← Back
CWE-79

47,713 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (47,713)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Online Enrollment Management System Project
1Online Enrollment Management System
Jun 17, 2026
Nov 8, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A Stored Cross Site Scripting (XSS) vulnerability exists in Sourcecodester Online Enrollment Management System in PHP and PayPal Free Source Code 1.0 in the Add-Users page via the Name parameter.
1Schiocco
1Support Board
Jun 17, 2026
Nov 8, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The Support Board WordPress plugin before 3.3.5 allows Authenticated (Agent+) users to perform Cross-Site Scripting attacks by placing a payload in the notes field, when an administrator or any authenticated user go to t...Show more
The Support Board WordPress plugin before 3.3.5 allows Authenticated (Agent+) users to perform Cross-Site Scripting attacks by placing a payload in the notes field, when an administrator or any authenticated user go to the chat the XSS will be automatically executed.Show less
1Wp Survey Plus Project
1Wp Survey Plus
Jun 17, 2026
Nov 8, 2021
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
The WP Survey Plus WordPress plugin through 1.0 does not have any authorisation and CSRF checks in place in its AJAX actions, allowing any user to call them and add/edit/delete Surveys. Furthermore, due to the lack of sa...Show more
The WP Survey Plus WordPress plugin through 1.0 does not have any authorisation and CSRF checks in place in its AJAX actions, allowing any user to call them and add/edit/delete Surveys. Furthermore, due to the lack of sanitization in the Surveys' Title, this could also lead to Stored Cross-Site Scripting issuesShow less
1Androidbubbles
1Wp Header Images
Jun 17, 2026
Nov 8, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The WP Header Images WordPress plugin before 2.0.1 does not sanitise and escape the t parameter before outputting it back in the plugin's settings page, leading to a Reflected Cross-Site Scripting issue
1Print O Matic Project
1Print O Matic
Jun 17, 2026
Nov 8, 2021
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The Print-O-Matic WordPress plugin before 2.0.3 does not escape some of its settings before outputting them in attribute, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfil...Show more
The Print-O-Matic WordPress plugin before 2.0.3 does not escape some of its settings before outputting them in attribute, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.Show less
1Wp All Export Project
1Wp All Export
Jun 17, 2026
Nov 8, 2021
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The Export any WordPress data to XML/CSV WordPress plugin before 1.3.1 does not escape its Export's Name before outputting it in Manage Exports settings, which could allow high privilege users to perform Cross-Site Scrip...Show more
The Export any WordPress data to XML/CSV WordPress plugin before 1.3.1 does not escape its Export's Name before outputting it in Manage Exports settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowedShow less
1Qwizcards Project
1Qwizcards
Jun 17, 2026
Nov 8, 2021
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The Qwizcards – online quizzes and flashcards WordPress plugin before 3.62 does not properly sanitize and escape some of its settings, allowing high privilege users to perform Cross-Site Scripting attacks even when the u...Show more
The Qwizcards – online quizzes and flashcards WordPress plugin before 3.62 does not properly sanitize and escape some of its settings, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.Show less
1Quiz Tool Lite Project
1Quiz Tool Lite
Jun 17, 2026
Nov 8, 2021
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The Quiz Tool Lite WordPress plugin through 2.3.15 does not sanitize multiple input fields used when creating or managing quizzes and in other setting options, allowing high privilege users to perform Cross-Site Scriptin...Show more
The Quiz Tool Lite WordPress plugin through 2.3.15 does not sanitize multiple input fields used when creating or managing quizzes and in other setting options, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.Show less
1Tipsandtricks Hq
1Simple Download Monitor
Jun 17, 2026
Nov 8, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Simple Download Monitor WordPress plugin before 3.9.5 does not escape the 1) sdm_active_tab GET parameter and 2) sdm_stats_start_date/sdm_stats_end_date POST parameters before outputting them back in attributes, lead...Show more
The Simple Download Monitor WordPress plugin before 3.9.5 does not escape the 1) sdm_active_tab GET parameter and 2) sdm_stats_start_date/sdm_stats_end_date POST parameters before outputting them back in attributes, leading to Reflected Cross-Site Scripting issuesShow less
1Tipsandtricks Hq
1Simple Download Monitor
Jun 17, 2026
Nov 8, 2021
N/A· v4
9.0 CRITICAL· v3
6.0 MEDIUM· v2
