← Back
CWE-79

47,687 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (47,687)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Webnus
1Modern Events Calendar Lite
Jun 17, 2026
Dec 13, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Modern Events Calendar Lite WordPress plugin before 6.1.5 does not sanitise and escape the current_month_divider parameter of its mec_list_load_more AJAX call (available to both unauthenticated and authenticated user...Show more
The Modern Events Calendar Lite WordPress plugin before 6.1.5 does not sanitise and escape the current_month_divider parameter of its mec_list_load_more AJAX call (available to both unauthenticated and authenticated users) before outputting it back in the response, leading to a Reflected Cross-Site Scripting issueShow less
1Calderaforms
1Caldera Forms
Jun 17, 2026
Dec 13, 2021
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The Caldera Forms WordPress plugin before 1.9.5 does not sanitise and escape the Form Name before outputting it in attributes, which could allow high privilege users to perform Cross-Site Scripting attacks even when the...Show more
The Caldera Forms WordPress plugin before 1.9.5 does not sanitise and escape the Form Name before outputting it in attributes, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.Show less
1Get Custom Field Values Project
1Get Custom Field Values
Jun 17, 2026
Dec 13, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The Get Custom Field Values WordPress plugin before 4.0.1 does not escape custom fields before outputting them in the page, which could allow users with a role as low as contributor to perform Cross-Site Scripting attack...Show more
The Get Custom Field Values WordPress plugin before 4.0.1 does not escape custom fields before outputting them in the page, which could allow users with a role as low as contributor to perform Cross-Site Scripting attacksShow less
1Display Post Metadata Project
1Display Post Metadata
Jun 17, 2026
Dec 13, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The Display Post Metadata WordPress plugin before 1.5.0 adds a shortcode to print out custom fields, however their content is not sanitised or escaped which could allow users with a role as low as Contributor to perform...Show more
The Display Post Metadata WordPress plugin before 1.5.0 adds a shortcode to print out custom fields, however their content is not sanitised or escaped which could allow users with a role as low as Contributor to perform Cross-Site Scripting attacksShow less
1Ultimate Nofollow Project
1Ultimate Nofollow
Jun 17, 2026
Dec 13, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The Ultimate NoFollow WordPress plugin through 1.4.8 does not sanitise and escape the href attribute of its shortcodes, allowing users with a role as low as contributor to perform Cross-Site Scripting attacks
1Wpeden
1Shiny Buttons
Jun 17, 2026
Dec 13, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Shiny Buttons WordPress plugin through 1.1.0 does not have any authorisation and CSRF in place when saving a template (wpbtn_save_template function hooked to the init action), nor sanitise and escape them before outp...Show more
The Shiny Buttons WordPress plugin through 1.1.0 does not have any authorisation and CSRF in place when saving a template (wpbtn_save_template function hooked to the init action), nor sanitise and escape them before outputting them in the admin dashboard, which allow unauthenticated users to add a malicious template and lead to Stored Cross-Site Scripting issues.Show less
1Flex Local Fonts Project
1Flex Local Fonts
Jun 17, 2026
Dec 13, 2021
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The Flex Local Fonts WordPress plugin through 1.0.0 does not escape the Class Name field when adding a font, which could allow hight privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html c...Show more
The Flex Local Fonts WordPress plugin through 1.0.0 does not escape the Class Name field when adding a font, which could allow hight privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.Show less
1Inspirational Quote Rotator Project
1Inspirational Quote Rotator
Jun 17, 2026
Dec 13, 2021
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The Inspirational Quote Rotator WordPress plugin through 1.0.0 does not sanitize and escape some of its quote fields when adding/editing a quote as admin, leading to Stored Cross-Site scripting issues when the quote is o...Show more
The Inspirational Quote Rotator WordPress plugin through 1.0.0 does not sanitize and escape some of its quote fields when adding/editing a quote as admin, leading to Stored Cross-Site scripting issues when the quote is output in the "Quotes list" even when the unfiltered_html capability is disallowedShow less
1Wp System Log Project
1Wp System Log
Jun 17, 2026
Dec 13, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The WP System Log WordPress plugin before 1.0.21 does not sanitise, validate and escape the IP address retrieved from login requests before outputting them in the admin dashboard, which could allow unauthenticated attack...Show more
The WP System Log WordPress plugin before 1.0.21 does not sanitise, validate and escape the IP address retrieved from login requests before outputting them in the admin dashboard, which could allow unauthenticated attacker to perform Cross-Site Scripting attacks against admins viewing the logs.Show less
1Comment Engine Pro Project
1Comment Engine Pro
Jun 17, 2026
Dec 10, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Stored Cross-Site Scripting (XSS) vulnerability discovered in WordPress Comment Engine Pro plugin (versions <= 1.0), could be exploited by users with Editor or higher role.
