← Back
CWE-79

47,723 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (47,723)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Bplugins
1Streamcast Radio Player
Jun 17, 2026
Oct 18, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The StreamCast – Radio Player for WordPress plugin before 2.1.1 does not sanitise or validate the parameters from its shortcode, allowing users with a role as low as contributor to set Cross-Site Scripting payload in the...Show more
The StreamCast – Radio Player for WordPress plugin before 2.1.1 does not sanitise or validate the parameters from its shortcode, allowing users with a role as low as contributor to set Cross-Site Scripting payload in them which will be triggered in the page/s with the embed malicious shortcodeShow less
1Bplugins
1Polo Video Gallery
Jun 17, 2026
Oct 18, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The Polo Video Gallery – Best wordpress video gallery plugin WordPress plugin through 1.2 does not sanitise or validate the parameters from its shortcode, allowing users with a role as low as contributor to set Cross-Sit...Show more
The Polo Video Gallery – Best wordpress video gallery plugin WordPress plugin through 1.2 does not sanitise or validate the parameters from its shortcode, allowing users with a role as low as contributor to set Cross-Site Scripting payload in them which will be triggered in the page/s with the embed malicious shortcodeShow less
1Bplugins
1Easy Twitter Feed
Jun 17, 2026
Oct 18, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The Easy Twitter Feed WordPress plugin before 1.2 does not sanitise or validate the parameters from its shortcode, allowing users with a role as low as contributor to set Cross-Site Scripting payload in them which will b...Show more
The Easy Twitter Feed WordPress plugin before 1.2 does not sanitise or validate the parameters from its shortcode, allowing users with a role as low as contributor to set Cross-Site Scripting payload in them which will be triggered in the page/s with the embed malicious shortcodeShow less
1Bplugins
1Html5 Audio Player
Jun 17, 2026
Oct 18, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The Html5 Audio Player – Audio Player for WordPress plugin before 2.1.3 does not sanitise or validate the parameters from its shortcode, allowing users with a role as low as contributor to set Cross-Site Scripting payloa...Show more
The Html5 Audio Player – Audio Player for WordPress plugin before 2.1.3 does not sanitise or validate the parameters from its shortcode, allowing users with a role as low as contributor to set Cross-Site Scripting payload in them which will be triggered in the page/s with the embed malicious shortcodeShow less
1Rocketchat
1Rocket.chat
Jun 17, 2026
Oct 18, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A link preview rendering issue in Rocket.Chat versions before 3.9 could lead to potential XSS attacks.
1Myfactory
1Fms
Jun 17, 2026
Oct 18, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
myfactory.FMS before 7.1-912 allows XSS via the Error parameter.
1Myfactory
1Fms
Jun 17, 2026
Oct 18, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
myfactory.FMS before 7.1-912 allows XSS via the UID parameter.
1Mitsubishielectric
1Smartrtu Firmware
Nov 21, 2024
Oct 15, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Mitsubishi Electric Europe B.V. SmartRTU devices allow XSS via the username parameter or PATH_INFO to login.php.
1Adobe
1Connect
Jun 17, 2026
Oct 15, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Adobe Connect version 11.2.3 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScri...Show more
Adobe Connect version 11.2.3 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.Show less
1Author Bio Box Project
1Author Bio Box
Jun 17, 2026
Oct 15, 2021
N/A· v4
4.8 MEDIUM· v3
2.1 LOW· v2
The Author Bio Box WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and sanitization via several parameters found in the ~/includes/admin/class-author-bio-box-admin.php f...Show more
The Author Bio Box WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and sanitization via several parameters found in the ~/includes/admin/class-author-bio-box-admin.php file which allowed attackers with administrative user access to inject arbitrary web scripts, in versions up to and including 3.3.1. This affects multi-site installations where unfiltered_html is disabled for administrators, and sites where unfiltered_html is disabled.Show less
1Cnrs
1Hal
Jun 17, 2026
Oct 15, 2021
N/A· v4
4.8 MEDIUM· v3
2.1 LOW· v2
The HAL WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and sanitization via several parameters found in the ~/wp-hal.php file which allowed attackers with administrativ...Show more
The HAL WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and sanitization via several parameters found in the ~/wp-hal.php file which allowed attackers with administrative user access to inject arbitrary web scripts, in versions up to and including 2.1.1. This affects multi-site installations where unfiltered_html is disabled for administrators, and sites where unfiltered_html is disabled.Show less
1Kajoom
1Kjm Admin Notices
Jun 17, 2026
Oct 15, 2021
N/A· v4
4.8 MEDIUM· v3
2.1 LOW· v2
The KJM Admin Notices WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and sanitization via several parameters found in the ~/admin/class-kjm-admin-notices-admin.php file...Show more
