← Back
CWE-79

47,733 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (47,733)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Followistic
1Smart Email Alerts
Jun 17, 2026
Aug 16, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Smart Email Alerts WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the api_key in the ~/views/settings.php file which allows attackers to inject arbitrary web scripts, in versions up to and inclu...Show more
The Smart Email Alerts WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the api_key in the ~/views/settings.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.0.10.Show less
1Seopress
1Seopress
Jun 17, 2026
Aug 16, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The SEOPress WordPress plugin is vulnerable to Stored Cross-Site-Scripting via the processPut function found in the ~/src/Actions/Api/TitleDescriptionMeta.php file which allows authenticated attackers to inject arbitrary...Show more
The SEOPress WordPress plugin is vulnerable to Stored Cross-Site-Scripting via the processPut function found in the ~/src/Actions/Api/TitleDescriptionMeta.php file which allows authenticated attackers to inject arbitrary web scripts, in versions 5.0.0 - 5.0.3.Show less
2Ivanti
Pulsesecure
2Connect Secure
Pulse Connect Secure
Jun 17, 2026
Aug 16, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A vulnerability in Pulse Connect Secure before 9.1R12 could allow a threat actor to perform a cross-site script attack against an authenticated administrator via an unsanitized web parameter.
1Quokka Project
1Quokka
Jun 17, 2026
Aug 16, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross Site Scripting (XSS) in Quokka v0.4.0 allows remote attackers to execute arbitrary code via the 'Username' parameter in the component 'quokka/admin/actions.py'.
1Talelin
1Lin Cms Flask
Jun 17, 2026
Aug 16, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross Site Scripting (XSS) in Lin-CMS-Flask v0.1.1 allows remote attackers to execute arbitrary code by entering scripts in the the 'Username' parameter of the in component 'app/api/cms/user.py'.
1Hospital Management System Project
1Hospital Management System
Jun 17, 2026
Aug 16, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Persistent cross-site scripting (XSS) in Hospital Management System targeted towards web admin through contact.php.
1Hospital Management System Project
1Hospital Management System
Jun 17, 2026
Aug 16, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Persistent cross-site scripting (XSS) in Hospital Management System targeted towards web admin through prescribe.php.
1Online Catering Reservation System Project
1Online Catering Reservation System
Jun 17, 2026
Aug 16, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A cross-site scripting (XSS) vulnerability in Online Catering Reservation System using PHP on Sourcecodester allows an attacker to arbitrarily inject code in the search bar.
1Crocoblock
1Jetengine
Jun 17, 2026
Aug 16, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Crocoblock JetEngine before 2.6.1 allows XSS by remote authenticated users via a custom form input.
1Mimetic
1Mimetic Books
Jun 17, 2026
Aug 16, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The Mimetic Books WordPress plugin through 0.2.13 was vulnerable to Authenticated Stored Cross-Site Scripting (XSS) in the "Default Publisher ID" field on the plugin's settings page.
1Wonderplugin
1Wonder Pdf Embed
Jun 17, 2026
Aug 16, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The Wonder PDF Embed WordPress plugin before 1.7 does not escape parameters of its wonderplugin_pdf shortcode, which could allow users with a role as low as Contributor to perform Stored XSS attacks.
1Wonderplugin
1Wonder Video Embed
Jun 17, 2026
Aug 16, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The Wonder Video Embed WordPress plugin before 1.8 does not escape parameters of its wonderplugin_video shortcode, which could allow users with a role as low as Contributor to perform Stored XSS attacks.
1Current Book Project
1Current Book
Jun 17, 2026
Aug 16, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The Current Book WordPress plugin through 1.0.1 does not sanitize user input when an authenticated user adds Author or Book Title, then does not escape these values when outputting to the browser leading to an Authentica...Show more
The Current Book WordPress plugin through 1.0.1 does not sanitize user input when an authenticated user adds Author or Book Title, then does not escape these values when outputting to the browser leading to an Authenticated Stored XSS Cross-Site Scripting issue.Show less
1Custom Login Redirect Project
1Custom Login Redirect
Jun 17, 2026
Aug 16, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Custom Login Redirect WordPress plugin through 1.0.0 does not have CSRF check in place when saving its settings, and do not sanitise or escape user input before outputting them back in the page, leading to a Stored C...Show more
The Custom Login Redirect WordPress plugin through 1.0.0 does not have CSRF check in place when saving its settings, and do not sanitise or escape user input before outputting them back in the page, leading to a Stored Cross-Site Scripting issueShow less
1Light Messages Project
1Light Messages
Jun 17, 2026
Aug 16, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Light Messages WordPress plugin through 1.0 is lacking CSRF check when updating it's settings, and is not sanitising its Message Content in them (even with the unfiltered_html disallowed). As a result, an attacker co...Show more
The Light Messages WordPress plugin through 1.0 is lacking CSRF check when updating it's settings, and is not sanitising its Message Content in them (even with the unfiltered_html disallowed). As a result, an attacker could make a logged in admin update the settings to arbitrary values, and set a Cross-Site Scripting payload in the Message Content. Depending on the options set, the XSS payload can be triggered either in the backend only (in the plugin's settings), or both frontend and backend.Show less
1Phonetrack
1Phonetrack Meu Site Manager
Jun 17, 2026
Aug 16, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The PhoneTrack Meu Site Manager WordPress plugin through 0.1 does not sanitise or escape its "php_id" setting before outputting it back in an attribute in the page, leading to a stored Cross-Site Scripting issue.
110web
1Form Maker
Jun 17, 2026
Aug 16, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder WordPress plugin before 1.13.60 does not escape its Form Title before outputting it in an attribute when editing a form in the admin dashboard, l...Show more
The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder WordPress plugin before 1.13.60 does not escape its Form Title before outputting it in an attribute when editing a form in the admin dashboard, leading to an authenticated Stored Cross-Site Scripting issueShow less
1Vikwp
1Car Rental Management System
Jun 17, 2026
Aug 16, 2021
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The VikRentCar Car Rental Management System WordPress plugin before 1.1.10 does not sanitise the 'Text Next to Icon' field when adding or editing a Characteristic, allowing high privilege users such as admin to use XSS p...Show more
The VikRentCar Car Rental Management System WordPress plugin before 1.1.10 does not sanitise the 'Text Next to Icon' field when adding or editing a Characteristic, allowing high privilege users such as admin to use XSS payload in it, leading to an authenticated Stored Cross-Site Scripting issueShow less
1Wpfront
1Notification Bar
Jun 17, 2026
Aug 16, 2021
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The WPFront Notification Bar WordPress plugin before 2.0.0.07176 does not sanitise or escape its Custom CSS setting, allowing high privilege users such as admin to set XSS payload in it even when the unfiltered_html capa...Show more
The WPFront Notification Bar WordPress plugin before 2.0.0.07176 does not sanitise or escape its Custom CSS setting, allowing high privilege users such as admin to set XSS payload in it even when the unfiltered_html capability is disallowed, leading to an authenticated Stored Cross-Site Scripting issueShow less
1Videowhisper
1Video Posts Webcam Recorder
Jun 17, 2026
Aug 16, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The Video Posts Webcam Recorder WordPress plugin before 3.2.4 has an authenticated reflected cross site scripting (XSS) vulnerability in one of the administrative functions for handling deletion of videos.