← Back
CWE-79

47,730 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (47,730)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1User Activation Email Project
1User Activation Email
Jun 17, 2026
Sep 9, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The User Activation Email WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the uae-key parameter found in the ~/user-activation-email.php file which allows attackers to inject arbitrary web scripts, i...Show more
The User Activation Email WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the uae-key parameter found in the ~/user-activation-email.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.3.0.Show less
130lines
1Rentpress
Jun 17, 2026
Sep 9, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The RentPress WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the selections parameter found in the ~/src/rentPress/AjaxRequests.php file which allows attackers to inject arbitrary web scripts, in ve...Show more
The RentPress WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the selections parameter found in the ~/src/rentPress/AjaxRequests.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 6.6.4.Show less
1Twitter Friends Widget Project
1Twitter Friends Widget
Jun 17, 2026
Sep 9, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Twitter Friends Widget WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the pmc_TF_user and pmc_TF_password parameter found in the ~/twitter-friends-widget.php file which allows attackers to injec...Show more
The Twitter Friends Widget WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the pmc_TF_user and pmc_TF_password parameter found in the ~/twitter-friends-widget.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 3.1.Show less
1Custom Sub Menus Project
1Custom Sub Menus
Jun 17, 2026
Sep 9, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Custom Menu Plugin WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the selected_menu parameter found in the ~/custom-menus.php file which allows attackers to inject arbitrary web scripts, in vers...Show more
The Custom Menu Plugin WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the selected_menu parameter found in the ~/custom-menus.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.3.3.Show less
1Simplesamlphp Authentication Project
1Simplesamlphp Authentication
Jun 17, 2026
Sep 9, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The simpleSAMLphp Authentication WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to a reflected $_SERVER["PHP_SELF"] value in the ~/simplesamlphp-authentication.php file which allows attackers to inj...Show more
The simpleSAMLphp Authentication WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to a reflected $_SERVER["PHP_SELF"] value in the ~/simplesamlphp-authentication.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 0.7.0.Show less
1Windyroad
1More From Google
Jun 17, 2026
Sep 9, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The More From Google WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to a reflected $_SERVER["PHP_SELF"] value in the ~/morefromgoogle.php file which allows attackers to inject arbitrary web scripts,...Show more
The More From Google WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to a reflected $_SERVER["PHP_SELF"] value in the ~/morefromgoogle.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 0.0.2.Show less
13d Cover Carousel Project
13d Cover Carousel
Jun 17, 2026
Sep 9, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The 3D Cover Carousel WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the id parameter in the ~/cover-carousel.php file which allows attackers to inject arbitrary web scripts, in versions up to and i...Show more
The 3D Cover Carousel WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the id parameter in the ~/cover-carousel.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.0.Show less
1Kibokolabs
1Konnichiwa
Jun 17, 2026
Sep 9, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Konnichiwa! Membership WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the plan_id parameter in the ~/views/subscriptions.html.php file which allows attackers to inject arbitrary web scripts, in...Show more
The Konnichiwa! Membership WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the plan_id parameter in the ~/views/subscriptions.html.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 0.8.3.Show less
1Wp Academic People List Project
1Wp Academic People List
Jun 17, 2026
Sep 9, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The WP Academic People List WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the category_name parameter in the ~/admin-panel.php file which allows attackers to inject arbitrary web scripts, in versio...Show more
The WP Academic People List WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the category_name parameter in the ~/admin-panel.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 0.4.1.Show less
1Dswjcms Project
1Dswjcms
Jun 17, 2026
Sep 9, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A stored cross-site scripting (XSS) vulnerability in the index.php/Dswjcms/Site/articleList component of Dswjcms 1.6.4 allows attackers to execute arbitrary web scripts or HTML.
1Dswjcms Project
1Dswjcms
Jun 17, 2026
Sep 9, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A stored cross-site scripting (XSS) vulnerability in the index.php/Dswjcms/Basis/links component of Dswjcms 1.6.4 allows attackers to execute arbitrary web scripts or HTML.
1Qdpm
1Qdpm
Jun 17, 2026
Sep 9, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
qdPM V9.1 is vulnerable to Cross Site Scripting (XSS) via qdPM\install\modules\database_config.php.
