CWE-79
47,733 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (47,733)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Youtube Embed Project 1Youtube Embed Jun 17, 2026 Aug 16, 2021 N/A· v4 5.4 MEDIUM· v3 2.1 LOW· v2 The YouTube Embed WordPress plugin before 5.2.2 does not validate, escape or sanitise some of its shortcode attributes, leading to Stored XSS issues by 1. using w, h, controls, cc_lang, color, language, start, stop, or s...Show more |
1Verse O Matic Project 1Verse O Matic Jun 17, 2026 Aug 16, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The Verse-O-Matic WordPress plugin through 4.1.1 does not have any CSRF checks in place, allowing attackers to make logged in administrators do unwanted actions, such as add/edit/delete arbitrary verses and change the se...Show more |
The My Site Audit WordPress plugin through 1.2.4 does not sanitise or escape the Audit Name field when creating an audit, allowing high privilege users to set JavaScript payloads in them, even when he unfiltered_html cap...Show more |
1Social Tape Project 1Social Tape Jun 17, 2026 Aug 16, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The Social Tape WordPress plugin through 1.0 does not have CSRF checks in place when saving its settings, and do not sanitise or escape them before outputting them back in the page, leading to a stored Cross-Site Scripti...Show more |
1Telugu Bible Verse Daily Project 1Telugu Bible Verse Daily Jun 17, 2026 Aug 16, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The తెలుగు బైబిల్ వచనములు WordPress plugin through 1.0 is lacking any CSRF check when saving its settings and verses, and do not sanitise or escape them when outputting them back in the page. This could allow attackers t...Show more |
The Photo Gallery by 10Web – Mobile-Friendly Image Gallery WordPress plugin before 1.5.75 did not ensure that uploaded SVG files added to a gallery do not contain malicious content. As a result, users allowed to add imag...Show more |
imgURL 2.31 allows XSS via an X-Forwarded-For HTTP header. |
In ocProducts Composr CMS before 10.0.38, an attacker can inject JavaScript via the staff_messaging messaging system for XSS. |
In ocProducts Composr CMS before 10.0.38, an attacker can inject JavaScript via Comcode for XSS. |
In “Dolibarr ERP CRM”, WYSIWYG Editor module, v2.8.1 to v13.0.2 are affected by a stored XSS vulnerability that allows low privileged application users to store malicious scripts in the “Private Note” field at “/adherent...Show more |
TastyIgniter 3.0.7 allows XSS via /account, /reservation, /admin/dashboard, and /admin/system_logs. |
1Dated News Project 1Dated News Jun 17, 2026 Aug 13, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The dated_news (aka Dated News) extension through 5.1.1 for TYPO3 allows XSS. |
The yoast_seo (aka Yoast SEO) extension before 7.2.3 for TYPO3 allows XSS. |
The femanager extension before 5.5.1 and 6.x before 6.3.1 for TYPO3 allows XSS via a crafted SVG document. |
The miniorange_saml (aka Miniorange Saml) extension before 1.4.3 for TYPO3 allows XSS. |
The Join Meeting page of Mitel MiCollab Web Client before 9.2 FP2 could allow an attacker to access (view and modify) user data by executing arbitrary code due to insufficient input validation, aka Cross-Site Scripting (...Show more |
1Openbaraza 1Openbaraza Human Capital Management Jun 17, 2026 Aug 13, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 openBaraza HCM 3.1.6 does not properly neutralize user-controllable input: an unauthenticated remote attacker can conduct a stored cross-site scripting (XSS) attack against an administrative user from hr/subscription.jsp...Show more |
1Openbaraza 1Openbaraza Human Capital Management Jun 17, 2026 Aug 13, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 openBaraza HCM 3.1.6 does not properly neutralize user-controllable input, which allows reflected cross-site scripting (XSS) on multiple pages: hr/subscription.jsp and hr/application.jsp and and hr/index.jsp (with view=...Show more |
4Ckeditor DebianFedoraproject+1 more12Application Express Banking Party ManagementCkeditor+9 moreJun 17, 2026 Aug 13, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 ckeditor is an open source WYSIWYG HTML editor with rich content support. A potential vulnerability has been discovered in CKEditor 4 [Fake Objects](https://ckeditor.com/cke4/addon/fakeobjects) package. The vulnerability...Show more |
PluXML 5.8.7 allows core/admin/profil.php stored XSS via the Information field. |