← Back
CWE-79

47,732 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (47,732)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Basercms
1Basercms
Jun 17, 2026
Aug 25, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
baserCMS is an open source content management system with a focus on Japanese language support. In affected versions there is a cross-site scripting vulnerability in the file upload function of the management system of b...Show more
baserCMS is an open source content management system with a focus on Japanese language support. In affected versions there is a cross-site scripting vulnerability in the file upload function of the management system of baserCMS. Users are advised to update as soon as possible. No workaround are available to mitigate this issue.Show less
3Apple
DebianFedoraproject
7Debian Linux
FedoraIpados+4 more
Jun 17, 2026
Aug 24, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A logic issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.0.1, iOS 15.1 and iPadOS 15.1, watchOS 8.1, tvOS 15.1. Processing maliciously crafted web content may lead to universal...Show more
A logic issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.0.1, iOS 15.1 and iPadOS 15.1, watchOS 8.1, tvOS 15.1. Processing maliciously crafted web content may lead to universal cross site scripting.Show less
1Adobe
1Experience Manager
Jun 17, 2026
Aug 24, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Adobe Experience Manager Cloud Service offering, as well as versions 6.5.8.0 (and below) is affected by a Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vuln...Show more
Adobe Experience Manager Cloud Service offering, as well as versions 6.5.8.0 (and below) is affected by a Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.Show less
1Adobe
1Experience Manager
Jun 17, 2026
Aug 24, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Adobe Experience Manager Cloud Service offering, as well as versions 6.5.8.0 (and below) is affected by a Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vuln...Show more
Adobe Experience Manager Cloud Service offering, as well as versions 6.5.8.0 (and below) is affected by a Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.Show less
1Cxuu
1Cxuucms
Jun 17, 2026
Aug 23, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Multiple Cross Site Scripting (XSS) vulnerabilities exists in CXUUCMS 3.1 in the search and c parameters in (1) public/search.php and in the (2) c parameter in admin.php.
1Flatcore
1Flatcore Cms
Jun 17, 2026
Aug 23, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross Site Scripting (XSS) vulnerability exiss in FlatCore-CMS 2.0.7 via the upload image function.
2Debian
Ledgersmb
2Debian Linux
Ledgersmb
Jun 17, 2026
Aug 23, 2021
N/A· v4
9.6 CRITICAL· v3
6.8 MEDIUM· v2
LedgerSMB does not sufficiently HTML-encode error messages sent to the browser. By sending a specially crafted URL to an authenticated user, this flaw can be abused for remote code execution and information disclosure.
2Debian
Ledgersmb
2Debian Linux
Ledgersmb
Jun 17, 2026
Aug 23, 2021
N/A· v4
9.6 CRITICAL· v3
6.8 MEDIUM· v2
LedgerSMB does not check the origin of HTML fragments merged into the browser's DOM. By sending a specially crafted URL to an authenticated user, this flaw can be abused for remote code execution and information disclosu...Show more
LedgerSMB does not check the origin of HTML fragments merged into the browser's DOM. By sending a specially crafted URL to an authenticated user, this flaw can be abused for remote code execution and information disclosure.Show less
1Erident Custom Login And Dashboard Project
1Erident Custom Login And Dashboard
Jun 17, 2026
Aug 23, 2021
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The Erident Custom Login and Dashboard WordPress plugin before 3.5.9 did not properly sanitise its settings, allowing high privilege users to use XSS payloads in them (even when the unfileted_html is disabled)
1Simple Banner Project
1Simple Banner
Jun 17, 2026
Aug 23, 2021
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The Simple Banner WordPress plugin before 2.10.4 does not sanitise and escape one of its settings, allowing high privilege users such as admin to use Cross-Site Scripting payload even when the unfiltered_html capability...Show more
The Simple Banner WordPress plugin before 2.10.4 does not sanitise and escape one of its settings, allowing high privilege users such as admin to use Cross-Site Scripting payload even when the unfiltered_html capability is disallowed.Show less
1Harmonicdesign
1Hd Quiz
Jun 17, 2026
Aug 23, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The HD Quiz WordPress plugin before 1.8.4 does not escape some of its Answers before outputting them in attribute when generating the Quiz, which could lead to Stored Cross-Site Scripting issues
