← Back
CWE-79

47,730 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (47,730)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Wp Webhooks
1Email Encoder
Jun 17, 2026
Sep 6, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Email Encoder – Protect Email Addresses WordPress plugin before 2.1.2 has an endpoint that requires no authentication and will render a user supplied value in the HTML response without escaping or sanitizing the data...Show more
The Email Encoder – Protect Email Addresses WordPress plugin before 2.1.2 has an endpoint that requires no authentication and will render a user supplied value in the HTML response without escaping or sanitizing the data.Show less
1Dna88
1Highlight
Jun 17, 2026
Sep 6, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The Highlight WordPress plugin before 0.9.3 does not sanitise its CustomCSS setting, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
1Gdprinfo
1Cookie Notice & Consent Banner For Gdpr & Ccpa Compliance
Jun 17, 2026
Sep 6, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The Cookie Notice & Consent Banner for GDPR & CCPA Compliance WordPress plugin before 1.7.2 does not properly sanitize inputs to prevent injection of arbitrary HTML within the plugin's design customization options.
1Cozyvision
1Sms Alert Order Notifications
Jun 17, 2026
Sep 6, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The SMS Alert Order Notifications WordPress plugin before 3.4.7 is affected by a cross site scripting (XSS) vulnerability in the plugin's setting page.
1Addtoany
1Addtoany Share Buttons
Jun 17, 2026
Sep 6, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The AddToAny Share Buttons WordPress plugin before 1.7.46 does not sanitise its Sharing Header setting when outputting it in frontend pages, allowing high privilege users such as admin to perform Cross-Site Scripting att...Show more
The AddToAny Share Buttons WordPress plugin before 1.7.46 does not sanitise its Sharing Header setting when outputting it in frontend pages, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowedShow less
1Trumani
1Stop Spammers
Jun 17, 2026
Sep 6, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The Stop Spammers Security | Block Spam Users, Comments, Forms WordPress plugin before 2021.18 does not escape some of its settings, allowing high privilege users such as admin to set Cross-Site Scripting payloads in the...Show more
The Stop Spammers Security | Block Spam Users, Comments, Forms WordPress plugin before 2021.18 does not escape some of its settings, allowing high privilege users such as admin to set Cross-Site Scripting payloads in them even when the unfiltered_html capability is disallowedShow less
1Web Settler
1Form Builder
Jun 17, 2026
Sep 6, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The Form Builder | Create Responsive Contact Forms WordPress plugin before 1.9.8.4 does not sanitise or escape its Form Title, allowing high privilege users such as admin to set Cross-Site Scripting payload in them, even...Show more
The Form Builder | Create Responsive Contact Forms WordPress plugin before 1.9.8.4 does not sanitise or escape its Form Title, allowing high privilege users such as admin to set Cross-Site Scripting payload in them, even when the unfiltered_html capability is disallowedShow less
1Gambit
1Titan Framework
Jun 17, 2026
Sep 6, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The iframe-font-preview.php file of the titan-framework does not properly escape the font-weight and font-family GET parameters before outputting them back in an href attribute, leading to Reflected Cross-Site Scripting...Show more
The iframe-font-preview.php file of the titan-framework does not properly escape the font-weight and font-family GET parameters before outputting them back in an href attribute, leading to Reflected Cross-Site Scripting issuesShow less
1Johndatserakis
1File Upload With Preview
Jun 17, 2026
Sep 5, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
This affects the package file-upload-with-preview before 4.2.0. A file containing malicious JavaScript code in the name can be uploaded (a user needs to be tricked into uploading such a file).
1Jforum
1Jforum
Jun 17, 2026
Sep 4, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
ViewCommon.java in JForum2 2.7.0 allows XSS via a user signature.
1Gibbonedu
1Gibbon
Jun 17, 2026
Sep 3, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A reflected XSS vulnerability exists in multiple pages in version 22 of the Gibbon application that allows for arbitrary execution of JavaScript (gibbonCourseClassID, gibbonPersonID, subpage, currentDate, or allStudents...Show more
A reflected XSS vulnerability exists in multiple pages in version 22 of the Gibbon application that allows for arbitrary execution of JavaScript (gibbonCourseClassID, gibbonPersonID, subpage, currentDate, or allStudents to index.php).Show less
1Cybernetikz
1Easy Social Icons
Jun 17, 2026
Sep 2, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Easy Social Icons plugin <= 3.0.8 for WordPress echoes out the raw value of `$_SERVER['PHP_SELF']` in its main file. On certain configurations including Apache+modPHP this makes it possible to use it to perform a ref...Show more
The Easy Social Icons plugin <= 3.0.8 for WordPress echoes out the raw value of `$_SERVER['PHP_SELF']` in its main file. On certain configurations including Apache+modPHP this makes it possible to use it to perform a reflected Cross-Site Scripting attack by injecting malicious code in the request path.Show less
1Apache
1Zeppelin
Jun 17, 2026
Sep 2, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross Site Scripting vulnerability in markdown interpreter of Apache Zeppelin allows an attacker to inject malicious scripts. This issue affects Apache Zeppelin Apache Zeppelin versions prior to 0.9.0.
1Cisco
1Identity Services Engine
Jun 17, 2026
Sep 2, 2021
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) Software could allow an authenticated, remote attacker with administrative credentials to conduct a cross-site scripting (XSS)...Show more
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) Software could allow an authenticated, remote attacker with administrative credentials to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability exists because the web-based management interface does not properly validate user-supplied input. An attacker could exploit this vulnerability by injecting malicious code into specific pages of the interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface or access sensitive, browser-based information. To exploit this vulnerability, an attacker would need valid administrative credentials.Show less
1Cisco
1Prime Collaboration Provisioning
Jun 17, 2026
Sep 2, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A vulnerability in the web-based management interface of Cisco Prime Collaboration Provisioning could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interfa...Show more
A vulnerability in the web-based management interface of Cisco Prime Collaboration Provisioning could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability is due to insufficient validation of user-supplied input by the web-based management interface. An attacker could exploit this vulnerability by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface or access sensitive, browser-based information.Show less
1Wtcms Project
1Wtcms
Jun 17, 2026
Sep 1, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
WTCMS 1.0 contains a stored cross-site scripting (XSS) vulnerability in the link address field under the background links module.
1Wtcms Project
1Wtcms
Jun 17, 2026
Sep 1, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
WTCMS 1.0 contains a stored cross-site scripting (XSS) vulnerability in the link field under the background menu management module.
1Wtcms Project
1Wtcms
Jun 17, 2026
Sep 1, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
WTCMS 1.0 contains a stored cross-site scripting (XSS) vulnerability in the source field under the article management module.
1Wtcms Project
1Wtcms
Jul 9, 2026
Sep 1, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
WTCMS 1.0 contains a reflective cross-site scripting (XSS) vulnerability in the page management background which allows attackers to obtain cookies via a crafted payload entered into the search box.
1Wtcms Project
1Wtcms
Jun 17, 2026
Sep 1, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
WTCMS 1.0 contains a reflective cross-site scripting (XSS) vulnerability in the keyword search function under the background articles module.