← Back
CWE-79

47,733 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (47,733)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Youtube Embed Project
1Youtube Embed
Jun 17, 2026
Aug 16, 2021
N/A· v4
5.4 MEDIUM· v3
2.1 LOW· v2
The YouTube Embed WordPress plugin before 5.2.2 does not validate, escape or sanitise some of its shortcode attributes, leading to Stored XSS issues by 1. using w, h, controls, cc_lang, color, language, start, stop, or s...Show more
The YouTube Embed WordPress plugin before 5.2.2 does not validate, escape or sanitise some of its shortcode attributes, leading to Stored XSS issues by 1. using w, h, controls, cc_lang, color, language, start, stop, or style parameter of youtube shortcode, 2. by using style, class, rel, target, width, height, or alt parameter of youtube_thumb shortcode, or 3. by embedding a video whose title or description contains XSS payload (if API key is configured).Show less
1Verse O Matic Project
1Verse O Matic
Jun 17, 2026
Aug 16, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Verse-O-Matic WordPress plugin through 4.1.1 does not have any CSRF checks in place, allowing attackers to make logged in administrators do unwanted actions, such as add/edit/delete arbitrary verses and change the se...Show more
The Verse-O-Matic WordPress plugin through 4.1.1 does not have any CSRF checks in place, allowing attackers to make logged in administrators do unwanted actions, such as add/edit/delete arbitrary verses and change the settings. Due to the lack of sanitisation in the settings and verses, this could also lead to Stored Cross-Site Scripting issuesShow less
1Draftpress
1My Site Audit
Jun 17, 2026
Aug 16, 2021
N/A· v4
5.5 MEDIUM· v3
3.5 LOW· v2
The My Site Audit WordPress plugin through 1.2.4 does not sanitise or escape the Audit Name field when creating an audit, allowing high privilege users to set JavaScript payloads in them, even when he unfiltered_html cap...Show more
The My Site Audit WordPress plugin through 1.2.4 does not sanitise or escape the Audit Name field when creating an audit, allowing high privilege users to set JavaScript payloads in them, even when he unfiltered_html capability is disallowed, leading to an authenticated Stored Cross-Site Scripting issueShow less
1Social Tape Project
1Social Tape
Jun 17, 2026
Aug 16, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Social Tape WordPress plugin through 1.0 does not have CSRF checks in place when saving its settings, and do not sanitise or escape them before outputting them back in the page, leading to a stored Cross-Site Scripti...Show more
The Social Tape WordPress plugin through 1.0 does not have CSRF checks in place when saving its settings, and do not sanitise or escape them before outputting them back in the page, leading to a stored Cross-Site Scripting issue via a CSRF attackShow less
1Telugu Bible Verse Daily Project
1Telugu Bible Verse Daily
Jun 17, 2026
Aug 16, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The తెలుగు బైబిల్ వచనములు WordPress plugin through 1.0 is lacking any CSRF check when saving its settings and verses, and do not sanitise or escape them when outputting them back in the page. This could allow attackers t...Show more
The తెలుగు బైబిల్ వచనములు WordPress plugin through 1.0 is lacking any CSRF check when saving its settings and verses, and do not sanitise or escape them when outputting them back in the page. This could allow attackers to make a logged in admin change the settings, as well as add malicious verses containing JavaScript code in them, leading to Stored XSS issuesShow less
110web
1Photo Gallery
Jun 17, 2026
Aug 16, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Photo Gallery by 10Web – Mobile-Friendly Image Gallery WordPress plugin before 1.5.75 did not ensure that uploaded SVG files added to a gallery do not contain malicious content. As a result, users allowed to add imag...Show more
The Photo Gallery by 10Web – Mobile-Friendly Image Gallery WordPress plugin before 1.5.75 did not ensure that uploaded SVG files added to a gallery do not contain malicious content. As a result, users allowed to add images to gallery can upload an SVG file containing JavaScript code, which will be executed when accessing the image directly (ie in the /wp-content/uploads/photo-gallery/ folder), leading to a Cross-Site Scripting (XSS) issueShow less
1Imgurl Project
1Imgurl
Jun 17, 2026
Aug 16, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
imgURL 2.31 allows XSS via an X-Forwarded-For HTTP header.
1Compo
1Composr Cms
Jun 17, 2026
Aug 16, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In ocProducts Composr CMS before 10.0.38, an attacker can inject JavaScript via the staff_messaging messaging system for XSS.
1Compo
1Composr Cms
Jun 17, 2026
Aug 16, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
In ocProducts Composr CMS before 10.0.38, an attacker can inject JavaScript via Comcode for XSS.
