← Back
CWE-79

47,713 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (47,713)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
3Debian
FedoraprojectRoundcube
3Debian Linux
FedoraWebmail
Jun 17, 2026
Nov 19, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to XSS in handling an attachment's filename extension when displaying a MIME type warning message.
1Cisco
1Common Services Platform Collector
Jun 17, 2026
Nov 19, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A vulnerability in the web-based management interface of Cisco Common Services Platform Collector (CSPC) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the...Show more
A vulnerability in the web-based management interface of Cisco Common Services Platform Collector (CSPC) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability is due to insufficient validation of user-supplied input that is processed by the web-based management interface. An attacker could exploit this vulnerability by adding malicious code to the configuration by using the web-based management interface. A successful exploit could allow the attacker to execute arbitrary code in the context of the interface or access sensitive, browser-based information.Show less
1Osisoft
1Pi Web Api
Jun 17, 2026
Nov 18, 2021
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
A remote authenticated attacker with write access to a PI Server could trick a user into interacting with a PI Web API endpoint and redirect them to a malicious website. As a result, a victim may disclose sensitive infor...Show more
A remote authenticated attacker with write access to a PI Server could trick a user into interacting with a PI Web API endpoint and redirect them to a malicious website. As a result, a victim may disclose sensitive information to the attacker or be provided with false information.Show less
3Ckeditor
DrupalOracle
9Agile Product Lifecycle Management
Application ExpressBanking Apis+6 more
Jun 17, 2026
Nov 17, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
CKEditor4 is an open source WYSIWYG HTML editor. In affected version a vulnerability has been discovered in the core HTML processing module and may affect all plugins used by CKEditor 4. The vulnerability allowed to inje...Show more
CKEditor4 is an open source WYSIWYG HTML editor. In affected version a vulnerability has been discovered in the core HTML processing module and may affect all plugins used by CKEditor 4. The vulnerability allowed to inject malformed comments HTML bypassing content sanitization, which could result in executing JavaScript code. It affects all users using the CKEditor 4 at version < 4.17.0. The problem has been recognized and patched. The fix will be available in version 4.17.0.Show less
1Osisoft
1Pi Vision
Jun 17, 2026
Nov 17, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A remote attacker with write access to PI Vision could inject code into a display. Unauthorized information disclosure, modification, or deletion is possible if a victim views or interacts with the infected display using...Show more
A remote attacker with write access to PI Vision could inject code into a display. Unauthorized information disclosure, modification, or deletion is possible if a victim views or interacts with the infected display using Microsoft Internet Explorer. The impact affects PI System data and other data accessible with victim's user permissions.Show less
1Codepeople
1Contact Form Email
Jun 17, 2026
Nov 17, 2021
N/A· v4
4.8 MEDIUM· v3
2.1 LOW· v2
The Contact Form Email WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and escaping via the name parameter found in the ~/trunk/cp-admin-int-list.inc.php file which allo...Show more
The Contact Form Email WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and escaping via the name parameter found in the ~/trunk/cp-admin-int-list.inc.php file which allowed attackers with administrative user access to inject arbitrary web scripts, in versions up to and including 1.3.24. This affects multi-site installations where unfiltered_html is disabled for administrators, and sites where unfiltered_html is disabled.Show less
4Ckeditor
DrupalFedoraproject+1 more
11Agile Plm
Agile Product Lifecycle ManagementApplication Express+8 more
Aug 25, 2026
Nov 17, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
CKEditor4 is an open source WYSIWYG HTML editor. In affected versions a vulnerability has been discovered in the Advanced Content Filter (ACF) module and may affect all plugins used by CKEditor 4. The vulnerability allow...Show more
CKEditor4 is an open source WYSIWYG HTML editor. In affected versions a vulnerability has been discovered in the Advanced Content Filter (ACF) module and may affect all plugins used by CKEditor 4. The vulnerability allowed to inject malformed HTML bypassing content sanitization, which could result in executing JavaScript code. It affects all users using the CKEditor 4 at version < 4.17.0. The problem has been recognized and patched. The fix will be available in version 4.17.0.Show less
1Brainstormforce
1Starter Templates
Jun 17, 2026
Nov 17, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
On sites that also had the Elementor plugin for WordPress installed, it was possible for users with the edit_posts capability, which includes Contributor-level users, to import blocks onto any page using the astra-page-e...Show more
On sites that also had the Elementor plugin for WordPress installed, it was possible for users with the edit_posts capability, which includes Contributor-level users, to import blocks onto any page using the astra-page-elementor-batch-process AJAX action. An attacker could craft and host a block containing malicious JavaScript on a server they controlled, and then use it to overwrite any post or page by sending an AJAX request with the action set to astra-page-elementor-batch-process and the url parameter pointed to their remotely-hosted malicious block, as well as an id parameter containing the post or page to overwrite. Any post or page that had been built with Elementor, including published pages, could be overwritten by the imported block, and the malicious JavaScript in the imported block would then be executed in the browser of any visitors to that page.Show less
1Smartertools
1Smartermail
Jun 17, 2026
Nov 17, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
SmarterTools SmarterMail 16.x through 100.x before 100.0.7803 allows XSS.
