CWE-79
47,722 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (47,722)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
7Debian DrupalFedoraproject+4 more29Agile Plm Agile Product Lifecycle ManagementApplication Express+26 moreAug 25, 2026 Oct 26, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of various `*Text` options of the Datepicker widget from untrusted sources may execute untrusted code. The issue is fi...Show more |
7Debian DrupalFedoraproject+4 more30Agile Plm Agile Product Lifecycle ManagementApplication Express+27 moreAug 25, 2026 Oct 26, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the `altField` option of the Datepicker widget from untrusted sources may execute untrusted code. The issue is fixe...Show more |
Pi-hole's Web interface (based on AdminLTE) provides a central location to manage one's Pi-hole and review the statistics generated by FTLDNS. Prior to version 5.8, cross-site scripting is possible when adding a client v...Show more |
1Antsword Redis Project 1Antsword Redis Jun 17, 2026 Oct 26, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 AS_Redis is an AntSword plugin for Redis. The Redis Manage plugin for AntSword prior to version 0.5 is vulnerable to Self-XSS due to due to insufficient input validation and sanitization via redis server configuration. S...Show more |
Cross-site scripting vulnerability in Movable Type Movable Type Premium 1.37 and earlier and Movable Type Premium Advanced 1.37 and earlier allows a remote authenticated attacker to inject an arbitrary script via unspeci...Show more |
1Atlassian 4Data Center JiraJira Data Center+1 moreJun 17, 2026 Oct 26, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability in the /secure/admin/ImporterFinishedPage....Show more |
Nextcloud is an open-source, self-hosted productivity platform. The Nextcloud Contacts application prior to version 4.0.3 was vulnerable to a stored Cross-Site Scripting (XSS) vulnerability. For exploitation, a user woul...Show more |
Galette is a membership management web application geared towards non profit organizations. In versions prior to 0.9.5, malicious javascript code can be stored to be displayed later on self subscription page. The self su...Show more |
Akaunting v1.3.17 was discovered to contain a stored cross-site scripting (XSS) vulnerability which allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the Company Name input field. |
The YOP Poll WordPress plugin before 6.1.2 does not escape the perpage parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting |
1Strategy11 1Formidable Form Builder Jun 17, 2026 Oct 25, 2021 N/A· v4 9.6 CRITICAL· v3 6.8 MEDIUM· v2 The Formidable Form Builder WordPress plugin before 4.09.05 allows to inject certain HTML Tags like <audio>,<video>,<img>,<a> and<button>.This could allow an unauthenticated, remote attacker to exploit a HTML-injection b...Show more |
1Great Quotes Project 1Great Quotes Jun 17, 2026 Oct 25, 2021 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 The Great Quotes WordPress plugin through 1.0.0 does not sanitise and escape the Quote and Author fields of its Quotes, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfilte...Show more |
The WordPress Contact Forms by Cimatti WordPress plugin before 1.4.12 does not sanitise and escape the Form Title before outputting it in some admin pages. which could allow high privilege users to perform Cross-Site Scr...Show more |
1Easy Media Download Project 1Easy Media Download Jun 17, 2026 Oct 25, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 The Easy Media Download WordPress plugin before 1.1.7 does not escape the text argument of its shortcode, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks. |
1Cookie Bar Project 1Cookie Bar Jun 17, 2026 Oct 25, 2021 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 The Cookie Bar WordPress plugin before 1.8.9 doesn't properly sanitise the Cookie Bar Message setting, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capabili...Show more |
1Strategy11 1Formidable Form Builder Jun 17, 2026 Oct 25, 2021 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 The Formidable Form Builder – Contact Form, Survey & Quiz Forms Plugin for WordPress plugin before 5.0.07 does not sanitise and escape its Form's Labels, allowing high privileged users to perform Cross-Site Scripting att...Show more |
1Motopress 1Motopress Slider Lite Jun 17, 2026 Oct 25, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 The Responsive WordPress Slider WordPress plugin through 2.2.0 does not sanitise and escape some of the Slider options, allowing Cross-Site Scripting payloads to be set in them. Furthermore, as by default any authenticat...Show more |
1Jquery Reply To Comment Project 1Jquery Reply To Comment Jun 17, 2026 Oct 25, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The jQuery Reply to Comment WordPress plugin through 1.31 does not have any CSRF check when saving its settings, nor sanitise or escape its 'Quote String' and 'Reply String' settings before outputting them in Comments, l...Show more |
The Video Gallery WordPress plugin before 1.1.5 does not escape the Title and Description of the videos in a gallery before outputting them in attributes, leading to Stored Cross-Site Scripting issues |
The Visual Form Builder WordPress plugin before 3.0.4 does not sanitise or escape its Form Name, allowing high privilege users such as admin to set Cross-Site Scripting payload in them, even when the unfiltered_html capa...Show more |