CWE-79
47,728 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (47,728)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Ibm 1Tivoli Netcool/omnibus Webgui Jun 17, 2026 Sep 20, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 IBM Jazz for Service Management and IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the in...Show more |
1Ibm 1Tivoli Netcool/omnibus Webgui Jun 17, 2026 Sep 20, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 IBM Jazz for Service Management and IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the in...Show more |
1Limit Login Attempts Project 1Limit Login Attempts Jun 17, 2026 Sep 20, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The Limit Login Attempts WordPress plugin before 4.0.50 does not escape the IP addresses (which can be controlled by attacker via headers such as X-Forwarded-For) of attempted logins before outputting them in the reports...Show more |
The WordPress Slider Block Gutenslider plugin before 5.2.0 does not escape the minWidth attribute of a Gutenburg block, which could allow users with a role as low as contributor to perform Cross-Site Scripting attacks |
The Google Fonts Typography WordPress plugin before 3.0.3 does not escape and sanitise some of its block settings, allowing users with as role as low as Contributor to perform Stored Cross-Site Scripting attacks via bloc...Show more |
The Donate With QRCode WordPress plugin before 1.4.5 does not sanitise or escape its QRCode Image setting, which result into a Stored Cross-Site Scripting (XSS). Furthermore, the plugin also does not have any CSRF and ca...Show more |
The Post Views Counter WordPress plugin before 1.3.5 does not sanitise or escape its Post Views Label settings, which could allow high privilege users to perform Cross-Site Scripting attacks in the frontend even when the...Show more |
1Wp Mapa Politico Espana Project 1Wp Mapa Politico Espana Jun 17, 2026 Sep 20, 2021 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 The WP Mapa Politico Espana WordPress plugin before 3.7.0 does not sanitise or escape some of its settings before outputting them in attributes, allowing high privilege users to perform Cross-Site Scripting attacks even...Show more |
1Offshorewebmaster 1Availability Calendar Jun 17, 2026 Sep 20, 2021 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 The Availability Calendar WordPress plugin before 1.2.2 does not sanitise or escape its Category Names before outputting them in page/post where the associated shortcode is embed, allowing high privilege users to perform...Show more |
The WP Dialog WordPress plugin through 1.2.5.5 does not sanitise and escape some of its settings before outputting them in pages, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfilt...Show more |
The You Shang WordPress plugin through 1.0.1 does not escape its qrcode links settings, which result into Stored Cross-Site Scripting issues in frontend posts and the plugins settings page depending on the payload used |
1Itservicejung 1Youforms Free For Copecart Jun 17, 2026 Sep 20, 2021 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 The youForms for WordPress plugin through 1.0.5 does not sanitise escape the Button Text field of its Templates, allowing high privilege users (editors and admins) to perform Cross-Site Scripting attacks even when the un...Show more |
The Splash Header WordPress plugin before 1.20.8 doesn't sanitise and escape some of its settings while outputting them in the admin dashboard, leading to an authenticated Stored Cross-Site Scripting issue. |
1Motopress 1Timetable And Event Schedule Jun 17, 2026 Sep 20, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 The Timetable and Event Schedule WordPress plugin before 2.4.2 does not have proper access control when updating a timeslot, allowing any user with the edit_posts capability (contributor+) to update arbitrary timeslot fr...Show more |
The ThinkTwit WordPress plugin before 1.7.1 did not sanitise or escape its "Consumer key" setting before outputting it its settings page, leading to a Stored Cross-Site Scripting issue. |
The Alojapro Widget WordPress plugin through 1.1.15 doesn't properly sanitise its Custom CSS settings, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is dis...Show more |
1Getshortcodes 1Shortcodes Ultimate Jun 17, 2026 Sep 20, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 The Shortcodes Ultimate WordPress plugin before 5.10.2 allows users with Contributor roles to perform stored XSS via shortcode attributes. Note: the plugin is inconsistent in its handling of shortcode attributes; some do...Show more |
1Ericsson 1Enterprise Content Management Jun 17, 2026 Sep 17, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 In Ericsson ECM before 18.0, it was observed that Security Management Endpoint in User Profile Management Section is vulnerable to stored XSS via a name, leading to session hijacking and full account takeover. |
A stored cross-site scripting issue impacts certain areas of the Web UI for Code Insight v7.x releases up to and including 2020 R1 (7.11.0-64). |
adminlte is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |