CWE-79
47,728 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (47,728)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Cross-site Scripting (XSS) vulnerability in Stylemix Directory Listings WordPress plugin – uListing allows Reflected XSS.This issue affects Directory Listings WordPress plugin – uListing: from n/a through 2.0.5. |
1Yithemes 1Yith Maintenance Mode Jun 17, 2026 Sep 27, 2021 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities in YITH Maintenance Mode (WordPress plugin) versions <= 1.3.8, there are 46 vulnerable parameters that were missed by the vendor while patching the...Show more |
1Yithemes 1Yith Maintenance Mode Jun 17, 2026 Sep 27, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 Authenticated Stored Cross-Site Scripting (XSS) vulnerability in YITH Maintenance Mode (WordPress plugin) versions <= 1.3.7, vulnerable parameter &yith_maintenance_newsletter_submit_label. Possible even when unfiltered H...Show more |
1Mx Time Zone Clocks Project 1Mx Time Zone Clocks Jun 17, 2026 Sep 27, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 The MX Time Zone Clocks WordPress plugin before 3.4.1 does not escape the time_zone attribute of the mxmtzc_time_zone_clocks shortcode, allowing users with a role as low as Contributor to perform Stored Cross-Site Script...Show more |
The CoolClock WordPress plugin before 4.3.5 does not escape some shortcode attributes, allowing users with a role as low as Contributor toperform Stored Cross-Site Scripting attacks |
1Wpxpo 1Postx Gutenberg Blocks For Post Grid Jun 17, 2026 Sep 27, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 The PostX – Gutenberg Blocks for Post Grid WordPress plugin before 2.4.10, with Saved Templates Addon enabled, allows users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks via the plugin'...Show more |
1Wpxpo 1Postx Gutenberg Blocks For Post Grid Jun 17, 2026 Sep 27, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 The PostX – Gutenberg Blocks for Post Grid WordPress plugin before 2.4.10 allows users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks via the plugin's block. |
1Wp Map Block Project 1Wp Map Block Jun 17, 2026 Sep 27, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 The WP Map Block WordPress plugin before 1.2.3 does not escape some attributes of the WP Map Block, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks |
1Wpzoom 1Recipe Card Blocks For Gutenberg & Elementor Jun 17, 2026 Sep 27, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 The Recipe Card Blocks by WPZOOM WordPress plugin before 2.8.3 does not properly sanitise or escape some of the properties of the Recipe Card Block (such as ingredientsLayout, iconSet, steps, ingredients, recipeTitle, or...Show more |
1Wpzoom 1Recipe Card Blocks For Gutenberg & Elementor Jun 17, 2026 Sep 27, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The Recipe Card Blocks by WPZOOM WordPress plugin before 2.8.1 does not escape the message parameter before outputting it back in the admin dashboard, leading to a Reflected Cross-Site Scripting issue |
The TranslatePress WordPress plugin before 2.0.9 does not implement a proper sanitisation on the translated strings. The 'trp_sanitize_string' function only removes script tag with a regex, still allowing other HTML tags...Show more |
1Hu Manity 1Cookie Notice & Compliance For Gdpr / Ccpa Jun 17, 2026 Sep 27, 2021 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 The Cookie Notice & Compliance for GDPR / CCPA WordPress plugin before 2.1.2 does not escape the value of its Button Text setting when outputting it in an attribute in the frontend, allowing high privilege users such as...Show more |
1Hpe 6Storeonce 3620 Firmware Storeonce 3640 FirmwareStoreonce 5200 Firmware+3 moreJun 17, 2026 Sep 27, 2021 N/A· v4 6.5 MEDIUM· v3 6.0 MEDIUM· v2 A potential DOM-based Cross Site Scripting security vulnerability has been identified in HPE StoreOnce. The vulnerability could be remotely exploited to cause an elevation of privilege leading to partial impact to confid...Show more |
An issue was discovered in Concrete CMS through 8.5.5. There is unauthenticated stored XSS in blog comments via the website field. |
An issue was discovered in Concrete CMS through 8.5.5. There is XSS via Markdown Comments. |
1F5 1Big Ip Access Policy Manager Jun 17, 2026 Sep 27, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 On version 16.x before 16.1.0, 15.1.x before 15.1.4, 14.1.x before 14.1.4.4, and all versions of 13.1.x, 12.1.x, and 11.6.x, a reflected cross-site scripting (XSS) vulnerability exists in the resource information page fo...Show more |
btcpayserver is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
Shopkit v2.7 contains a reflective cross-site scripting (XSS) vulnerability in the /account/register component, which allows attackers to hijack user credentials via a crafted payload in the E-Mail text field. |
OpenNMS version 18.0.1 and prior are vulnerable to a stored XSS issue due to insufficient filtering of SNMP agent supplied data. By creating a malicious SNMP 'sysName' or 'sysContact' response, an attacker can store an X...Show more |
OpenNMS version 18.0.1 and prior are vulnerable to a stored XSS issue due to insufficient filtering of SNMP trap supplied data. By creating a malicious SNMP trap, an attacker can store an XSS payload which will trigger w...Show more |