1Pimcore
1Pimcore
Jun 17, 2026
Dec 10, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
pimcore is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
1Pimcore
1Pimcore
Jun 17, 2026
Dec 10, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
pimcore is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
1Zzzcms
1Zzzcms
Jun 17, 2026
Dec 9, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A Cross Site Scripting (XSS) exists in ZZZCMS V1.7.1 via an editfile action in save.php.
1Mcafee
1Network Security Manager
Jun 17, 2026
Dec 9, 2021
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Cross Site Scripting (XSS) vulnerability in McAfee Network Security Manager (NSM) prior to 10.1 Minor 7 allows a remote authenticated administrator to embed a XSS in the administrator interface via specially crafted cust...Show more
Cross Site Scripting (XSS) vulnerability in McAfee Network Security Manager (NSM) prior to 10.1 Minor 7 allows a remote authenticated administrator to embed a XSS in the administrator interface via specially crafted custom rules containing HTML. NSM did not correctly sanitize custom rule content in all scenarios.Show less
1Globaldatingsoftware
1Premiumdatingscript
Jun 17, 2026
Dec 9, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A reflected Cross Site Scripting (XSS) vulnerability exists in Premiumdatingscript 4.2.7.7 via the aerror_description parameter in assets/sources/instagram.php script.
1Gryphonconnect
1Gryphon Tower Firmware
Jun 17, 2026
Dec 9, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A reflected cross-site scripting vulnerability exists in the url parameter of the /cgi-bin/luci/site_access/ page on the Gryphon Tower router's web interface. An attacker could exploit this issue by tricking a user into...Show more
A reflected cross-site scripting vulnerability exists in the url parameter of the /cgi-bin/luci/site_access/ page on the Gryphon Tower router's web interface. An attacker could exploit this issue by tricking a user into following a specially crafted link, granting the attacker javascript execution in the context of the victim's browser.Show less
1Mozilla
1Firefox
Jun 17, 2026
Dec 8, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
When receiving a URL through a SEND intent, Firefox would have searched for the text, but subsequent usages of the address bar might have caused the URL to load unintentionally, which could lead to XSS and spoofing attac...Show more
When receiving a URL through a SEND intent, Firefox would have searched for the text, but subsequent usages of the address bar might have caused the URL to load unintentionally, which could lead to XSS and spoofing attacks. *This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 95.Show less
2Debian
Mozilla
4Debian Linux
FirefoxFirefox Esr+1 more
Jun 17, 2026
Dec 8, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Documents loaded with the CSP sandbox directive could have escaped the sandbox's script restriction by embedding additional content. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95...Show more
Documents loaded with the CSP sandbox directive could have escaped the sandbox's script restriction by embedding additional content. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95.Show less
1Mozilla
1Firefox
Jun 17, 2026
Dec 8, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A Universal XSS vulnerability was present in Firefox for Android resulting from improper sanitization when processing a URL scanned from a QR code. *This bug only affects Firefox for Android. Other operating systems are...Show more
A Universal XSS vulnerability was present in Firefox for Android resulting from improper sanitization when processing a URL scanned from a QR code. *This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 94.Show less
1Bosch
2Bosch Video Management System
Video Recording Manager
Jun 17, 2026
Dec 8, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An error in a page handler of the VRM may lead to a reflected cross site scripting (XSS) in the web-based interface. To exploit this vulnerability an attack must be able to modify the HTTP header that is sent. This issue...Show more
An error in a page handler of the VRM may lead to a reflected cross site scripting (XSS) in the web-based interface. To exploit this vulnerability an attack must be able to modify the HTTP header that is sent. This issue also affects installations of the DIVAR IP and BVMS with VRM installed.Show less