1Dolibarr
1Dolibarr
Jun 17, 2026
Aug 15, 2021
N/A· v4
9.0 CRITICAL· v3
3.5 LOW· v2
In “Dolibarr ERP CRM”, WYSIWYG Editor module, v2.8.1 to v13.0.2 are affected by a stored XSS vulnerability that allows low privileged application users to store malicious scripts in the “Private Note” field at “/adherent...Show more
In “Dolibarr ERP CRM”, WYSIWYG Editor module, v2.8.1 to v13.0.2 are affected by a stored XSS vulnerability that allows low privileged application users to store malicious scripts in the “Private Note” field at “/adherents/note.php?id=1” endpoint. These scripts are executed in a victim’s browser when they open the page containing the vulnerable field. In the worst case, the victim who inadvertently triggers the attack is a highly privileged administrator. The injected scripts can extract the Session ID, which can lead to full Account takeover of the admin and due to other vulnerability (Improper Access Control on Private notes) a low privileged user can update the private notes which could lead to privilege escalation.Show less
1Tastyigniter
1Tastyigniter
Jun 17, 2026
Aug 15, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
TastyIgniter 3.0.7 allows XSS via /account, /reservation, /admin/dashboard, and /admin/system_logs.
1Dated News Project
1Dated News
Jun 17, 2026
Aug 13, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The dated_news (aka Dated News) extension through 5.1.1 for TYPO3 allows XSS.
1Yoast
1Yoast Seo
Jun 17, 2026
Aug 13, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The yoast_seo (aka Yoast SEO) extension before 7.2.3 for TYPO3 allows XSS.
1In2code
1Femanager
Jun 17, 2026
Aug 13, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The femanager extension before 5.5.1 and 6.x before 6.3.1 for TYPO3 allows XSS via a crafted SVG document.
1Miniorange
1Saml
Jun 17, 2026
Aug 13, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The miniorange_saml (aka Miniorange Saml) extension before 1.4.3 for TYPO3 allows XSS.
1Mitel
1Micollab
Jun 17, 2026
Aug 13, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Join Meeting page of Mitel MiCollab Web Client before 9.2 FP2 could allow an attacker to access (view and modify) user data by executing arbitrary code due to insufficient input validation, aka Cross-Site Scripting (...Show more
The Join Meeting page of Mitel MiCollab Web Client before 9.2 FP2 could allow an attacker to access (view and modify) user data by executing arbitrary code due to insufficient input validation, aka Cross-Site Scripting (XSS).Show less
1Openbaraza
1Openbaraza Human Capital Management
Jun 17, 2026
Aug 13, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
openBaraza HCM 3.1.6 does not properly neutralize user-controllable input: an unauthenticated remote attacker can conduct a stored cross-site scripting (XSS) attack against an administrative user from hr/subscription.jsp...Show more
openBaraza HCM 3.1.6 does not properly neutralize user-controllable input: an unauthenticated remote attacker can conduct a stored cross-site scripting (XSS) attack against an administrative user from hr/subscription.jsp and hr/application.jsp and and hr/index.jsp (with view=).Show less
1Openbaraza
1Openbaraza Human Capital Management
Jun 17, 2026
Aug 13, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
openBaraza HCM 3.1.6 does not properly neutralize user-controllable input, which allows reflected cross-site scripting (XSS) on multiple pages: hr/subscription.jsp and hr/application.jsp and and hr/index.jsp (with view=...Show more
openBaraza HCM 3.1.6 does not properly neutralize user-controllable input, which allows reflected cross-site scripting (XSS) on multiple pages: hr/subscription.jsp and hr/application.jsp and and hr/index.jsp (with view= and data=).Show less
4Ckeditor
DebianFedoraproject+1 more
12Application Express
Banking Party ManagementCkeditor+9 more
Jun 17, 2026
Aug 13, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
ckeditor is an open source WYSIWYG HTML editor with rich content support. A potential vulnerability has been discovered in CKEditor 4 [Fake Objects](https://ckeditor.com/cke4/addon/fakeobjects) package. The vulnerability...Show more
ckeditor is an open source WYSIWYG HTML editor with rich content support. A potential vulnerability has been discovered in CKEditor 4 [Fake Objects](https://ckeditor.com/cke4/addon/fakeobjects) package. The vulnerability allowed to inject malformed Fake Objects HTML, which could result in executing JavaScript code. It affects all users using the CKEditor 4 plugins listed above at version < 4.16.2. The problem has been recognized and patched. The fix will be available in version 4.16.2.Show less
1Pluxml
1Pluxml
Jun 17, 2026
Aug 12, 2021
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
PluXML 5.8.7 allows core/admin/profil.php stored XSS via the Information field.