1Rittal
1Cmc Pu Iii 7030.000 Firmware
Jun 17, 2026
Sep 9, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Rittal CMC PU III Web management (version V3.11.00_2) fails to sanitize user input on several parameters of the configuration (User Configuration dialog, Task Configuration dialog and set logging filter dialog). This all...Show more
Rittal CMC PU III Web management (version V3.11.00_2) fails to sanitize user input on several parameters of the configuration (User Configuration dialog, Task Configuration dialog and set logging filter dialog). This allows an attacker to backdoor the device with HTML and browser-interpreted content (such as JavaScript or other client-side scripts). The XSS payload will be triggered when the user accesses some specific sections of the application.Show less
1Codecabin
1Wp Go Maps
Jun 17, 2026
Sep 9, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Multiple Authenticated Persistent Cross-Site Scripting (XSS) vulnerabilities in WordPress WP Google Maps Pro premium plugin (versions <= 8.1.11). Vulnerable parameters: &wpgmaps_marker_category_name, Value > &attributes[...Show more
Multiple Authenticated Persistent Cross-Site Scripting (XSS) vulnerabilities in WordPress WP Google Maps Pro premium plugin (versions <= 8.1.11). Vulnerable parameters: &wpgmaps_marker_category_name, Value > &attributes[], Name > &attributes[], &icons[], &names[], &description, &link, &title.Show less
1Codecabin
1Wp Go Maps
Jun 17, 2026
Sep 9, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Multiple Authenticated Persistent Cross-Site Scripting (XSS) vulnerabilities in WordPress WP Google Maps plugin (versions <= 8.1.12). Vulnerable parameters: &dataset_name, &wpgmza_gdpr_retention_purpose, &wpgmza_gdpr_com...Show more
Multiple Authenticated Persistent Cross-Site Scripting (XSS) vulnerabilities in WordPress WP Google Maps plugin (versions <= 8.1.12). Vulnerable parameters: &dataset_name, &wpgmza_gdpr_retention_purpose, &wpgmza_gdpr_company_name, &name #2, &name, &polyname #2, &polyname, &address.Show less
1Librenms
1Librenms
Jun 17, 2026
Sep 8, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
In LibreNMS < 21.3.0, a stored XSS vulnerability was identified in the API Access page due to insufficient sanitization of the $api->description variable. As a result, arbitrary Javascript code can get executed.
1Paloaltonetworks
1Pan Os
Jun 17, 2026
Sep 8, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A reflected cross-site scripting (XSS) vulnerability in the Palo Alto Network PAN-OS web interface enables an authenticated network-based attacker to mislead another authenticated PAN-OS administrator to click on a speci...Show more
A reflected cross-site scripting (XSS) vulnerability in the Palo Alto Network PAN-OS web interface enables an authenticated network-based attacker to mislead another authenticated PAN-OS administrator to click on a specially crafted link that performs arbitrary actions in the PAN-OS web interface as the targeted authenticated administrator. This issue impacts: PAN-OS 8.1 versions earlier than 8.1.20; PAN-OS 9.0 versions earlier than 9.0.14; PAN-OS 9.1 versions earlier than 9.1.10; PAN-OS 10.0 versions earlier than 10.0.2. This issue does not affect Prisma Access.Show less
1Apple
6Ipados
Iphone OsMacos+3 more
Jun 17, 2026
Sep 8, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A logic issue was addressed with improved state management. This issue is fixed in tvOS 14.6, iOS 14.6 and iPadOS 14.6, Safari 14.1.1, macOS Big Sur 11.4, watchOS 7.5. Processing maliciously crafted web content may lead...Show more
A logic issue was addressed with improved state management. This issue is fixed in tvOS 14.6, iOS 14.6 and iPadOS 14.6, Safari 14.1.1, macOS Big Sur 11.4, watchOS 7.5. Processing maliciously crafted web content may lead to universal cross site scripting.Show less
1Apple
5Ipados
Iphone OsMacos+2 more
Jun 17, 2026
Sep 8, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A logic issue was addressed with improved restrictions. This issue is fixed in macOS Big Sur 11.3, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5. Processing maliciously crafted web content may lead to universal cross...Show more
A logic issue was addressed with improved restrictions. This issue is fixed in macOS Big Sur 11.3, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5. Processing maliciously crafted web content may lead to universal cross site scripting.Show less
1Apple
8Icloud
IpadosIphone Os+5 more
Jun 17, 2026
Sep 8, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An input validation issue was addressed with improved input validation. This issue is fixed in iTunes 12.11.3 for Windows, iCloud for Windows 12.3, macOS Big Sur 11.3, Safari 14.1, watchOS 7.4, tvOS 14.5, iOS 14.5 and iP...Show more
An input validation issue was addressed with improved input validation. This issue is fixed in iTunes 12.11.3 for Windows, iCloud for Windows 12.3, macOS Big Sur 11.3, Safari 14.1, watchOS 7.4, tvOS 14.5, iOS 14.5 and iPadOS 14.5. Processing maliciously crafted web content may lead to a cross site scripting attack.Show less