CWE-79
47,712 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (47,712)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Youtube Php Mirroring Project 1Youtube Php Mirroring Jun 17, 2026 Nov 29, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 youtube-php-mirroring (last update Jun 9, 2017) is affected by a Cross Site Scripting (XSS) vulnerability in file ytproxy/index.php. |
issabelPBX version 2.11 is affected by a Cross Site Scripting (XSS) vulnerability. In file page.backup_restore.php, the exit function will terminate the script and print the message to the user. The message will contain...Show more |
1Workerman Thinkphp Redis Project 1Workerman Thinkphp Redis Jun 17, 2026 Nov 29, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Workerman-ThinkPHP-Redis (last update Mar 16, 2018) is affected by a Cross Site Scripting (XSS) vulnerability. In file Controller.class.php, the exit function will terminate the script and print the message to the user....Show more |
twmap v2.91_v4.33 is affected by a Cross Site Scripting (XSS) vulnerability. In file list.php, the exit function will terminate the script and print the message to the user. The message will contain $_REQUEST then there...Show more |
phpWhois (last update Jun 30 2021) is affected by a Cross Site Scripting (XSS) vulnerability. In file example.php, the exit function will terminate the script and print the message to the user. The message will contain $...Show more |
1My Calendar Project 1My Calendar Jun 17, 2026 Nov 29, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 The My Calendar WordPress plugin before 3.2.18 does not sanitise and escape the callback parameter of the mc_post_lookup AJAX action (available to any authenticated user) before outputting it back in the response, leadin...Show more |
1Smashballoon 1Smash Balloon Social Post Feed Jun 17, 2026 Nov 29, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 The Smash Balloon Social Post Feed WordPress plugin before 4.0.1 did not have any privilege or nonce validation before saving the plugin's setting. As a result, any logged-in user on a vulnerable site could update the se...Show more |
The Check & Log Email WordPress plugin before 1.0.4 does not escape the d parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting |
1Media Tags Project 1Media Tags Jun 17, 2026 Nov 29, 2021 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 The Media-Tags WordPress plugin through 3.2.0.2 does not sanitise and escape any of its Labels settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_htnl capabi...Show more |
1Essentialplugin 1Popup Anything Jun 17, 2026 Nov 29, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 The Popup Anything WordPress plugin before 2.0.4 does not escape the Link Text and Button Text fields of Popup, which could allow users with a role as low as Contributor to perform Cross-Site Scripting attacks |
1Roundupwp 1Registrations For The Events Calendar Jun 17, 2026 Nov 29, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The Registrations for the Events Calendar WordPress plugin before 2.7.5 does not escape the v parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting |
1Stylishcostcalculator 1Stylish Cost Calculator Jun 17, 2026 Nov 29, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 The Stylish Cost Calculator WordPress plugin before 7.0.4 does not have any authorisation and CSRF checks on some of its AJAX actions (available to authenticated users), which could allow any authenticated users, such as...Show more |
The Shop Page WP WordPress plugin before 1.2.8 does not sanitise and escape some of the Product fields, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is di...Show more |
1Wprssaggregator 1Wp Rss Aggregator Jun 17, 2026 Nov 29, 2021 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 The WP RSS Aggregator WordPress plugin before 4.19.2 does not properly sanitise and escape the URL to Blacklist field, allowing malicious HTML to be inserted by high privilege users even when the unfiltered_html capabili...Show more |
1Generateblocks 1Generateblocks Jun 17, 2026 Nov 29, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 The GenerateBlocks WordPress plugin before 1.4.0 does not validate the generateblocks/container block's tagName attribute, which could allow users with a role as low as contributor to perform Cross-Site Scripting attacks...Show more |
The About Author Box WordPress plugin before 1.0.2 does not sanitise and escape the Social Profiles field values before outputting them in attributes, which could allow user with a role as low as contributor to perform C...Show more |
The myCred WordPress plugin before 1.7.8 does not sanitise and escape the user parameter before outputting it back in the Points Log admin dashboard, leading to a Reflected Cross-Site Scripting |
janus-gateway is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
1Emoji Button Project 1Emoji Button Jun 17, 2026 Nov 26, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 @joeattardi/emoji-button is a Vanilla JavaScript emoji picker component. In affected versions there are two vectors for XSS attacks: a URL for a custom emoji, and an i18n string. In both of these cases, a value can be cr...Show more |
1Linuxfoundation 1Auth Backend Jun 17, 2026 Nov 26, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Backstage is an open platform for building developer portals. In affected versions the auth-backend plugin allows a malicious actor to trick another user into visiting a vulnerable URL that executes an XSS attack. This a...Show more |