← Back
CWE-79

47,723 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (47,723)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Microsoft
1Dynamics 365
Jun 17, 2026
Oct 13, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
1Microsoft
1Dynamics 365
Jun 17, 2026
Oct 13, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Microsoft Dynamics 365 Customer Engagement Cross-Site Scripting Vulnerability
1Dzzoffice
1Dzzoffice
Jun 17, 2026
Oct 12, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A Stored Cross Site Sripting (XSS) vulnerability exists in DzzOffice 2.02.1 via the settingnew parameter.
1Sap
1Netweaver
Jun 17, 2026
Oct 12, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
SAP NetWeaver - versions 700, 701, 702, 730, does not sufficiently encode user-controlled inputs, allowing an attacker to cause a potential victim to supply a malicious content to a vulnerable web application, which is t...Show more
SAP NetWeaver - versions 700, 701, 702, 730, does not sufficiently encode user-controlled inputs, allowing an attacker to cause a potential victim to supply a malicious content to a vulnerable web application, which is then reflected to the victim and executed by the web browser, resulting in Cross-Site Scripting vulnerability.Show less
1Php Fusion
1Phpfusion
Jun 17, 2026
Oct 11, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
PHPFusion 9.03.110 is affected by cross-site scripting (XSS) in the preg patterns filter html tag without "//" in descript() function An authenticated user can trigger XSS by appending "//" in the end of text.
1Dzzoffice
1Dzzoffice
Jun 17, 2026
Oct 11, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Dzzoffice Version 2.02.1 is affected by cross-site scripting (XSS) due to a lack of sanitization of input data at all upload functions in webroot/dzz/attach/Uploader.class.php and return a wrong response in content-type...Show more
Dzzoffice Version 2.02.1 is affected by cross-site scripting (XSS) due to a lack of sanitization of input data at all upload functions in webroot/dzz/attach/Uploader.class.php and return a wrong response in content-type of output data in webroot/dzz/attach/controller.php.Show less
1Os4ed
1Opensis
Jun 17, 2026
Oct 11, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Opensis-Classic Version 8.0 is affected by cross-site scripting (XSS). An unauthenticated user can inject and execute JavaScript code through the link_url parameter in Ajax_url_encode.php.
1Projectsend
1Projectsend
Jun 17, 2026
Oct 11, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Projectsend version r1295 is affected by Cross Site Scripting (XSS) due to lack of sanitization when echo output data in returnFilesIds() function. A low privilege user can call this function through process.php file and...Show more
Projectsend version r1295 is affected by Cross Site Scripting (XSS) due to lack of sanitization when echo output data in returnFilesIds() function. A low privilege user can call this function through process.php file and execute scripting code.Show less
1Gvectors
1Wpdiscuz
Jun 17, 2026
Oct 11, 2021
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The Comments – wpDiscuz WordPress plugin through 7.3.0 does not properly sanitise or escape the Follow and Unfollow messages before outputting them in the page, which could allow high privilege users to perform Stored Cr...Show more
The Comments – wpDiscuz WordPress plugin through 7.3.0 does not properly sanitise or escape the Follow and Unfollow messages before outputting them in the page, which could allow high privilege users to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.Show less
1Ayecode
1Geodirectory
Jun 17, 2026
Oct 11, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The GeoDirectory Business Directory WordPress plugin before 2.1.1.3 was vulnerable to Authenticated Stored Cross-Site Scripting (XSS).
1Kriesi
1Enfold
Jun 17, 2026
Oct 11, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Enfold Enfold WordPress theme before 4.8.4 was vulnerable to Reflected Cross-Site Scripting (XSS). The vulnerability is present on Enfold versions previous than 4.8.4 which use Avia Page Builder.
1Dwbooster
1Appointment Hour Booking
Jun 17, 2026
Oct 11, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The Appointment Hour Booking WordPress plugin before 1.3.17 does not properly sanitize values used when creating new calendars.
1Awplife
1Weather Effect
Jun 17, 2026
Oct 11, 2021
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The Weather Effect WordPress plugin before 1.3.6 does not properly validate and escape some of its settings (like *_size_leaf, *_flakes_leaf, *_speed) which could lead to Stored Cross-Site Scripting issues
1Expresstech
1Quiz And Survey Master
Jun 17, 2026
Oct 11, 2021
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The Quiz And Survey Master WordPress plugin before 7.3.2 does not escape the Quiz Url Slug setting before outputting it in some pages, which could allow high privilege users to perform Cross-Site Scripting attacks even w...Show more
The Quiz And Survey Master WordPress plugin before 7.3.2 does not escape the Quiz Url Slug setting before outputting it in some pages, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowedShow less
1Kibokolabs
1Chained Quiz
Jun 17, 2026
Oct 11, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The Chained Quiz WordPress plugin before 1.2.7.2 does not properly sanitize or escape inputs in the plugin's settings.
1Awplife
1Weather Effect
Jun 17, 2026
Oct 11, 2021
N/A· v4
5.4 MEDIUM· v3
4.3 MEDIUM· v2
The Weather Effect WordPress plugin before 1.3.4 does not have any CSRF checks in place when saving its settings, and do not validate or escape them, which could lead to Stored Cross-Site Scripting issue.
1Duplicatepro
1Duplicate Page
Jun 17, 2026
Oct 11, 2021
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The Duplicate Page WordPress plugin through 4.4.2 does not sanitise or escape the Duplicate Post Suffix settings before outputting it, which could allow high privilege users to perform Stored Cross-Site Scripting attacks...Show more
The Duplicate Page WordPress plugin through 4.4.2 does not sanitise or escape the Duplicate Post Suffix settings before outputting it, which could allow high privilege users to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.Show less
1Wpbrigade
1Simple Social Buttons
Jun 17, 2026
Oct 11, 2021
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The Simple Social Media Share Buttons WordPress plugin before 3.2.4 does not escape the Share Title settings before outputting it in the frontend pages or posts (depending on the settings used), allowing high privilege u...Show more
The Simple Social Media Share Buttons WordPress plugin before 3.2.4 does not escape the Share Title settings before outputting it in the frontend pages or posts (depending on the settings used), allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.Show less
1Wpdevart
1Coming Soon And Maintenance Mode
Jun 17, 2026
Oct 11, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The Coming soon and Maintenance mode WordPress plugin before 3.5.3 does not properly sanitize inputs submitted by authenticated users when setting adding or modifying coming soon or maintenance mode pages, leading to sto...Show more
The Coming soon and Maintenance mode WordPress plugin before 3.5.3 does not properly sanitize inputs submitted by authenticated users when setting adding or modifying coming soon or maintenance mode pages, leading to stored XSS.Show less
1Techearty
1Easy Accordion
Jun 17, 2026
Oct 11, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The Easy Accordion WordPress plugin before 2.0.22 does not properly sanitize inputs when adding new items to an accordion.