CWE-79
47,713 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (47,713)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Linuxfoundation 1Auth Backend Jun 17, 2026 Nov 26, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Backstage is an open platform for building developer portals. In affected versions the auth-backend plugin allows a malicious actor to trick another user into visiting a vulnerable URL that executes an XSS attack. This a...Show more |
1Getawesomesupport 1Awesome Support Jun 17, 2026 Nov 26, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 Multiple Authenticated Reflected Cross-Site Scripting (XSS) vulnerabilities in WordPress Awesome Support plugin (versions <= 6.0.6), vulnerable parameters (&id, &assignee). |
1Acurax 1Floating Social Media Icon Jun 17, 2026 Nov 26, 2021 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 Authenticated Stored Cross-Site Scripting (XSS) vulnerability discovered in WordPress Floating Social Media Icon plugin (versions <= 4.3.5) Social Media Configuration form. Requires high role user like admin. |
Cross-site scripting vulnerability in rwtxt versions prior to v1.8.6 allows a remote attacker to inject an arbitrary script via unspecified vectors. |
1Saasproject 1Booking Package Jun 17, 2026 Nov 24, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Cross-site scripting vulnerability in Booking Package - Appointment Booking Calendar System versions prior to 1.5.11 allows a remote attacker to inject an arbitrary script via unspecified vectors. |
A carefully crafted plugin link invocation could trigger an XSS vulnerability on Apache JSPWiki, related to the Denounce plugin, which could allow the attacker to execute javascript in the victim's browser and get some s...Show more |
3Debian FedoraprojectGoogle3Chrome Debian LinuxFedoraJun 17, 2026 Nov 23, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Insufficient data validation in New Tab Page in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to inject arbitrary scripts or HTML in a new browser tab via a crafted HTML page. |
A Reflected Cross-Site Scripting vulnerability in McAfee Policy Auditor prior to 6.5.2 allows a remote unauthenticated attacker to inject arbitrary web script or HTML via the UID request parameter. The malicious script i...Show more |
A Reflected Cross-Site Scripting vulnerability in McAfee Policy Auditor prior to 6.5.2 allows a remote unauthenticated attacker to inject arbitrary web script or HTML via the profileNodeID request parameters. The malicio...Show more |
1Django Wiki Project 1Django Wiki Jun 17, 2026 Nov 23, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 In Django-wiki, versions 0.0.20 to 0.7.8 are vulnerable to Stored Cross-Site Scripting (XSS) in Notifications Section. An attacker who has access to edit pages can inject JavaScript payload in the title field. When a vic...Show more |
The Elementor Website Builder WordPress plugin before 3.4.8 does not sanitise or escape user input appended to the DOM via a malicious hash, resulting in a DOM Cross-Site Scripting issue. |
The ImageBoss WordPress plugin before 3.0.6 does not sanitise and escape its Source Name setting, which could allow high privilege users to perform Cross-Site Scripting attacks |
The Slideshow Gallery WordPress plugin before 1.7.4 does not sanitise and escape the Slide "Title", "Description", and Gallery "Title" fields, which could allow high privilege users to perform Cross-Site Scripting attack...Show more |
1Implecode 1Ecommerce Product Catalog Jun 17, 2026 Nov 23, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The eCommerce Product Catalog Plugin for WordPress plugin before 3.0.39 does not escape the ic-settings-search parameter before outputting it back in the page in an attribute, leading to a Reflected Cross-Site Scripting...Show more |
The Tutor LMS WordPress plugin before 1.9.11 does not sanitise and escape user input before outputting back in attributes in the Student Registration page, leading to a Reflected Cross-Site Scripting issue |
1Vasyltech 1Advanced Access Manager Jun 17, 2026 Nov 23, 2021 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 The Advanced Access Manager WordPress plugin before 6.8.0 does not escape some of its settings when outputting them, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html cap...Show more |
The BetterLinks WordPress plugin before 1.2.6 does not sanitise and escape some of imported link fields, which could lead to Stored Cross-Site Scripting issues when an admin import a malicious CSV. |
1Infornweb 1Logo Showcase With Slick Slider Jun 17, 2026 Nov 23, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 The Logo Showcase with Slick Slider WordPress plugin before 1.2.4 does not sanitise the Grid Settings, which could allow users with a role as low as Author to perform stored Cross-Site Scripting attacks via post metadata...Show more |
1Cminds 2Video Lessons Manager Video Lessons Manager ProAug 24, 2026 Nov 23, 2021 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 The Video Lessons Manager WordPress plugin before 1.7.2 and Video Lessons Manager Pro WordPress plugin before 3.5.9 do not properly sanitize and escape values when updating their settings, which could allow high privileg...Show more |
The Forminator WordPress plugin before 1.15.4 does not sanitize and escape the email field label, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed |