← Back
CWE-79

47,722 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (47,722)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Emarketdesign
1Request A Quote
Jun 17, 2026
Oct 25, 2021
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The Request a Quote WordPress plugin before 2.3.9 does not sanitise, validate or escape some of its settings in the admin dashboard, leading to authenticated Stored Cross-Site Scripting issues even when the unfiltered_ht...Show more
The Request a Quote WordPress plugin before 2.3.9 does not sanitise, validate or escape some of its settings in the admin dashboard, leading to authenticated Stored Cross-Site Scripting issues even when the unfiltered_html capability is disallowed.Show less
1Sanskruti
1St Daily Tip
Jun 17, 2026
Oct 25, 2021
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
The St-Daily-Tip WordPress plugin through 4.7 does not have any CSRF check in place when saving its 'Default Text to Display if no tips' setting, and was also lacking sanitisation as well as escaping before outputting it...Show more
The St-Daily-Tip WordPress plugin through 4.7 does not have any CSRF check in place when saving its 'Default Text to Display if no tips' setting, and was also lacking sanitisation as well as escaping before outputting it the page. This could allow attacker to make logged in administrators set a malicious payload in it, leading to a Stored Cross-Site Scripting issueShow less
1Wp Special Textboxes Project
1Wp Special Textboxes
Jun 17, 2026
Oct 25, 2021
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The Special Text Boxes WordPress plugin before 5.9.110 does not sanitise or escape some of its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is dis...Show more
The Special Text Boxes WordPress plugin before 5.9.110 does not sanitise or escape some of its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed.Show less
1Video Player For Youtube Project
1Video Player For Youtube
Jun 17, 2026
Oct 25, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The Video Player for YouTube WordPress plugin before 1.4 does not sanitise or validate the parameters from its shortcode, allowing users with a role as low as contributor to set Cross-Site Scripting payload in them which...Show more
The Video Player for YouTube WordPress plugin before 1.4 does not sanitise or validate the parameters from its shortcode, allowing users with a role as low as contributor to set Cross-Site Scripting payload in them which will be triggered in the page/s with the embed malicious shortcodeShow less
1Ninjaforms
1Contact Form
Jun 17, 2026
Oct 25, 2021
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The Ninja Forms Contact Form WordPress plugin before 3.5.8.2 does not sanitise and escape the custom class name of the form field created, which could allow high privilege users to perform Cross-Site Scripting attacks ev...Show more
The Ninja Forms Contact Form WordPress plugin before 3.5.8.2 does not sanitise and escape the custom class name of the form field created, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.Show less
1Dotnetfoundation
1Piranha Cms
Jun 17, 2026
Oct 25, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
In PiranhaCMS, versions 7.0.0 to 9.1.1 are vulnerable to stored XSS due to the page title improperly sanitized. By creating a page with a specially crafted page title, a low privileged user can trigger arbitrary JavaScri...Show more
In PiranhaCMS, versions 7.0.0 to 9.1.1 are vulnerable to stored XSS due to the page title improperly sanitized. By creating a page with a specially crafted page title, a low privileged user can trigger arbitrary JavaScript execution.Show less
1Swiftfiletransfer
1Swift File Transfer
Jun 17, 2026
Oct 22, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Swift File Transfer Mobile v1.1.2 was discovered to contain a cross-site scripting (XSS) vulnerability via the devicename parameter which allows attackers to execute arbitrary web scripts or HTML via a crafted payload en...Show more
Swift File Transfer Mobile v1.1.2 was discovered to contain a cross-site scripting (XSS) vulnerability via the devicename parameter which allows attackers to execute arbitrary web scripts or HTML via a crafted payload entered as the device name itself.Show less
1Sugarcrm
1Sugarcrm
Jun 17, 2026
Oct 22, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Multiple cross-site scripting (XSS) vulnerabilities in the Support module of SugarCRM v6.5.18 allows attackers to execute arbitrary web scripts or HTML via crafted payloads entered into the primary address state or alter...Show more
Multiple cross-site scripting (XSS) vulnerabilities in the Support module of SugarCRM v6.5.18 allows attackers to execute arbitrary web scripts or HTML via crafted payloads entered into the primary address state or alternate address state input fields.Show less
1Taotesting
1Tao Assessment Platform
Jun 17, 2026
Oct 22, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
TAO Open Source Assessment Platform v3.3.0 RC02 was discovered to contain a cross-site scripting (XSS) vulnerability in the content parameter of the Rubric Block (Add) module. This vulnerability allows attackers to execu...Show more
TAO Open Source Assessment Platform v3.3.0 RC02 was discovered to contain a cross-site scripting (XSS) vulnerability in the content parameter of the Rubric Block (Add) module. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the rubric name value.Show less
1Macrob7 Macs Framework Content Management System Project
1Macrob7 Macs Framework Content Management System
Jun 17, 2026
Oct 22, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Macrob7 Macs Framework Content Management System - 1.14f contains a cross-site scripting (XSS) vulnerability in the account reset function, which allows attackers to execute arbitrary web scripts or HTML via a crafted pa...Show more
Macrob7 Macs Framework Content Management System - 1.14f contains a cross-site scripting (XSS) vulnerability in the account reset function, which allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the e-mail input field.Show less
1Dedecms
1Dedecms
Jun 17, 2026
Oct 22, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
DedeCMS v7.5 SP2 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in the component makehtml_homepage.php via the `filename`, `mid`, `userid`, and `templet' parameters.
