← Back
CWE-79

47,722 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (47,722)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Nextscripts
1Social Networks Auto Poster
Jun 17, 2026
Nov 1, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The NextScripts: Social Networks Auto-Poster <= 4.3.20 WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the $_REQUEST['page'] parameter which is echoed out on inc/nxs_class_snap.php by supplying the a...Show more
The NextScripts: Social Networks Auto-Poster <= 4.3.20 WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the $_REQUEST['page'] parameter which is echoed out on inc/nxs_class_snap.php by supplying the appropriate value 'nxssnap-post' to load the page in $_GET['page'] along with malicious JavaScript in $_POST['page'].Show less
1Mcafee
1Data Loss Prevention Endpoint
Jun 17, 2026
Nov 1, 2021
N/A· v4
6.1 MEDIUM· v3
3.5 LOW· v2
Cross site scripting (XSS) vulnerability in McAfee Data Loss Prevention (DLP) ePO extension prior to 11.7.100 allows a remote attacker to highjack an active DLP ePO administrator session by convincing the logged in admin...Show more
Cross site scripting (XSS) vulnerability in McAfee Data Loss Prevention (DLP) ePO extension prior to 11.7.100 allows a remote attacker to highjack an active DLP ePO administrator session by convincing the logged in administrator to click on a carefully crafted link in the case management part of the DLP ePO extension.Show less
1Youphptube
1Youphptube
Jul 9, 2026
Nov 1, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
AVideo/YouPHPTube 10.0 and prior is affected by multiple reflected Cross Script Scripting vulnerabilities via the videoName parameter which allows a remote attacker to steal administrators' session cookies or perform act...Show more
AVideo/YouPHPTube 10.0 and prior is affected by multiple reflected Cross Script Scripting vulnerabilities via the videoName parameter which allows a remote attacker to steal administrators' session cookies or perform actions as an administrator.Show less
1Youphptube
1Youphptube
Jul 9, 2026
Nov 1, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
AVideo/YouPHPTube 10.0 and prior has multiple reflected Cross Script Scripting vulnerabilities via the u parameter which allows a remote attacker to steal administrators' session cookies or perform actions as an administ...Show more
AVideo/YouPHPTube 10.0 and prior has multiple reflected Cross Script Scripting vulnerabilities via the u parameter which allows a remote attacker to steal administrators' session cookies or perform actions as an administrator.Show less
1Youphptube
1Youphptube
Jul 9, 2026
Nov 1, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
AVideo/YouPHPTube AVideo/YouPHPTube 10.0 and prior has multiple reflected Cross Script Scripting vulnerabilities via the searchPhrase parameter which allows a remote attacker to steal administrators' session cookies or p...Show more
AVideo/YouPHPTube AVideo/YouPHPTube 10.0 and prior has multiple reflected Cross Script Scripting vulnerabilities via the searchPhrase parameter which allows a remote attacker to steal administrators' session cookies or perform actions as an administrator.Show less
1E Dynamics
1Events Made Easy
Jun 17, 2026
Nov 1, 2021
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The Events Made Easy WordPress plugin before 2.2.24 does not sanitise and escape Custom Field Names, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disal...Show more
The Events Made Easy WordPress plugin before 2.2.24 does not sanitise and escape Custom Field Names, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowedShow less
1Wordplus
1Better Messages
Jun 17, 2026
Nov 1, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The BP Better Messages WordPress plugin before 1.9.9.41 sanitise (with sanitize_text_field) but does not escape the 'subject' parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripti...Show more
The BP Better Messages WordPress plugin before 1.9.9.41 sanitise (with sanitize_text_field) but does not escape the 'subject' parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting issueShow less
1Connections Pro
1Connections Business Directory
Jun 17, 2026
Nov 1, 2021
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The Connections Business Directory WordPress plugin before 10.4.3 does not escape the Address settings when creating an Entry, which could allow high privilege users to perform Cross-Site Scripting when the unfiltered_ht...Show more
The Connections Business Directory WordPress plugin before 10.4.3 does not escape the Address settings when creating an Entry, which could allow high privilege users to perform Cross-Site Scripting when the unfiltered_html capability is disallowed.Show less
1Etruel
1Wpematico Rss Feed Fetcher
Jun 17, 2026
Nov 1, 2021
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The WPeMatico RSS Feed Fetcher WordPress plugin before 2.6.12 does not escape the Feed URL added to a campaign before outputting it in an attribute, allowing high privilege users to perform Cross-Site Scripting attacks e...Show more
The WPeMatico RSS Feed Fetcher WordPress plugin before 2.6.12 does not escape the Feed URL added to a campaign before outputting it in an attribute, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.Show less
1Flat Preloader Project
1Flat Preloader
Jun 17, 2026
Nov 1, 2021
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The Flat Preloader WordPress plugin before 1.5.5 does not escape some of its settings when outputting them in attribute in the frontend, which could allow high privilege users to perform Cross-Site Scripting attacks even...Show more
The Flat Preloader WordPress plugin before 1.5.5 does not escape some of its settings when outputting them in attribute in the frontend, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowedShow less
1W3eden
1Download Manager
Jun 17, 2026
Nov 1, 2021
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The WordPress Download Manager WordPress plugin before 3.2.16 does not escape some of the Download settings when outputting them, allowing high privilege users to perform XSS attacks even when the unfiltered_html capabil...Show more
The WordPress Download Manager WordPress plugin before 3.2.16 does not escape some of the Download settings when outputting them, allowing high privilege users to perform XSS attacks even when the unfiltered_html capability is disallowedShow less
1Wpreactions
1Wp Reactions Lite
Jun 17, 2026
Nov 1, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The WP Reactions Lite WordPress plugin before 1.3.6 does not properly sanitize inputs within wp-admin pages, allowing users with sufficient access to inject XSS payloads within /wp-admin/ pages.