1Tammersoft
1Shared Files
Jun 17, 2026
Nov 17, 2021
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The Shared Files WordPress plugin before 1.6.61 does not sanitise and escape the Download Counter Text settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_htm...Show more
The Shared Files WordPress plugin before 1.6.61 does not sanitise and escape the Download Counter Text settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowedShow less
1Qr Redirector Project
1Qr Redirector
Jun 17, 2026
Nov 17, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The QR Redirector WordPress plugin before 1.6.1 does not sanitise and escape some of the QR Redirect fields, which could allow users with a role as low as Contributor perform Stored Cross-Site Scripting attacks.
1Insert Pages Project
1Insert Pages
Jun 17, 2026
Nov 17, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The Insert Pages WordPress plugin before 3.7.0 adds a shortcode that prints out other pages' content and custom fields. It can be used by users with a role as low as Contributor to perform Cross-Site Scripting attacks by...Show more
The Insert Pages WordPress plugin before 3.7.0 adds a shortcode that prints out other pages' content and custom fields. It can be used by users with a role as low as Contributor to perform Cross-Site Scripting attacks by storing the payload/s in another post's custom fields.Show less
1Helpful Project
1Helpful
Jun 17, 2026
Nov 17, 2021
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The Helpful WordPress plugin before 4.4.59 does not sanitise and escape some of its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is dis...Show more
The Helpful WordPress plugin before 4.4.59 does not sanitise and escape some of its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowedShow less
1Yop Poll
1Yop Poll
Jun 17, 2026
Nov 17, 2021
N/A· v4
5.4 MEDIUM· v3
4.3 MEDIUM· v2
The YOP Poll WordPress plugin before 6.3.1 is affected by a stored Cross-Site Scripting vulnerability which exists in the Create Poll - Options module where a user with a role as low as author is allowed to execute arbit...Show more
The YOP Poll WordPress plugin before 6.3.1 is affected by a stored Cross-Site Scripting vulnerability which exists in the Create Poll - Options module where a user with a role as low as author is allowed to execute arbitrary script code within the context of the application. This vulnerability is due to insufficient validation of custom label parameters - vote button label , results link label and back to vote caption label.Show less
1Yop Poll
1Yop Poll
Jun 17, 2026
Nov 17, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The YOP Poll WordPress plugin before 6.3.1 is affected by a stored Cross-Site Scripting vulnerability, which exists in the Admin preview module where a user with a role as low as author is allowed to execute arbitrary sc...Show more
The YOP Poll WordPress plugin before 6.3.1 is affected by a stored Cross-Site Scripting vulnerability, which exists in the Admin preview module where a user with a role as low as author is allowed to execute arbitrary script code within the context of the application. This vulnerability is due to insufficient validation of question and answer text parameters in Create Poll module.Show less
1Wpplugin
1Accept Donations With Paypal
Jun 17, 2026
Nov 17, 2021
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The Accept Donations with PayPal WordPress plugin before 1.3.2 does not escape the Amount Menu Name field of created Buttons, which could allow a high privilege users to perform Cross-Site Scripting attacks even when the...Show more
The Accept Donations with PayPal WordPress plugin before 1.3.2 does not escape the Amount Menu Name field of created Buttons, which could allow a high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.Show less
1My Tickets Project
1My Tickets
Jun 17, 2026
Nov 17, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The My Tickets WordPress plugin before 1.8.31 does not properly sanitise and escape the Email field of booked tickets before outputting it in the Payment admin dashboard, which could allow unauthenticated users to perfor...Show more
The My Tickets WordPress plugin before 1.8.31 does not properly sanitise and escape the Email field of booked tickets before outputting it in the Payment admin dashboard, which could allow unauthenticated users to perform Cross-Site Scripting attacks against adminsShow less
1Webventures
1Client Invoicing By Sprout Invoices
Jun 17, 2026
Nov 17, 2021
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The Client Invoicing by Sprout Invoices WordPress plugin before 19.9.7 does not sanitise and escape some of its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfil...Show more
The Client Invoicing by Sprout Invoices WordPress plugin before 19.9.7 does not sanitise and escape some of its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowedShow less
1Wpshopmart
1Testimonial Builder
Jun 17, 2026
Nov 17, 2021
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The Testimonial WordPress plugin before 1.6.0 does not escape some testimonial fields which could allow high privilege users to perform Cross Site Scripting attacks even when the unfiltered_html capability is disallowed
1Ruijie
1Rg Uac 6000 E50 Firmware
Jun 17, 2026
Nov 16, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Ruijie RG-UAC 6000-E50 commit 9071227 was discovered to contain a cross-site scripting (XSS) vulnerability via the rule_name parameter. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a c...Show more
Ruijie RG-UAC 6000-E50 commit 9071227 was discovered to contain a cross-site scripting (XSS) vulnerability via the rule_name parameter. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload.Show less