CWE-79
47,733 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (47,733)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Followistic 1Smart Email Alerts Jun 17, 2026 Aug 16, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The Smart Email Alerts WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the api_key in the ~/views/settings.php file which allows attackers to inject arbitrary web scripts, in versions up to and inclu...Show more |
The SEOPress WordPress plugin is vulnerable to Stored Cross-Site-Scripting via the processPut function found in the ~/src/Actions/Api/TitleDescriptionMeta.php file which allows authenticated attackers to inject arbitrary...Show more |
2Ivanti Pulsesecure2Connect Secure Pulse Connect SecureJun 17, 2026 Aug 16, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 A vulnerability in Pulse Connect Secure before 9.1R12 could allow a threat actor to perform a cross-site script attack against an authenticated administrator via an unsanitized web parameter. |
Cross Site Scripting (XSS) in Quokka v0.4.0 allows remote attackers to execute arbitrary code via the 'Username' parameter in the component 'quokka/admin/actions.py'. |
Cross Site Scripting (XSS) in Lin-CMS-Flask v0.1.1 allows remote attackers to execute arbitrary code by entering scripts in the the 'Username' parameter of the in component 'app/api/cms/user.py'. |
1Hospital Management System Project 1Hospital Management System Jun 17, 2026 Aug 16, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Persistent cross-site scripting (XSS) in Hospital Management System targeted towards web admin through contact.php. |
1Hospital Management System Project 1Hospital Management System Jun 17, 2026 Aug 16, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Persistent cross-site scripting (XSS) in Hospital Management System targeted towards web admin through prescribe.php. |
1Online Catering Reservation System Project 1Online Catering Reservation System Jun 17, 2026 Aug 16, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 A cross-site scripting (XSS) vulnerability in Online Catering Reservation System using PHP on Sourcecodester allows an attacker to arbitrarily inject code in the search bar. |
Crocoblock JetEngine before 2.6.1 allows XSS by remote authenticated users via a custom form input. |
The Mimetic Books WordPress plugin through 0.2.13 was vulnerable to Authenticated Stored Cross-Site Scripting (XSS) in the "Default Publisher ID" field on the plugin's settings page. |
1Wonderplugin 1Wonder Pdf Embed Jun 17, 2026 Aug 16, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 The Wonder PDF Embed WordPress plugin before 1.7 does not escape parameters of its wonderplugin_pdf shortcode, which could allow users with a role as low as Contributor to perform Stored XSS attacks. |
1Wonderplugin 1Wonder Video Embed Jun 17, 2026 Aug 16, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 The Wonder Video Embed WordPress plugin before 1.8 does not escape parameters of its wonderplugin_video shortcode, which could allow users with a role as low as Contributor to perform Stored XSS attacks. |
1Current Book Project 1Current Book Jun 17, 2026 Aug 16, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 The Current Book WordPress plugin through 1.0.1 does not sanitize user input when an authenticated user adds Author or Book Title, then does not escape these values when outputting to the browser leading to an Authentica...Show more |
1Custom Login Redirect Project 1Custom Login Redirect Jun 17, 2026 Aug 16, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The Custom Login Redirect WordPress plugin through 1.0.0 does not have CSRF check in place when saving its settings, and do not sanitise or escape user input before outputting them back in the page, leading to a Stored C...Show more |
1Light Messages Project 1Light Messages Jun 17, 2026 Aug 16, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The Light Messages WordPress plugin through 1.0 is lacking CSRF check when updating it's settings, and is not sanitising its Message Content in them (even with the unfiltered_html disallowed). As a result, an attacker co...Show more |
1Phonetrack 1Phonetrack Meu Site Manager Jun 17, 2026 Aug 16, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 The PhoneTrack Meu Site Manager WordPress plugin through 0.1 does not sanitise or escape its "php_id" setting before outputting it back in an attribute in the page, leading to a stored Cross-Site Scripting issue. |
The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder WordPress plugin before 1.13.60 does not escape its Form Title before outputting it in an attribute when editing a form in the admin dashboard, l...Show more |
1Vikwp 1Car Rental Management System Jun 17, 2026 Aug 16, 2021 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 The VikRentCar Car Rental Management System WordPress plugin before 1.1.10 does not sanitise the 'Text Next to Icon' field when adding or editing a Characteristic, allowing high privilege users such as admin to use XSS p...Show more |
The WPFront Notification Bar WordPress plugin before 2.0.0.07176 does not sanitise or escape its Custom CSS setting, allowing high privilege users such as admin to set XSS payload in it even when the unfiltered_html capa...Show more |
1Videowhisper 1Video Posts Webcam Recorder Jun 17, 2026 Aug 16, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 The Video Posts Webcam Recorder WordPress plugin before 3.2.4 has an authenticated reflected cross site scripting (XSS) vulnerability in one of the administrative functions for handling deletion of videos. |