1Motopress
1Restaurant Menu
Jun 17, 2026
Nov 1, 2021
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The Restaurant Menu by MotoPress WordPress plugin before 2.4.2 does not properly sanitize or escape inputs when creating new menu items, which could allow high privilege users to perform Cross-Site Scripting attacks even...Show more
The Restaurant Menu by MotoPress WordPress plugin before 2.4.2 does not properly sanitize or escape inputs when creating new menu items, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowedShow less
1Webnus
1Modern Events Calendar Lite
Jun 17, 2026
Nov 1, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The Modern Events Calendar Lite WordPress plugin before 5.22.3 does not properly sanitize or escape values set by users with access to adjust settings withing wp-admin.
1Wp Sitemap Page Project
1Wp Sitemap Page
Jun 17, 2026
Nov 1, 2021
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The WP Sitemap Page WordPress plugin before 1.7.0 does not properly sanitise and escape some of its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html c...Show more
The WP Sitemap Page WordPress plugin before 1.7.0 does not properly sanitise and escape some of its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.Show less
1Flat Preloader Project
1Flat Preloader
Jun 17, 2026
Nov 1, 2021
N/A· v4
5.4 MEDIUM· v3
5.0 MEDIUM· v2
The Flat Preloader WordPress plugin before 1.5.4 does not enforce nonce checks when saving its settings, as well as does not sanitise and escape them, which could allow attackers to a make logged in admin change them wit...Show more
The Flat Preloader WordPress plugin before 1.5.4 does not enforce nonce checks when saving its settings, as well as does not sanitise and escape them, which could allow attackers to a make logged in admin change them with a Cross-Site Scripting payload (triggered either in the frontend or backend depending on the payload)Show less
1Wpkube
1Cool Tag Cloud
Jun 17, 2026
Nov 1, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The Cool Tag Cloud WordPress plugin before 2.26 does not escape the style attribute of the cool_tag_cloud shortcode, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attack...Show more
The Cool Tag Cloud WordPress plugin before 2.26 does not escape the style attribute of the cool_tag_cloud shortcode, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks.Show less
1Sonaar
1Mp3 Audio Player For Music, Radio & Podcast
Jun 17, 2026
Nov 1, 2021
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The MP3 Audio Player for Music, Radio & Podcast by Sonaar WordPress plugin before 2.4.2 does not properly sanitize or escape data in some of its Playlist settings, allowing high privilege users to perform Cross-Site Scri...Show more
The MP3 Audio Player for Music, Radio & Podcast by Sonaar WordPress plugin before 2.4.2 does not properly sanitize or escape data in some of its Playlist settings, allowing high privilege users to perform Cross-Site Scripting attacksShow less
1Wpplugin
1Accept Donations With Paypal
Jun 17, 2026
Nov 1, 2021
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
The Accept Donations with PayPal WordPress plugin before 1.3.1 offers a function to create donation buttons, which internally are posts. The process to create a new button is lacking a CSRF check. An attacker could use t...Show more
The Accept Donations with PayPal WordPress plugin before 1.3.1 offers a function to create donation buttons, which internally are posts. The process to create a new button is lacking a CSRF check. An attacker could use this to make an authenticated admin create a new button. Furthermore, one of the Button field is not escaped before being output in an attribute when editing a Button, leading to a Stored Cross-Site Scripting issue as well.Show less
1Dazzlersoftware
1Coming Soon, Under Construction & Maintenance Mode By Dazzler
Jun 17, 2026
Nov 1, 2021
N/A· v4
4.8 MEDIUM· v3
2.1 LOW· v2
The Coming Soon, Under Construction & Maintenance Mode By Dazzler WordPress plugin before 1.6.7 does not sanitise or escape its description setting when outputting it in the frontend when the Coming Soon mode is enabled,...Show more
The Coming Soon, Under Construction & Maintenance Mode By Dazzler WordPress plugin before 1.6.7 does not sanitise or escape its description setting when outputting it in the frontend when the Coming Soon mode is enabled, even when the unfiltered_html capability is disallowed, leading to an authenticated Stored Cross-Site Scripting issueShow less