← Back
CWE-79

47,728 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (47,728)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Evona
1Per Page Add To Head
Jun 17, 2026
Sep 13, 2021
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The Per page add to head WordPress plugin through 1.4.4 does not properly sanitise one of its setting, allowing malicious HTML to be inserted by high privilege users even when the unfiltered_html capability is disallowed...Show more
The Per page add to head WordPress plugin through 1.4.4 does not properly sanitise one of its setting, allowing malicious HTML to be inserted by high privilege users even when the unfiltered_html capability is disallowed, which could lead to Cross-Site Scripting issues.Show less
1Oz Plugin
1Book Appointment Online
Jun 17, 2026
Sep 13, 2021
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The Book appointment online WordPress plugin before 1.39 does not sanitise or escape Service Prices before outputting it in the List, which could allow high privilege users to perform Cross-Site Scripting attacks even wh...Show more
The Book appointment online WordPress plugin before 1.39 does not sanitise or escape Service Prices before outputting it in the List, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.Show less
1Custom Post View Generator Project
1Custom Post View Generator
Jun 17, 2026
Sep 13, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The create_post_page AJAX action of the Custom Post View Generator WordPress plugin through 0.4.6 (available to authenticated user) does not sanitise or escape user input before outputting it back in the response, leadin...Show more
The create_post_page AJAX action of the Custom Post View Generator WordPress plugin through 0.4.6 (available to authenticated user) does not sanitise or escape user input before outputting it back in the response, leading to a Reflected Cross-Site issueShow less
1Evona
1Per Page Add To Head
Jun 17, 2026
Sep 13, 2021
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
The Per page add to head WordPress plugin before 1.4.4 is lacking any CSRF check when saving its settings, which could allow attackers to make a logged in admin change them. Furthermore, as the plugin allows arbitrary HT...Show more
The Per page add to head WordPress plugin before 1.4.4 is lacking any CSRF check when saving its settings, which could allow attackers to make a logged in admin change them. Furthermore, as the plugin allows arbitrary HTML to be inserted in one of the setting (feature mentioned by the plugin), this could lead to Stored XSS issue which will be triggered either in the backend, frontend or both depending on the payload used.Show less
1Tipsandtricks Hq
1Software License Manager
Jun 17, 2026
Sep 13, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Software License Manager WordPress plugin before 4.4.8 does not sanitise or escape the edit_record parameter before outputting it back in the page in the admin dashboard, leading to a Reflected Cross-Site Scripting i...Show more
The Software License Manager WordPress plugin before 4.4.8 does not sanitise or escape the edit_record parameter before outputting it back in the page in the admin dashboard, leading to a Reflected Cross-Site Scripting issueShow less
1Mmrs151
1Daily Prayer Time
Jun 17, 2026
Sep 13, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The Daily Prayer Time WordPress plugin before 2021.08.10 does not sanitise or escape some of its settings before outputting them in the page, leading to Authenticated Stored Cross-Site Scripting issues.
1Smashballoon
1Smash Balloon Social Post Feed
Jun 17, 2026
Sep 13, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Smash Balloon Social Post Feed WordPress plugin before 2.19.2 does not sanitise or escape the feedID POST parameter in its feed_locator AJAX action (available to both authenticated and unauthenticated users) before o...Show more
The Smash Balloon Social Post Feed WordPress plugin before 2.19.2 does not sanitise or escape the feedID POST parameter in its feed_locator AJAX action (available to both authenticated and unauthenticated users) before outputting a truncated version of it in the admin dashboard, leading to an unauthenticated Stored Cross-Site Scripting issue which will be executed in the context of a logged in administrator.Show less
1Language Bar Flags Project
1Language Bar Flags
Jun 17, 2026
Sep 13, 2021
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
The Language Bar Flags WordPress plugin through 1.0.8 does not have any CSRF in place when saving its settings and did not sanitise or escape them when generating the flag bar in the frontend. This could allow attackers...Show more
The Language Bar Flags WordPress plugin through 1.0.8 does not have any CSRF in place when saving its settings and did not sanitise or escape them when generating the flag bar in the frontend. This could allow attackers to make a logged in admin change the settings, and set Cross-Site Scripting payload in them, which will be executed in the frontend for all usersShow less
1Paessler
1Prtg Network Monitor
Jun 17, 2026
Sep 13, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
PRTG Network Monitor before 21.3.69.1333 allows stored XSS via an unsanitized string imported from a User Object in a connected Active Directory instance.
