CWE-79
47,730 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (47,730)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Feedify 1Web Push Notifications Jun 17, 2026 Sep 10, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The Feedify – Web Push Notifications WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the feedify_msg parameter found in the ~/includes/base.php file which allows attackers to inject arbitrary web scr...Show more |
1Outsidesource 1Osd Subscribe Jun 17, 2026 Sep 10, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The OSD Subscribe WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the osd_subscribe_message parameter found in the ~/options/osd_subscribe_options_subscribers.php file which allows attackers to injec...Show more |
1Spideranalyse Project 1Spideranalyse Jun 17, 2026 Sep 10, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The spideranalyse WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the date parameter found in the ~/analyse/index.php file which allows attackers to inject arbitrary web scripts, in versions up to an...Show more |
1Techastha 1Integration Of Moneybird For Woocommerce Jun 17, 2026 Sep 10, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The Integration of Moneybird for WooCommerce WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the error_description parameter found in the ~/templates/wcmb-admin.php file which allows attackers to inj...Show more |
1Advance Search Project 1Advance Search Jun 17, 2026 Sep 10, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The Advance Search WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the wpas_id parameter found in the ~/inc/admin/views/html-advance-search-admin-options.php file which allows attackers to inject arb...Show more |
1Custom Website Data Project 1Custom Website Data Jun 17, 2026 Sep 10, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The Custom Website Data WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the id parameter found in the ~/views/edit.php file which allows attackers to inject arbitrary web scripts, in versions up to a...Show more |
1Dreamfoxmedia 1Woocommerce Payment Gateway Per Category Jun 17, 2026 Sep 10, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The WooCommerce Payment Gateway Per Category WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to a reflected $_SERVER["PHP_SELF"] value in the ~/includes/plugin_settings.php file which allows attacker...Show more |
1Wordpress Simple Shop Project 1Wordpress Simple Shop Jun 17, 2026 Sep 10, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The Wordpress Simple Shop WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the update_row parameter found in the ~/includes/add_product.php file which allows attackers to inject arbitrary web scripts,...Show more |
1Devondev 1Simple Matted Thumbnails Jun 17, 2026 Sep 10, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The Simple Matted Thumbnails WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to a reflected $_SERVER["PHP_SELF"] value in the ~/simple-matted-thumbnail.php file which allows attackers to inject arbit...Show more |
1Border Loading Bar Project 1Border Loading Bar Jun 17, 2026 Sep 10, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The Border Loading Bar WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the `f` and `t` parameter found in the ~/titan-framework/iframe-googlefont-preview.php file which allows attackers to inject arb...Show more |
1Carrcommunications 1Rsvpmaker Excel Jun 17, 2026 Sep 10, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The RSVPMaker Excel WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to a reflected $_SERVER["PHP_SELF"] value in the ~/phpexcel/PHPExcel/Shared/JAMA/docs/download.php file which allows attackers to i...Show more |
The Edit Comments XT WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to a reflected $_SERVER["PHP_SELF"] value in the ~/edit-comments-xt.php file which allows attackers to inject arbitrary web script...Show more |
1Wiseagent 1Wise Agent Capture Forms Jun 17, 2026 Sep 10, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The Wise Agent Capture Forms WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to a reflected $_SERVER["PHP_SELF"] value in the ~/WiseAgentCaptureForm.php file which allows attackers to inject arbitrar...Show more |
1Amazingweb 1Wp Design Maps Places Jun 17, 2026 Sep 10, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The WP Design Maps & Places WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the filename parameter found in the ~/wpdmp-admin.php file which allows attackers to inject arbitrary web scripts, in versi...Show more |
1Wp Scrippets Project 1Wp Scrippets Jun 17, 2026 Sep 10, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The WP Scrippets WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to a reflected $_SERVER["PHP_SELF"] value in the ~/wp-scrippets.php file which allows attackers to inject arbitrary web scripts, in ve...Show more |
1Ops Robots Txt Project 1Ops Robots Txt Jun 17, 2026 Sep 10, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The On Page SEO + Whatsapp Chat Button Plugin WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to a reflected $_SERVER["PHP_SELF"] value in the ~/settings.php file which allows attackers to inject arb...Show more |
The WP-T-Wap WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the posted parameter found in the ~/wap/writer.php file which allows attackers to inject arbitrary web scripts, in versions up to and incl...Show more |
The Yet Another bol.com Plugin WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to a reflected $_SERVER["PHP_SELF"] value in the ~/yabp.php file which allows attackers to inject arbitrary web scripts,...Show more |
1Dj Emailpublish Project 1Dj Emailpublish Jun 17, 2026 Sep 10, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The DJ EmailPublish WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to a reflected $_SERVER["PHP_SELF"] value in the ~/dj-email-publish.php file which allows attackers to inject arbitrary web scripts...Show more |
The Notices WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to a reflected $_SERVER["PHP_SELF"] value in the ~/notices.php file which allows attackers to inject arbitrary web scripts, in versions up...Show more |