The KJM Admin Notices WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and sanitization via several parameters found in the ~/admin/class-kjm-admin-notices-admin.php file which allowed attackers with administrative user access to inject arbitrary web scripts, in versions up to and including 2.0.1. This affects multi-site installations where unfiltered_html is disabled for administrators, and sites where unfiltered_html is disabled.Show less
1Mybb Cross Poster Project
1Mybb Cross Poster
Jun 17, 2026
Oct 15, 2021
N/A· v4
4.8 MEDIUM· v3
2.1 LOW· v2
The MyBB Cross-Poster WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and sanitization via several parameters found in the ~/classes/MyBBXPSettings.php file which allowe...Show more
The MyBB Cross-Poster WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and sanitization via several parameters found in the ~/classes/MyBBXPSettings.php file which allowed attackers with administrative user access to inject arbitrary web scripts, in versions up to and including 1.0. This affects multi-site installations where unfiltered_html is disabled for administrators, and sites where unfiltered_html is disabled.Show less
1Job Portal Project
1Job Portal
Jun 17, 2026
Oct 15, 2021
N/A· v4
4.8 MEDIUM· v3
2.1 LOW· v2
The job-portal WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and sanitization via several parameters found in the ~/admin/jobs_function.php file which allowed attacker...Show more
The job-portal WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and sanitization via several parameters found in the ~/admin/jobs_function.php file which allowed attackers with administrative user access to inject arbitrary web scripts, in versions up to and including 0.0.1. This affects multi-site installations where unfiltered_html is disabled for administrators, and sites where unfiltered_html is disabled.Show less
1Wp Jobmanager
1Job Manager
Jun 17, 2026
Oct 15, 2021
N/A· v4
4.8 MEDIUM· v3
2.1 LOW· v2
The Job Manager WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and sanitization via several parameters found in the ~/admin-jobs.php file which allowed attackers with a...Show more
The Job Manager WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and sanitization via several parameters found in the ~/admin-jobs.php file which allowed attackers with administrative user access to inject arbitrary web scripts, in versions up to and including 0.7.25. This affects multi-site installations where unfiltered_html is disabled for administrators, and sites where unfiltered_html is disabled.Show less
1Wpgenious
1Wpgenius Job Listing
Jun 17, 2026
Oct 15, 2021
N/A· v4
4.8 MEDIUM· v3
2.1 LOW· v2
The WpGenius Job Listing WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and sanitization via several parameters found in the ~/src/admin/class/class-wpgenious-job-listi...Show more
The WpGenius Job Listing WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and sanitization via several parameters found in the ~/src/admin/class/class-wpgenious-job-listing-options.php file which allowed attackers with administrative user access to inject arbitrary web scripts, in versions up to and including 1.0.2. This affects multi-site installations where unfiltered_html is disabled for administrators, and sites where unfiltered_html is disabled.Show less
1Perceptionsystem
1Job Board Vanila
Jun 17, 2026
Oct 15, 2021
N/A· v4
4.8 MEDIUM· v3
2.1 LOW· v2
The Job Board Vanila WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and sanitization via the psjb_exp_in and the psjb_curr_in parameters found in the ~/job-settings.php...Show more
The Job Board Vanila WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and sanitization via the psjb_exp_in and the psjb_curr_in parameters found in the ~/job-settings.php file which allowed attackers with administrative user access to inject arbitrary web scripts, in versions up to and including 1.0. This affects multi-site installations where unfiltered_html is disabled for administrators, and sites where unfiltered_html is disabled.Show less
1Bzmngr
1Business Manager
Jun 17, 2026
Oct 15, 2021
N/A· v4
4.8 MEDIUM· v3
2.1 LOW· v2
The Business Manager WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and sanitization found throughout the plugin which allowed attackers with administrative user access...Show more
The Business Manager WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and sanitization found throughout the plugin which allowed attackers with administrative user access to inject arbitrary web scripts, in versions up to and including 1.4.5. This affects multi-site installations where unfiltered_html is disabled for administrators, and sites where unfiltered_html is disabled.Show less
1Huaju
1Easytest Online Learning Test Platform
Jun 17, 2026
Oct 15, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Easytest bulletin board management function of online learning platform does not filter special characters. After obtaining a user’s privilege, remote attackers can inject JavaScript and execute stored XSS attack.
1Xinheinformation
1Xinhe Teaching Platform System
Jun 17, 2026
Oct 15, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The “List_Add” function of message board of ShinHer StudyOnline System does not filter special characters in the title parameter. After logging in with user’s privilege, remote attackers can inject JavaScript and execute...Show more
The “List_Add” function of message board of ShinHer StudyOnline System does not filter special characters in the title parameter. After logging in with user’s privilege, remote attackers can inject JavaScript and execute stored XSS attacks.Show less