CWE-79
47,692 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (47,692)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Wso2 4Api Manager Identity ServerIdentity Server As Key Manager+1 moreJun 17, 2026 Dec 7, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 In accountrecoveryendpoint/recoverpassword.do in WSO2 Identity Server 5.7.0, it is possible to perform a DOM-Based XSS attack affecting the callback parameter modifying the URL that precedes the callback parameter. Once...Show more |
1Debug Meta Data Project 1Debug Meta Data Jun 17, 2026 Dec 7, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 The debug-meta-data plugin 1.1.2 for WordPress allows XSS. |
1Racktables Project 1Racktables Jul 9, 2026 Dec 7, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Cross Site Scripting (XSS) in redirect module of Racktables version 0.21.2, allows an attacker to inject arbitrary web script or HTML via the op parameter. |
A cross-site scripting (XSS) vulnerability in integration configuration in SquaredUp for SCOM 5.2.1.6654 allows remote attackers to inject arbitrary web script or HTML via modification of the authorisationUrl in some int...Show more |
A DOM-based XSS vulnerability affects SquaredUp for SCOM 5.2.1.6654. If successfully exploited, this vulnerability may allow attackers to inject malicious code into a user's device. |
A cross-site scripting (XSS) vulnerability in integration configuration in SquaredUp for SCOM 5.2.1.6654 allows remote attackers to inject arbitrary web script or HTML via dashboard actions. |
A cross-site scripting (XSS) vulnerability in Image Tile in SquaredUp for SCOM 5.2.1.6654 allows remote attackers to inject arbitrary web script or HTML via an SVG file. |
A stored Cross Site Scripting (XSS) vulnerability in Esri ArcGIS Server feature services versions 10.8.1 and 10.9 (only) feature services may allow a remote, unauthenticated attacker to pass and store malicious strings v...Show more |
The Photo Gallery by 10Web WordPress plugin before 1.5.68 is vulnerable to Reflected Cross-Site Scripting (XSS) issues via the bwg_album_breadcrumb_0 and shortcode_id GET parameters passed to the bwg_frontend_data AJAX a...Show more |
The LoginWP (Formerly Peter's Login Redirect) WordPress plugin before 3.0.0.5 does not sanitise and escape the rul_login_url and rul_logout_url parameter before outputting them back in attributes in an admin page, leadin...Show more |
1Woocommerce 1Woocommerce Currency Switcher Jun 17, 2026 Dec 6, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The WOOCS WordPress plugin before 1.3.7.1 does not sanitise and escape the key parameter of the woocs_update_profiles_data AJAX action (available to any authenticated user) before outputting it back in the response, lead...Show more |
1Wp Google Fonts Project 1Wp Google Fonts Jun 17, 2026 Dec 6, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The WP Google Fonts WordPress plugin before 3.1.5 does not escape the googlefont_ajax_name and googlefont_ajax_family parameter of the googlefont_action AJAx action (available to any authenticated user) before outputing...Show more |
The WordPress Online Booking and Scheduling Plugin WordPress plugin before 20.3.1 does not escape the Staff Full Name field before outputting it back in a page, which could lead to a Stored Cross-Site Scripting issue |
1Email Log Project 1Email Log Jun 17, 2026 Dec 6, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The Email Log WordPress plugin before 2.4.8 does not escape the d parameter before outputting it back in an attribute in the Log page, leading to a Reflected Cross-Site Scripting issue |
1Pdf.js Viewer Project 1Pdf.js Viewer Jun 17, 2026 Dec 6, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 The PDF.js Viewer WordPress plugin before 2.0.2 does not escape some of its shortcode and Gutenberg Block attributes, which could allow users with a role as low as Contributor to to perform Cross-Site Scripting attacks |
1Reputeinfosystems 1Contact Form, Survey & Popup Form Plugin For Wordpress Arforms Form Builder Jun 17, 2026 Dec 6, 2021 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 The Contact Form, Survey & Popup Form Plugin for WordPress plugin before 1.5 does not properly sanitize some of its settings allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_...Show more |
The Import any XML or CSV File to WordPress plugin before 3.6.3 does not escape the Import's Title and Unique Identifier fields before outputting them in admin pages, which could allow high privilege users to perform Cro...Show more |
A stored cross-site scripting (XSS) vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the course "Title" and "Content" fields. |
2Ibm Netapp2Cognos Analytics Oncommand InsightJun 17, 2026 Dec 3, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 IBM Cognos Analytics 11.1.7 and 11.2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading...Show more |
2Ibm Netapp2Cognos Analytics Oncommand InsightJun 17, 2026 Dec 3, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 IBM Cognos Analytics 11.1.7 and 11.2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading...Show more |