1Contact Form 7 Captcha Project
1Contact Form 7 Captcha
Jun 17, 2026
Aug 23, 2021
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
The Contact Form 7 Captcha WordPress plugin before 0.0.9 does not have any CSRF check in place when saving its settings, allowing attacker to make a logged in user with the manage_options change them. Furthermore, the se...Show more
The Contact Form 7 Captcha WordPress plugin before 0.0.9 does not have any CSRF check in place when saving its settings, allowing attacker to make a logged in user with the manage_options change them. Furthermore, the settings are not escaped when output in attributes, leading to a Stored Cross-Site Scripting issue.Show less
1Wpfront
1Scroll Top
Jun 17, 2026
Aug 23, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The WPFront Scroll Top WordPress plugin before 2.0.6.07225 does not sanitise or escape its Image ALT setting before outputting it attributes, leading to an Authenticated Stored Cross-Site Scripting issues even when the u...Show more
The WPFront Scroll Top WordPress plugin before 2.0.6.07225 does not sanitise or escape its Image ALT setting before outputting it attributes, leading to an Authenticated Stored Cross-Site Scripting issues even when the unfiltered_html capability is disallowed.Show less
1Veronalabs
1Wp Sms
Jun 17, 2026
Aug 23, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The WP SMS WordPress plugin before 5.4.13 does not sanitise the "wp_group_name" parameter before outputting it back in the "Groups" page, leading to an Authenticated Stored Cross-Site Scripting issue
13.7designs
1Project Status
Jun 17, 2026
Aug 23, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The pspin_duplicate_post_save_as_new_post function of the Project Status WordPress plugin through 1.6 does not sanitise, validate or escape the post GET parameter passed to it before outputting it in an error message whe...Show more
The pspin_duplicate_post_save_as_new_post function of the Project Status WordPress plugin through 1.6 does not sanitise, validate or escape the post GET parameter passed to it before outputting it in an error message when the related post does not exist, leading to a reflected XSS issueShow less
1Email Subscriber Project
1Email Subscriber
Jun 17, 2026
Aug 23, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The kento_email_subscriber_ajax AJAX action of the Email Subscriber WordPress plugin through 1.1, does not properly sanitise, validate and escape the submitted subscribe_email and subscribe_name POST parameters, insertin...Show more
The kento_email_subscriber_ajax AJAX action of the Email Subscriber WordPress plugin through 1.1, does not properly sanitise, validate and escape the submitted subscribe_email and subscribe_name POST parameters, inserting them in the DB and then outputting them back in the Subscriber list (/wp-admin/edit.php?post_type=kes_campaign&page=kento_email_subscriber_list_settings), leading a Stored XSS issue.Show less
1Kn Fix Your Title Project
1Kn Fix Your Title
Jun 17, 2026
Aug 23, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The KN Fix Your Title WordPress plugin through 1.0.1 was vulnerable to Authenticated Stored XSS in the separator field.
1Webfactoryltd
1Maintenance
Jun 17, 2026
Aug 23, 2021
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The Maintenance WordPress plugin before 4.03 does not sanitise or escape some of its settings, allowing high privilege users such as admin to se Cross-Site Scripting payload in them (even when the unfiltered_html capabil...Show more
The Maintenance WordPress plugin before 4.03 does not sanitise or escape some of its settings, allowing high privilege users such as admin to se Cross-Site Scripting payload in them (even when the unfiltered_html capability is disallowed), which will be triggered in the frontendShow less
1Wpcharitable
1Charitable
Jun 17, 2026
Aug 23, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The Charitable – Donation Plugin WordPress plugin before 1.6.51 is affected by an authenticated stored cross-site scripting vulnerability which was found in the add donation feature.
1Awplife
1Grid Gallery
Jun 17, 2026
Aug 23, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The Grid Gallery – Photo Image Grid Gallery WordPress plugin before 1.2.5 does not properly sanitize the title field for image galleries when adding them via the admin dashboard, resulting in an authenticated Stored Cros...Show more
The Grid Gallery – Photo Image Grid Gallery WordPress plugin before 1.2.5 does not properly sanitize the title field for image galleries when adding them via the admin dashboard, resulting in an authenticated Stored Cross-Site Scripting vulnerability.Show less