1Dedecms
1Dedecms
Jun 17, 2026
Oct 22, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
DedeCMS v7.5 SP2 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in the component sys_admin_user_edit.php via the `filename`, `mid`, `userid`, and `templet' parameters.
1Dedecms
1Dedecms
Jun 17, 2026
Oct 22, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
DedeCMS v7.5 SP2 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in the component file_manage_view.php via the `filename`, `mid`, `userid`, and `templet' parameters.
1Dedecms
1Dedecms
Jun 17, 2026
Oct 22, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
DedeCMS v7.5 SP2 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in the component mychannel_edit.php via the `filename`, `mid`, `userid`, and `templet' parameters.
1Dedecms
1Dedecms
Jun 17, 2026
Oct 22, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
DedeCMS v7.5 SP2 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in the component media_main.php via the `activepath`, `keyword`, `tag`, `fmdo=x&filename`, `CKEditor` and `CKEditorFuncNum` p...Show more
DedeCMS v7.5 SP2 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in the component media_main.php via the `activepath`, `keyword`, `tag`, `fmdo=x&filename`, `CKEditor` and `CKEditorFuncNum` parameters.Show less
1Dedecms
1Dedecms
Jun 17, 2026
Oct 22, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
DedeCMS v7.5 SP2 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in the component select_media.php via the `activepath`, `keyword`, `tag`, `fmdo=x&filename`, `CKEditor` and `CKEditorFuncNum`...Show more
DedeCMS v7.5 SP2 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in the component select_media.php via the `activepath`, `keyword`, `tag`, `fmdo=x&filename`, `CKEditor` and `CKEditorFuncNum` parameters.Show less
1Dedecms
1Dedecms
Jun 17, 2026
Oct 22, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
DedeCMS v7.5 SP2 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in the component tags_main.php via the `activepath`, `keyword`, `tag`, `fmdo=x&filename`, `CKEditor` and `CKEditorFuncNum` pa...Show more
DedeCMS v7.5 SP2 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in the component tags_main.php via the `activepath`, `keyword`, `tag`, `fmdo=x&filename`, `CKEditor` and `CKEditorFuncNum` parameters.Show less
1Dedecms
1Dedecms
Jun 17, 2026
Oct 22, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
DedeCMS v7.5 SP2 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in the component file_manage_view.php via the `activepath`, `keyword`, `tag`, `fmdo=x&filename`, `CKEditor` and `CKEditorFunc...Show more
DedeCMS v7.5 SP2 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in the component file_manage_view.php via the `activepath`, `keyword`, `tag`, `fmdo=x&filename`, `CKEditor` and `CKEditorFuncNum` parameters.Show less
1Dropouts
1Air Share
Jun 17, 2026
Oct 22, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Dropouts Technologies LLP Air Share v1.2 was discovered to contain a cross-site scripting (XSS) vulnerability in the devicename parameter. This vulnerability allows attackers to execute arbitrary web scripts or HTML via...Show more
Dropouts Technologies LLP Air Share v1.2 was discovered to contain a cross-site scripting (XSS) vulnerability in the devicename parameter. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the devicename information.Show less
1Swiftfiletransfer
1Swift File Transfer
Jun 17, 2026
Oct 22, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Swift File Transfer Mobile v1.1.2 and below was discovered to contain a cross-site scripting (XSS) vulnerability via the 'path' parameter of the 'list' and 'download' exception-handling.