CWE-79
47,732 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (47,732)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
baserCMS is an open source content management system with a focus on Japanese language support. In affected versions there is a cross-site scripting vulnerability in the file upload function of the management system of b...Show more |
3Apple DebianFedoraproject7Debian Linux FedoraIpados+4 moreJun 17, 2026 Aug 24, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 A logic issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.0.1, iOS 15.1 and iPadOS 15.1, watchOS 8.1, tvOS 15.1. Processing maliciously crafted web content may lead to universal...Show more |
Adobe Experience Manager Cloud Service offering, as well as versions 6.5.8.0 (and below) is affected by a Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vuln...Show more |
Adobe Experience Manager Cloud Service offering, as well as versions 6.5.8.0 (and below) is affected by a Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vuln...Show more |
Multiple Cross Site Scripting (XSS) vulnerabilities exists in CXUUCMS 3.1 in the search and c parameters in (1) public/search.php and in the (2) c parameter in admin.php. |
Cross Site Scripting (XSS) vulnerability exiss in FlatCore-CMS 2.0.7 via the upload image function. |
2Debian Ledgersmb2Debian Linux LedgersmbJun 17, 2026 Aug 23, 2021 N/A· v4 9.6 CRITICAL· v3 6.8 MEDIUM· v2 LedgerSMB does not sufficiently HTML-encode error messages sent to the browser. By sending a specially crafted URL to an authenticated user, this flaw can be abused for remote code execution and information disclosure. |
2Debian Ledgersmb2Debian Linux LedgersmbJun 17, 2026 Aug 23, 2021 N/A· v4 9.6 CRITICAL· v3 6.8 MEDIUM· v2 LedgerSMB does not check the origin of HTML fragments merged into the browser's DOM. By sending a specially crafted URL to an authenticated user, this flaw can be abused for remote code execution and information disclosu...Show more |
1Erident Custom Login And Dashboard Project 1Erident Custom Login And Dashboard Jun 17, 2026 Aug 23, 2021 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 The Erident Custom Login and Dashboard WordPress plugin before 3.5.9 did not properly sanitise its settings, allowing high privilege users to use XSS payloads in them (even when the unfileted_html is disabled) |
1Simple Banner Project 1Simple Banner Jun 17, 2026 Aug 23, 2021 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 The Simple Banner WordPress plugin before 2.10.4 does not sanitise and escape one of its settings, allowing high privilege users such as admin to use Cross-Site Scripting payload even when the unfiltered_html capability...Show more |
The HD Quiz WordPress plugin before 1.8.4 does not escape some of its Answers before outputting them in attribute when generating the Quiz, which could lead to Stored Cross-Site Scripting issues |
1Contact Form 7 Captcha Project 1Contact Form 7 Captcha Jun 17, 2026 Aug 23, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 The Contact Form 7 Captcha WordPress plugin before 0.0.9 does not have any CSRF check in place when saving its settings, allowing attacker to make a logged in user with the manage_options change them. Furthermore, the se...Show more |
The WPFront Scroll Top WordPress plugin before 2.0.6.07225 does not sanitise or escape its Image ALT setting before outputting it attributes, leading to an Authenticated Stored Cross-Site Scripting issues even when the u...Show more |
The WP SMS WordPress plugin before 5.4.13 does not sanitise the "wp_group_name" parameter before outputting it back in the "Groups" page, leading to an Authenticated Stored Cross-Site Scripting issue |
The pspin_duplicate_post_save_as_new_post function of the Project Status WordPress plugin through 1.6 does not sanitise, validate or escape the post GET parameter passed to it before outputting it in an error message whe...Show more |
1Email Subscriber Project 1Email Subscriber Jun 17, 2026 Aug 23, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The kento_email_subscriber_ajax AJAX action of the Email Subscriber WordPress plugin through 1.1, does not properly sanitise, validate and escape the submitted subscribe_email and subscribe_name POST parameters, insertin...Show more |
1Kn Fix Your Title Project 1Kn Fix Your Title Jun 17, 2026 Aug 23, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 The KN Fix Your Title WordPress plugin through 1.0.1 was vulnerable to Authenticated Stored XSS in the separator field. |
The Maintenance WordPress plugin before 4.03 does not sanitise or escape some of its settings, allowing high privilege users such as admin to se Cross-Site Scripting payload in them (even when the unfiltered_html capabil...Show more |
The Charitable – Donation Plugin WordPress plugin before 1.6.51 is affected by an authenticated stored cross-site scripting vulnerability which was found in the add donation feature. |
The Grid Gallery – Photo Image Grid Gallery WordPress plugin before 1.2.5 does not properly sanitize the title field for image galleries when adding them via the admin dashboard, resulting in an authenticated Stored Cros...Show more |