through 1.1.0 does not have any authorisation and CSRF in place when saving a template (wpbtn_save_template function hooked to the init action), nor sanitise and escape them before outp...Show more |
1Flex Local Fonts Project 1Flex Local Fonts Jun 17, 2026 Dec 13, 2021 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 The Flex Local Fonts WordPress plugin through 1.0.0 does not escape the Class Name field when adding a font, which could allow hight privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html c...Show more |
1Inspirational Quote Rotator Project 1Inspirational Quote Rotator Jun 17, 2026 Dec 13, 2021 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 The Inspirational Quote Rotator WordPress plugin through 1.0.0 does not sanitize and escape some of its quote fields when adding/editing a quote as admin, leading to Stored Cross-Site scripting issues when the quote is o...Show more |
1Wp System Log Project 1Wp System Log Jun 17, 2026 Dec 13, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The WP System Log WordPress plugin before 1.0.21 does not sanitise, validate and escape the IP address retrieved from login requests before outputting them in the admin dashboard, which could allow unauthenticated attack...Show more |
1Comment Engine Pro Project 1Comment Engine Pro Jun 17, 2026 Dec 10, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 Stored Cross-Site Scripting (XSS) vulnerability discovered in WordPress Comment Engine Pro plugin (versions <= 1.0), could be exploited by users with Editor or higher role. |
pimcore is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
pimcore is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
A Cross Site Scripting (XSS) exists in ZZZCMS V1.7.1 via an editfile action in save.php. |
1Mcafee 1Network Security Manager Jun 17, 2026 Dec 9, 2021 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 Cross Site Scripting (XSS) vulnerability in McAfee Network Security Manager (NSM) prior to 10.1 Minor 7 allows a remote authenticated administrator to embed a XSS in the administrator interface via specially crafted cust...Show more |
1Globaldatingsoftware 1Premiumdatingscript Jun 17, 2026 Dec 9, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 A reflected Cross Site Scripting (XSS) vulnerability exists in Premiumdatingscript 4.2.7.7 via the aerror_description parameter in assets/sources/instagram.php script. |
1Gryphonconnect 1Gryphon Tower Firmware Jun 17, 2026 Dec 9, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 A reflected cross-site scripting vulnerability exists in the url parameter of the /cgi-bin/luci/site_access/ page on the Gryphon Tower router's web interface. An attacker could exploit this issue by tricking a user into...Show more |
When receiving a URL through a SEND intent, Firefox would have searched for the text, but subsequent usages of the address bar might have caused the URL to load unintentionally, which could lead to XSS and spoofing attac...Show more |
2Debian Mozilla4Debian Linux FirefoxFirefox Esr+1 moreJun 17, 2026 Dec 8, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Documents loaded with the CSP sandbox directive could have escaped the sandbox's script restriction by embedding additional content. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95...Show more |
A Universal XSS vulnerability was present in Firefox for Android resulting from improper sanitization when processing a URL scanned from a QR code. *This bug only affects Firefox for Android. Other operating systems are...Show more |
1Bosch 2Bosch Video Management System Video Recording ManagerJun 17, 2026 Dec 8, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 An error in a page handler of the VRM may lead to a reflected cross site scripting (XSS) in the web-based interface. To exploit this vulnerability an attack must be able to modify the HTTP header that is sent. This issue...Show more |