← Back
CWE-79

47,723 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (47,723)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Alkacon
1Opencms
Jun 17, 2026
Oct 19, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
In “OpenCMS”, versions 10.5.0 to 11.0.2 are affected by a stored XSS vulnerability that allows low privileged application users to store malicious scripts in the Sitemap functionality. These scripts are executed in a vic...Show more
In “OpenCMS”, versions 10.5.0 to 11.0.2 are affected by a stored XSS vulnerability that allows low privileged application users to store malicious scripts in the Sitemap functionality. These scripts are executed in a victim’s browser when they open the page containing the vulnerable field.Show less
1Portainer
1Portainer
Jun 17, 2026
Oct 18, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross Site Scripting (XSS vulnerability exists in Portainer before 2.9.1 via the node input box in Custom Templates.
1Timetracker Project
1Timetracker
Jun 17, 2026
Oct 18, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
anuko/timetracker is an, open source time tracking system. In affected versions Time Tracker uses browser_today hidden control on a few pages to collect the today's date from user browsers. Because of not checking this p...Show more
anuko/timetracker is an, open source time tracking system. In affected versions Time Tracker uses browser_today hidden control on a few pages to collect the today's date from user browsers. Because of not checking this parameter for sanity in versions prior to 1.19.30.5601, it was possible to craft an html form with malicious JavaScript, use social engineering to convince logged on users to execute a POST from such form, and have the attacker-supplied JavaScript to be executed in user's browser. This has been patched in version 1.19.30.5600. Upgrade is recommended. If it is not practical, introduce ttValidDbDateFormatDate function as in the latest version and add a call to it within the access checks block.Show less
1Ibm
1Business Automation Workflow
Jun 17, 2026
Oct 18, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM Business Automation Workflow 18.0, 19.0, 20.0, and 21.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality...Show more
IBM Business Automation Workflow 18.0, 19.0, 20.0, and 21.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 206581.Show less
1Apache
1Superset
Jun 17, 2026
Oct 18, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Apache Superset up to and including 1.1 does not sanitize titles correctly on the Explore page. This allows an attacker with Explore access to save a chart with a malicious title, injecting html (including scripts) into...Show more
Apache Superset up to and including 1.1 does not sanitize titles correctly on the Explore page. This allows an attacker with Explore access to save a chart with a malicious title, injecting html (including scripts) into the page.Show less
1Pdf Viewer Block For Gutenberg Project
1Pdf Viewer Block For Gutenberg
Jun 17, 2026
Oct 18, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The Gutenberg PDF Viewer Block WordPress plugin before 1.0.1 does not sanitise and escape its block, which could allow users with a role as low as Contributor to perform Cross-Site Scripting attacks.
1Secondlinethemes
1Podcast Subscribe Buttons
Jun 17, 2026
Oct 18, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The Podcast Subscribe Buttons WordPress plugin before 1.4.2 allows users with any role capable of editing or adding posts to perform stored XSS.
1Themeum
1Tutor Lms
Jun 17, 2026
Oct 18, 2021
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The Tutor LMS WordPress plugin before 1.9.9 does not escape some of its settings before outputting them in attributes, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfilter...Show more
The Tutor LMS WordPress plugin before 1.9.9 does not escape some of its settings before outputting them in attributes, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.Show less
1Tammersoft
1Shared Files
Jun 17, 2026
Oct 18, 2021
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The Easy Download Manager and File Sharing Plugin with frontend file upload – a better Media Library — Shared Files WordPress plugin before 1.6.57 does not sanitise and escape some of its settings before outputting them...Show more
The Easy Download Manager and File Sharing Plugin with frontend file upload – a better Media Library — Shared Files WordPress plugin before 1.6.57 does not sanitise and escape some of its settings before outputting them in attributes, which could lead to Stored Cross-Site Scripting issues.Show less
1Tipsandtricks Hq
1Compact Wp Audio Player
Jun 17, 2026
Oct 18, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The Compact WP Audio Player WordPress plugin before 1.9.7 does not escape some of its shortcodes attributes, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks.
