CWE-79
47,730 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (47,730)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The Email Encoder – Protect Email Addresses WordPress plugin before 2.1.2 has an endpoint that requires no authentication and will render a user supplied value in the HTML response without escaping or sanitizing the data...Show more |
The Highlight WordPress plugin before 0.9.3 does not sanitise its CustomCSS setting, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed |
1Gdprinfo 1Cookie Notice & Consent Banner For Gdpr & Ccpa Compliance Jun 17, 2026 Sep 6, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 The Cookie Notice & Consent Banner for GDPR & CCPA Compliance WordPress plugin before 1.7.2 does not properly sanitize inputs to prevent injection of arbitrary HTML within the plugin's design customization options. |
1Cozyvision 1Sms Alert Order Notifications Jun 17, 2026 Sep 6, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The SMS Alert Order Notifications WordPress plugin before 3.4.7 is affected by a cross site scripting (XSS) vulnerability in the plugin's setting page. |
1Addtoany 1Addtoany Share Buttons Jun 17, 2026 Sep 6, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 The AddToAny Share Buttons WordPress plugin before 1.7.46 does not sanitise its Sharing Header setting when outputting it in frontend pages, allowing high privilege users such as admin to perform Cross-Site Scripting att...Show more |
The Stop Spammers Security | Block Spam Users, Comments, Forms WordPress plugin before 2021.18 does not escape some of its settings, allowing high privilege users such as admin to set Cross-Site Scripting payloads in the...Show more |
The Form Builder | Create Responsive Contact Forms WordPress plugin before 1.9.8.4 does not sanitise or escape its Form Title, allowing high privilege users such as admin to set Cross-Site Scripting payload in them, even...Show more |
The iframe-font-preview.php file of the titan-framework does not properly escape the font-weight and font-family GET parameters before outputting them back in an href attribute, leading to Reflected Cross-Site Scripting...Show more |
1Johndatserakis 1File Upload With Preview Jun 17, 2026 Sep 5, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 This affects the package file-upload-with-preview before 4.2.0. A file containing malicious JavaScript code in the name can be uploaded (a user needs to be tricked into uploading such a file). |
ViewCommon.java in JForum2 2.7.0 allows XSS via a user signature. |
A reflected XSS vulnerability exists in multiple pages in version 22 of the Gibbon application that allows for arbitrary execution of JavaScript (gibbonCourseClassID, gibbonPersonID, subpage, currentDate, or allStudents...Show more |
1Cybernetikz 1Easy Social Icons Jun 17, 2026 Sep 2, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The Easy Social Icons plugin <= 3.0.8 for WordPress echoes out the raw value of `$_SERVER['PHP_SELF']` in its main file. On certain configurations including Apache+modPHP this makes it possible to use it to perform a ref...Show more |
Cross Site Scripting vulnerability in markdown interpreter of Apache Zeppelin allows an attacker to inject malicious scripts. This issue affects Apache Zeppelin Apache Zeppelin versions prior to 0.9.0. |
1Cisco 1Identity Services Engine Jun 17, 2026 Sep 2, 2021 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) Software could allow an authenticated, remote attacker with administrative credentials to conduct a cross-site scripting (XSS)...Show more |
1Cisco 1Prime Collaboration Provisioning Jun 17, 2026 Sep 2, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 A vulnerability in the web-based management interface of Cisco Prime Collaboration Provisioning could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interfa...Show more |
WTCMS 1.0 contains a stored cross-site scripting (XSS) vulnerability in the link address field under the background links module. |
WTCMS 1.0 contains a stored cross-site scripting (XSS) vulnerability in the link field under the background menu management module. |
WTCMS 1.0 contains a stored cross-site scripting (XSS) vulnerability in the source field under the article management module. |
WTCMS 1.0 contains a reflective cross-site scripting (XSS) vulnerability in the page management background which allows attackers to obtain cookies via a crafted payload entered into the search box. |
WTCMS 1.0 contains a reflective cross-site scripting (XSS) vulnerability in the keyword search function under the background articles module. |