CWE-79
47,713 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (47,713)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Debian FedoraprojectRoundcube3Debian Linux FedoraWebmailJun 17, 2026 Nov 19, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to XSS in handling an attachment's filename extension when displaying a MIME type warning message. |
1Cisco 1Common Services Platform Collector Jun 17, 2026 Nov 19, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 A vulnerability in the web-based management interface of Cisco Common Services Platform Collector (CSPC) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the...Show more |
A remote authenticated attacker with write access to a PI Server could trick a user into interacting with a PI Web API endpoint and redirect them to a malicious website. As a result, a victim may disclose sensitive infor...Show more |
3Ckeditor DrupalOracle9Agile Product Lifecycle Management Application ExpressBanking Apis+6 moreJun 17, 2026 Nov 17, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 CKEditor4 is an open source WYSIWYG HTML editor. In affected version a vulnerability has been discovered in the core HTML processing module and may affect all plugins used by CKEditor 4. The vulnerability allowed to inje...Show more |
A remote attacker with write access to PI Vision could inject code into a display. Unauthorized information disclosure, modification, or deletion is possible if a victim views or interacts with the infected display using...Show more |
1Codepeople 1Contact Form Email Jun 17, 2026 Nov 17, 2021 N/A· v4 4.8 MEDIUM· v3 2.1 LOW· v2 The Contact Form Email WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and escaping via the name parameter found in the ~/trunk/cp-admin-int-list.inc.php file which allo...Show more |
4Ckeditor DrupalFedoraproject+1 more11Agile Plm Agile Product Lifecycle ManagementApplication Express+8 moreAug 25, 2026 Nov 17, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 CKEditor4 is an open source WYSIWYG HTML editor. In affected versions a vulnerability has been discovered in the Advanced Content Filter (ACF) module and may affect all plugins used by CKEditor 4. The vulnerability allow...Show more |
1Brainstormforce 1Starter Templates Jun 17, 2026 Nov 17, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 On sites that also had the Elementor plugin for WordPress installed, it was possible for users with the edit_posts capability, which includes Contributor-level users, to import blocks onto any page using the astra-page-e...Show more |
SmarterTools SmarterMail 16.x through 100.x before 100.0.7803 allows XSS. |
The Shared Files WordPress plugin before 1.6.61 does not sanitise and escape the Download Counter Text settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_htm...Show more |
1Qr Redirector Project 1Qr Redirector Jun 17, 2026 Nov 17, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 The QR Redirector WordPress plugin before 1.6.1 does not sanitise and escape some of the QR Redirect fields, which could allow users with a role as low as Contributor perform Stored Cross-Site Scripting attacks. |
1Insert Pages Project 1Insert Pages Jun 17, 2026 Nov 17, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 The Insert Pages WordPress plugin before 3.7.0 adds a shortcode that prints out other pages' content and custom fields. It can be used by users with a role as low as Contributor to perform Cross-Site Scripting attacks by...Show more |
The Helpful WordPress plugin before 4.4.59 does not sanitise and escape some of its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is dis...Show more |
The YOP Poll WordPress plugin before 6.3.1 is affected by a stored Cross-Site Scripting vulnerability which exists in the Create Poll - Options module where a user with a role as low as author is allowed to execute arbit...Show more |
The YOP Poll WordPress plugin before 6.3.1 is affected by a stored Cross-Site Scripting vulnerability, which exists in the Admin preview module where a user with a role as low as author is allowed to execute arbitrary sc...Show more |
1Wpplugin 1Accept Donations With Paypal Jun 17, 2026 Nov 17, 2021 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 The Accept Donations with PayPal WordPress plugin before 1.3.2 does not escape the Amount Menu Name field of created Buttons, which could allow a high privilege users to perform Cross-Site Scripting attacks even when the...Show more |
1My Tickets Project 1My Tickets Jun 17, 2026 Nov 17, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The My Tickets WordPress plugin before 1.8.31 does not properly sanitise and escape the Email field of booked tickets before outputting it in the Payment admin dashboard, which could allow unauthenticated users to perfor...Show more |
1Webventures 1Client Invoicing By Sprout Invoices Jun 17, 2026 Nov 17, 2021 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 The Client Invoicing by Sprout Invoices WordPress plugin before 19.9.7 does not sanitise and escape some of its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfil...Show more |
1Wpshopmart 1Testimonial Builder Jun 17, 2026 Nov 17, 2021 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 The Testimonial WordPress plugin before 1.6.0 does not escape some testimonial fields which could allow high privilege users to perform Cross Site Scripting attacks even when the unfiltered_html capability is disallowed |
1Ruijie 1Rg Uac 6000 E50 Firmware Jun 17, 2026 Nov 16, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Ruijie RG-UAC 6000-E50 commit 9071227 was discovered to contain a cross-site scripting (XSS) vulnerability via the rule_name parameter. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a c...Show more |