1Dearhive
1Dearflip
Jun 17, 2026
Oct 18, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The PDF Flipbook, 3D Flipbook WordPress – DearFlip WordPress plugin before 1.7.10 does not escape the class attribute of its shortcode before outputting it back in an attribute, which could allow users with a role as low...Show more
The PDF Flipbook, 3D Flipbook WordPress – DearFlip WordPress plugin before 1.7.10 does not escape the class attribute of its shortcode before outputting it back in an attribute, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacksShow less
1Thimpress
1Learnpress
Jun 17, 2026
Oct 18, 2021
N/A· v4
4.8 MEDIUM· v3
2.1 LOW· v2
The LearnPress WordPress plugin before 4.1.3.1 does not properly sanitize or escape various inputs within course settings, which could allow high privilege users to perform Cross-Site Scripting attacks when the unfiltred...Show more
The LearnPress WordPress plugin before 4.1.3.1 does not properly sanitize or escape various inputs within course settings, which could allow high privilege users to perform Cross-Site Scripting attacks when the unfiltred_html capability is disallowedShow less
1Onedesigns
1One User Avatar
Jun 17, 2026
Oct 18, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The One User Avatar WordPress plugin before 2.3.7 does not escape the link and target attributes of its shortcode, allowing users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks
1Scroll Banner Project
1Scroll Banner
Jun 17, 2026
Oct 18, 2021
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
The Scroll Baner WordPress plugin through 1.0 does not have CSRF check in place when saving its settings, nor perform any sanitisation, escaping or validation on them. This could allow attackers to make logged in admin c...Show more
The Scroll Baner WordPress plugin through 1.0 does not have CSRF check in place when saving its settings, nor perform any sanitisation, escaping or validation on them. This could allow attackers to make logged in admin change them and could lead to RCE (via a file upload) as well as XSSShow less
1Emarketdesign
1Customer Service Software & Support Ticket System
Jun 17, 2026
Oct 18, 2021
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The Customer Service Software & Support Ticket System WordPress plugin before 5.10.4 does not sanitize or escape form fields before outputting it in the List, which could allow high privilege users to perform Cross-Site...Show more
The Customer Service Software & Support Ticket System WordPress plugin before 5.10.4 does not sanitize or escape form fields before outputting it in the List, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.Show less
1Gamepress Project
1Gamepress
Jun 17, 2026
Oct 18, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The GamePress WordPress plugin through 1.1.0 does not escape the op_edit POST parameter before outputting it back in multiple Game Option pages, leading to Reflected Cross-Site Scripting issues
1Wechat Reward Project
1Wechat Reward
Jun 17, 2026
Oct 18, 2021
N/A· v4
5.4 MEDIUM· v3
4.3 MEDIUM· v2
The Wechat Reward WordPress plugin through 1.7 does not sanitise or escape its QR settings, nor has any CSRF check in place, allowing attackers to make a logged in admin change the settings and perform Cross-Site Scripti...Show more
The Wechat Reward WordPress plugin through 1.7 does not sanitise or escape its QR settings, nor has any CSRF check in place, allowing attackers to make a logged in admin change the settings and perform Cross-Site Scripting attacks.Show less
1Sociable Project
1Sociable
Jun 17, 2026
Oct 18, 2021
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The Sociable WordPress plugin through 4.3.4.1 does not sanitise or escape some of its settings before outputting them in the admins dashboard, allowing high privilege users to perform Cross-Site Scripting attacks against...Show more
The Sociable WordPress plugin through 4.3.4.1 does not sanitise or escape some of its settings before outputting them in the admins dashboard, allowing high privilege users to perform Cross-Site Scripting attacks against other users even when the unfiltered_html capability is disallowedShow less
1Wp Cookie Choice Project
1Wp Cookie Choice
Jun 17, 2026
Oct 18, 2021
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
The Wp Cookie Choice WordPress plugin through 1.1.0 is lacking any CSRF check when saving its options, and do not escape them when outputting them in attributes. As a result, an attacker could make a logged in admin chan...Show more
The Wp Cookie Choice WordPress plugin through 1.1.0 is lacking any CSRF check when saving its options, and do not escape them when outputting them in attributes. As a result, an attacker could make a logged in admin change them to arbitrary values including XSS payloads via a CSRF attack.Show less
1Planso
1Planso Forms
Jun 17, 2026
Oct 18, 2021
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The PlanSo Forms WordPress plugin through 2.6.3 does not escape the title of its Form before outputting it in attributes, allowing high privilege users such as admin to set XSS payload in it, even when the unfiltered_htm...Show more
The PlanSo Forms WordPress plugin through 2.6.3 does not escape the title of its Form before outputting it in attributes, allowing high privilege users such as admin to set XSS payload in it, even when the unfiltered_html is disallowed, leading to an Authenticated Stored Cross-Site Scripting issue.Show less