← Back
CWE-79

47,728 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (47,728)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ibm
1Tivoli Netcool/omnibus Webgui
Jun 17, 2026
Sep 20, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM Jazz for Service Management and IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the in...Show more
IBM Jazz for Service Management and IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 204265.Show less
1Ibm
1Tivoli Netcool/omnibus Webgui
Jun 17, 2026
Sep 20, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM Jazz for Service Management and IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the in...Show more
IBM Jazz for Service Management and IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 204264.Show less
1Limit Login Attempts Project
1Limit Login Attempts
Jun 17, 2026
Sep 20, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Limit Login Attempts WordPress plugin before 4.0.50 does not escape the IP addresses (which can be controlled by attacker via headers such as X-Forwarded-For) of attempted logins before outputting them in the reports...Show more
The Limit Login Attempts WordPress plugin before 4.0.50 does not escape the IP addresses (which can be controlled by attacker via headers such as X-Forwarded-For) of attempted logins before outputting them in the reports table, leading to an Unauthenticated Stored Cross-Site Scripting issue.Show less
1Gutenslider
1Gutenslider
Jun 17, 2026
Sep 20, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The WordPress Slider Block Gutenslider plugin before 5.2.0 does not escape the minWidth attribute of a Gutenburg block, which could allow users with a role as low as contributor to perform Cross-Site Scripting attacks
1Fontsplugin
1Fonts
Jun 17, 2026
Sep 20, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The Google Fonts Typography WordPress plugin before 3.0.3 does not escape and sanitise some of its block settings, allowing users with as role as low as Contributor to perform Stored Cross-Site Scripting attacks via bloc...Show more
The Google Fonts Typography WordPress plugin before 3.0.3 does not escape and sanitise some of its block settings, allowing users with as role as low as Contributor to perform Stored Cross-Site Scripting attacks via blockType (combined with content), align, color, variant and fontID argument of a Gutenberg block.Show less
1Wbolt
1Donate With Qrcode
Jun 17, 2026
Sep 20, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The Donate With QRCode WordPress plugin before 1.4.5 does not sanitise or escape its QRCode Image setting, which result into a Stored Cross-Site Scripting (XSS). Furthermore, the plugin also does not have any CSRF and ca...Show more
The Donate With QRCode WordPress plugin before 1.4.5 does not sanitise or escape its QRCode Image setting, which result into a Stored Cross-Site Scripting (XSS). Furthermore, the plugin also does not have any CSRF and capability checks in place when saving such setting, allowing any authenticated user (as low as subscriber), or unauthenticated user via a CSRF vector to update them and perform such attack.Show less
1Dfactory
1Post Views Counter
Jun 17, 2026
Sep 20, 2021
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The Post Views Counter WordPress plugin before 1.3.5 does not sanitise or escape its Post Views Label settings, which could allow high privilege users to perform Cross-Site Scripting attacks in the frontend even when the...Show more
The Post Views Counter WordPress plugin before 1.3.5 does not sanitise or escape its Post Views Label settings, which could allow high privilege users to perform Cross-Site Scripting attacks in the frontend even when the unfiltered_html capability is disallowedShow less
1Wp Mapa Politico Espana Project
1Wp Mapa Politico Espana
Jun 17, 2026
Sep 20, 2021
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The WP Mapa Politico Espana WordPress plugin before 3.7.0 does not sanitise or escape some of its settings before outputting them in attributes, allowing high privilege users to perform Cross-Site Scripting attacks even...Show more
The WP Mapa Politico Espana WordPress plugin before 3.7.0 does not sanitise or escape some of its settings before outputting them in attributes, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowedShow less
1Offshorewebmaster
1Availability Calendar
Jun 17, 2026
Sep 20, 2021
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The Availability Calendar WordPress plugin before 1.2.2 does not sanitise or escape its Category Names before outputting them in page/post where the associated shortcode is embed, allowing high privilege users to perform...Show more
The Availability Calendar WordPress plugin before 1.2.2 does not sanitise or escape its Category Names before outputting them in page/post where the associated shortcode is embed, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowedShow less
