CWE-79
47,723 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (47,723)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
In “OpenCMS”, versions 10.5.0 to 11.0.2 are affected by a stored XSS vulnerability that allows low privileged application users to store malicious scripts in the Sitemap functionality. These scripts are executed in a vic...Show more |
Cross Site Scripting (XSS vulnerability exists in Portainer before 2.9.1 via the node input box in Custom Templates. |
1Timetracker Project 1Timetracker Jun 17, 2026 Oct 18, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 anuko/timetracker is an, open source time tracking system. In affected versions Time Tracker uses browser_today hidden control on a few pages to collect the today's date from user browsers. Because of not checking this p...Show more |
1Ibm 1Business Automation Workflow Jun 17, 2026 Oct 18, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 IBM Business Automation Workflow 18.0, 19.0, 20.0, and 21.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality...Show more |
Apache Superset up to and including 1.1 does not sanitize titles correctly on the Explore page. This allows an attacker with Explore access to save a chart with a malicious title, injecting html (including scripts) into...Show more |
1Pdf Viewer Block For Gutenberg Project 1Pdf Viewer Block For Gutenberg Jun 17, 2026 Oct 18, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 The Gutenberg PDF Viewer Block WordPress plugin before 1.0.1 does not sanitise and escape its block, which could allow users with a role as low as Contributor to perform Cross-Site Scripting attacks. |
1Secondlinethemes 1Podcast Subscribe Buttons Jun 17, 2026 Oct 18, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 The Podcast Subscribe Buttons WordPress plugin before 1.4.2 allows users with any role capable of editing or adding posts to perform stored XSS. |
The Tutor LMS WordPress plugin before 1.9.9 does not escape some of its settings before outputting them in attributes, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfilter...Show more |
The Easy Download Manager and File Sharing Plugin with frontend file upload – a better Media Library — Shared Files WordPress plugin before 1.6.57 does not sanitise and escape some of its settings before outputting them...Show more |
1Tipsandtricks Hq 1Compact Wp Audio Player Jun 17, 2026 Oct 18, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 The Compact WP Audio Player WordPress plugin before 1.9.7 does not escape some of its shortcodes attributes, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks. |
The PDF Flipbook, 3D Flipbook WordPress – DearFlip WordPress plugin before 1.7.10 does not escape the class attribute of its shortcode before outputting it back in an attribute, which could allow users with a role as low...Show more |
The LearnPress WordPress plugin before 4.1.3.1 does not properly sanitize or escape various inputs within course settings, which could allow high privilege users to perform Cross-Site Scripting attacks when the unfiltred...Show more |
The One User Avatar WordPress plugin before 2.3.7 does not escape the link and target attributes of its shortcode, allowing users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks |
1Scroll Banner Project 1Scroll Banner Jun 17, 2026 Oct 18, 2021 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 The Scroll Baner WordPress plugin through 1.0 does not have CSRF check in place when saving its settings, nor perform any sanitisation, escaping or validation on them. This could allow attackers to make logged in admin c...Show more |
1Emarketdesign 1Customer Service Software & Support Ticket System Jun 17, 2026 Oct 18, 2021 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 The Customer Service Software & Support Ticket System WordPress plugin before 5.10.4 does not sanitize or escape form fields before outputting it in the List, which could allow high privilege users to perform Cross-Site...Show more |
1Gamepress Project 1Gamepress Jun 17, 2026 Oct 18, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The GamePress WordPress plugin through 1.1.0 does not escape the op_edit POST parameter before outputting it back in multiple Game Option pages, leading to Reflected Cross-Site Scripting issues |
1Wechat Reward Project 1Wechat Reward Jun 17, 2026 Oct 18, 2021 N/A· v4 5.4 MEDIUM· v3 4.3 MEDIUM· v2 The Wechat Reward WordPress plugin through 1.7 does not sanitise or escape its QR settings, nor has any CSRF check in place, allowing attackers to make a logged in admin change the settings and perform Cross-Site Scripti...Show more |
The Sociable WordPress plugin through 4.3.4.1 does not sanitise or escape some of its settings before outputting them in the admins dashboard, allowing high privilege users to perform Cross-Site Scripting attacks against...Show more |
1Wp Cookie Choice Project 1Wp Cookie Choice Jun 17, 2026 Oct 18, 2021 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 The Wp Cookie Choice WordPress plugin through 1.1.0 is lacking any CSRF check when saving its options, and do not escape them when outputting them in attributes. As a result, an attacker could make a logged in admin chan...Show more |
The PlanSo Forms WordPress plugin through 2.6.3 does not escape the title of its Form before outputting it in attributes, allowing high privilege users such as admin to set XSS payload in it, even when the unfiltered_htm...Show more |