1Gibbonedu
1Gibbon
Jun 17, 2026
Sep 13, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Gibbon v22.0.00 suffers from a stored XSS vulnerability within the wall messages component.
1Microfocus
1Access Manager
Jun 17, 2026
Sep 13, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Reflected Cross Site Scripting (XSS) vulnerability in NetIQ Access Manager prior to 5.0.1 and 4.5.4
1Btcpayserver
1Btcpay Server
Jun 17, 2026
Sep 10, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
btcpayserver is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
1Invitebox
1Invitebox
Jun 17, 2026
Sep 10, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The WordPress InviteBox Plugin for viral Refer-a-Friend Promotions WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the message parameter found in the ~/admin/admin.php file which allows attackers to...Show more
The WordPress InviteBox Plugin for viral Refer-a-Friend Promotions WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the message parameter found in the ~/admin/admin.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.4.1.Show less
1Kibokolabs
1Moolamojo
Jun 17, 2026
Sep 10, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The MoolaMojo WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the classes parameter found in the ~/views/button-generator.html.php file which allows attackers to inject arbitrary web scripts, in vers...Show more
The MoolaMojo WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the classes parameter found in the ~/views/button-generator.html.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 0.7.4.1.Show less
1Elyazalee
1Sms Ovh
Jun 17, 2026
Sep 10, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The SMS OVH WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the position parameter found in the ~/sms-ovh-sent.php file which allows attackers to inject arbitrary web scripts, in versions up to and i...Show more
The SMS OVH WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the position parameter found in the ~/sms-ovh-sent.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 0.1.Show less
1Bug Library Project
1Bug Library
Jun 17, 2026
Sep 10, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Bug Library WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the successimportcount parameter found in the ~/bug-library.php file which allows attackers to inject arbitrary web scripts, in version...Show more
The Bug Library WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the successimportcount parameter found in the ~/bug-library.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 2.0.3.Show less
1Gnu Mailman Integration Project
1Gnu Mailman Integration
Jun 17, 2026
Sep 10, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The GNU-Mailman Integration WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the gm_error parameter found in the ~/includes/admin/mailing-lists-page.php file which allows attackers to inject arbitrary...Show more
The GNU-Mailman Integration WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the gm_error parameter found in the ~/includes/admin/mailing-lists-page.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.0.6.Show less
1Webodid
1Dropdown And Scrollable Text
Jun 17, 2026
Sep 10, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Dropdown and scrollable Text WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the content parameter found in the ~/index.php file which allows attackers to inject arbitrary web scripts, in version...Show more
The Dropdown and scrollable Text WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the content parameter found in the ~/index.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 2.0.Show less
1Feedify
1Web Push Notifications
Jun 17, 2026
Sep 10, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Feedify – Web Push Notifications WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the feedify_msg parameter found in the ~/includes/base.php file which allows attackers to inject arbitrary web scr...Show more
The Feedify – Web Push Notifications WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the feedify_msg parameter found in the ~/includes/base.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 2.1.8.Show less
1Outsidesource
1Osd Subscribe
Jun 17, 2026
Sep 10, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The OSD Subscribe WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the osd_subscribe_message parameter found in the ~/options/osd_subscribe_options_subscribers.php file which allows attackers to injec...Show more
The OSD Subscribe WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the osd_subscribe_message parameter found in the ~/options/osd_subscribe_options_subscribers.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.2.3.Show less