1Wp Dialog Project
1Wp Dialog
Jun 17, 2026
Sep 20, 2021
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The WP Dialog WordPress plugin through 1.2.5.5 does not sanitise and escape some of its settings before outputting them in pages, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfilt...Show more
The WP Dialog WordPress plugin through 1.2.5.5 does not sanitise and escape some of its settings before outputting them in pages, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.Show less
1You Shang Project
1You Shang
Jun 17, 2026
Sep 20, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The You Shang WordPress plugin through 1.0.1 does not escape its qrcode links settings, which result into Stored Cross-Site Scripting issues in frontend posts and the plugins settings page depending on the payload used
1Itservicejung
1Youforms Free For Copecart
Jun 17, 2026
Sep 20, 2021
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The youForms for WordPress plugin through 1.0.5 does not sanitise escape the Button Text field of its Templates, allowing high privilege users (editors and admins) to perform Cross-Site Scripting attacks even when the un...Show more
The youForms for WordPress plugin through 1.0.5 does not sanitise escape the Button Text field of its Templates, allowing high privilege users (editors and admins) to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowedShow less
1Zeesweb
1Splash Header
Jun 17, 2026
Sep 20, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The Splash Header WordPress plugin before 1.20.8 doesn't sanitise and escape some of its settings while outputting them in the admin dashboard, leading to an authenticated Stored Cross-Site Scripting issue.
1Motopress
1Timetable And Event Schedule
Jun 17, 2026
Sep 20, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The Timetable and Event Schedule WordPress plugin before 2.4.2 does not have proper access control when updating a timeslot, allowing any user with the edit_posts capability (contributor+) to update arbitrary timeslot fr...Show more
The Timetable and Event Schedule WordPress plugin before 2.4.2 does not have proper access control when updating a timeslot, allowing any user with the edit_posts capability (contributor+) to update arbitrary timeslot from any events. Furthermore, no CSRF check is in place as well, allowing such attack to be perform via CSRF against a logged in with such capability. In versions before 2.3.19, the lack of sanitisation and escaping in some of the fields, like the descritption could also lead to Stored XSS issuesShow less
1Thinktwit Project
1Thinktwit
Jun 17, 2026
Sep 20, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The ThinkTwit WordPress plugin before 1.7.1 did not sanitise or escape its "Consumer key" setting before outputting it its settings page, leading to a Stored Cross-Site Scripting issue.
1Alojapro
1Alojapro Widget
Jun 17, 2026
Sep 20, 2021
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The Alojapro Widget WordPress plugin through 1.1.15 doesn't properly sanitise its Custom CSS settings, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is dis...Show more
The Alojapro Widget WordPress plugin through 1.1.15 doesn't properly sanitise its Custom CSS settings, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowedShow less
1Getshortcodes
1Shortcodes Ultimate
Jun 17, 2026
Sep 20, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The Shortcodes Ultimate WordPress plugin before 5.10.2 allows users with Contributor roles to perform stored XSS via shortcode attributes. Note: the plugin is inconsistent in its handling of shortcode attributes; some do...Show more
The Shortcodes Ultimate WordPress plugin before 5.10.2 allows users with Contributor roles to perform stored XSS via shortcode attributes. Note: the plugin is inconsistent in its handling of shortcode attributes; some do escape, most don't, and there are even some attributes that are insecure by design (like [su_button]'s onclick attribute).Show less
1Ericsson
1Enterprise Content Management
Jun 17, 2026
Sep 17, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
In Ericsson ECM before 18.0, it was observed that Security Management Endpoint in User Profile Management Section is vulnerable to stored XSS via a name, leading to session hijacking and full account takeover.
1Flexera
1Flexnet Code Insight
Jun 17, 2026
Sep 17, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A stored cross-site scripting issue impacts certain areas of the Web UI for Code Insight v7.x releases up to and including 2020 R1 (7.11.0-64).
1Pi Hole
1Web Interface
Jun 17, 2026
Sep 17, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
adminlte is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')