The Simple Download Monitor WordPress plugin before 3.9.5 does not escape the "File Thumbnail" post meta before outputting it in some pages, which could allow users with a role as low as Contributor to perform Stored Cro...Show more
The Simple Download Monitor WordPress plugin before 3.9.5 does not escape the "File Thumbnail" post meta before outputting it in some pages, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks. Given the that XSS is triggered even when the Download is in a review state, contributor could make JavaScript code execute in a context of a reviewer such as admin and make them create a rogue admin account, or install a malicious pluginShow less
1Igexsolutions
1Wpschoolpress
Jun 17, 2026
Nov 8, 2021
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The School Management System – WPSchoolPress WordPress plugin before 2.1.17 sanitise some fields using sanitize_text_field() but does not escape them before outputting in attributes, resulting in Stored Cross-Site Script...Show more
The School Management System – WPSchoolPress WordPress plugin before 2.1.17 sanitise some fields using sanitize_text_field() but does not escape them before outputting in attributes, resulting in Stored Cross-Site Scripting issues.Show less
1Bookingholdings
1Booking.com Banner Creator
Jun 17, 2026
Nov 8, 2021
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The Booking.com Banner Creator WordPress plugin before 1.4.3 does not properly sanitize inputs when creating banners, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltere...Show more
The Booking.com Banner Creator WordPress plugin before 1.4.3 does not properly sanitize inputs when creating banners, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowedShow less
1Bookingholdings
1Booking.com Product Helper
Jun 17, 2026
Nov 8, 2021
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The Booking.com Product Helper WordPress plugin before 1.0.2 does not sanitize and escape Product Code when creating Product Shortcode, which could allow high privilege users to perform Cross-Site Scripting attacks even...Show more
The Booking.com Product Helper WordPress plugin before 1.0.2 does not sanitize and escape Product Code when creating Product Shortcode, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowedShow less
1Addtoany
1Addtoany Share Buttons
Jun 17, 2026
Nov 8, 2021
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The AddToAny Share Buttons WordPress plugin before 1.7.48 does not escape its Image URL button setting, which could lead allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html ca...Show more
The AddToAny Share Buttons WordPress plugin before 1.7.48 does not escape its Image URL button setting, which could lead allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.Show less
1Wooassist
1Storefront Footer Text
Jun 17, 2026
Nov 8, 2021
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The Storefront Footer Text WordPress plugin through 1.0.1 does not sanitize and escape the "Footer Credit Text" added to pages, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfilter...Show more
The Storefront Footer Text WordPress plugin through 1.0.1 does not sanitize and escape the "Footer Credit Text" added to pages, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered-html capability is disallowed.Show less
1Gtranslate
1Google Language Translator
Jun 17, 2026
Nov 8, 2021
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The Translate WordPress – Google Language Translator WordPress plugin before 6.0.12 does not sanitise and escape some of its settings before outputting it in various pages, allowing high privilege users to perform Cross-...Show more
The Translate WordPress – Google Language Translator WordPress plugin before 6.0.12 does not sanitise and escape some of its settings before outputting it in various pages, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.Show less
1Ibm
1Security Guardium
Jun 17, 2026
Nov 8, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM Security Guardium 10.5, 10.6, 11.0, 11.1, 11.2, and 11.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionalit...Show more
IBM Security Guardium 10.5, 10.6, 11.0, 11.1, 11.2, and 11.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.Show less
1Ibm
1Qradar Network Security
Jun 17, 2026
Nov 8, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM QRadar Network Security 5.4.0 and 5.5.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially lea...Show more
IBM QRadar Network Security 5.4.0 and 5.5.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 174269.Show less
1Opnsense
1Opnsense
Jun 17, 2026
Nov 8, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A Cross-site scripting (XSS) vulnerability was discovered in OPNsense before 21.7.4 via the LDAP attribute return in the authentication tester.
1Cloudera
1Cloudera Manager
Jun 17, 2026
Nov 8, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cloudera Manager 5.x, 6.x, 7.1.x, 7.2.x, and 7.3.x allows XSS via the path parameter.