← Back
CWE-79

47,819 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (47,819)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Any Hostname Project
1Any Hostname
Jun 17, 2026
Aug 2, 2021
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The Any Hostname WordPress plugin through 1.0.6 does not sanitise or escape its "Allowed hosts" setting, leading to an authenticated stored XSS issue as high privilege users are able to set XSS payloads in it
1Event Geek Project
1Event Geek
Jun 17, 2026
Aug 2, 2021
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The Event Geek WordPress plugin through 2.5.2 does not sanitise or escape its "Use your own " setting before outputting it in the page, leading to an authenticated (admin+) stored Cross-Site Scripting issue
1Drawblog Project
1Drawblog
Jun 17, 2026
Aug 2, 2021
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The DrawBlog WordPress plugin through 0.90 does not sanitise or validate some of its settings before outputting them back in the page, leading to an authenticated stored Cross-Site Scripting issue
1Bookshelf Project
1Bookshelf
Jun 17, 2026
Aug 2, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The Bookshelf WordPress plugin through 2.0.4 does not sanitise or escape its "Paypal email address" setting before outputting it in the page, leading to an authenticated Stored Cross-Site Scripting issue
1Migrate Users Project
1Migrate Users
Jun 17, 2026
Aug 2, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Migrate Users WordPress plugin through 1.0.1 does not sanitise or escape its Delimiter option before outputting in a page, leading to a Stored Cross-Site Scripting issue. Furthermore, the plugin does not have CSRF ch...Show more
The Migrate Users WordPress plugin through 1.0.1 does not sanitise or escape its Delimiter option before outputting in a page, leading to a Stored Cross-Site Scripting issue. Furthermore, the plugin does not have CSRF check in place when saving its options, allowing the issue to be exploited via a CSRF attack.Show less
1Steam Group Viewer Project
1Steam Group Viewer
Jun 17, 2026
Aug 2, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The Steam Group Viewer WordPress plugin through 2.1 does not sanitise or escape its "Steam Group Address" settings before outputting it in the page, leading to an authenticated Stored Cross-Site Scripting issue
1Awesome Weather Widget Project
1Awesome Weather Widget
Jun 17, 2026
Aug 2, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Awesome Weather Widget WordPress plugin through 3.0.2 does not sanitize the id parameter of its awesome_weather_refresh AJAX action, leading to an unauthenticated Reflected Cross-Site Scripting (XSS) Vulnerability.
1Yada Wiki Project
1Yada Wiki
Jun 17, 2026
Aug 2, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The Yada Wiki WordPress plugin before 3.4.1 did not sanitise, validate or escape the anchor attribute of its shortcode, leading to a Stored Cross-Site Scripting issue
1Bozdoz
1Leaflet Map
Jun 17, 2026
Aug 2, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The Leaflet Map WordPress plugin before 3.0.0 does not escape some shortcode attributes before they are used in JavaScript code or HTML, which could allow users with a role as low as Contributors to exploit stored XSS is...Show more
The Leaflet Map WordPress plugin before 3.0.0 does not escape some shortcode attributes before they are used in JavaScript code or HTML, which could allow users with a role as low as Contributors to exploit stored XSS issuesShow less
1Wpdevart
1Youtube Embed, Playlist And Popup
Jun 17, 2026
Aug 2, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The YouTube Embed, Playlist and Popup by WpDevArt WordPress plugin before 2.3.9 did not escape, validate or sanitise some of its shortcode options, available to users with a role as low as Contributor, leading to an auth...Show more
The YouTube Embed, Playlist and Popup by WpDevArt WordPress plugin before 2.3.9 did not escape, validate or sanitise some of its shortcode options, available to users with a role as low as Contributor, leading to an authenticated Stored Cross-Site Scripting issue.Show less
1Themeum
1Tutor Lms
Jun 17, 2026
Aug 2, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The Tutor LMS – eLearning and online course solution WordPress plugin before 1.9.2 did not escape the Summary field of Announcements (when outputting it in an attribute), which can be created by users as low as Tutor Ins...Show more
The Tutor LMS – eLearning and online course solution WordPress plugin before 1.9.2 did not escape the Summary field of Announcements (when outputting it in an attribute), which can be created by users as low as Tutor Instructor. This lead to a Stored Cross-Site Scripting issue, which is triggered when viewing the Announcements list, and could result in privilege escalation when viewed by an admin.Show less
1Properfraction
1Profilepress
Jun 17, 2026
Aug 2, 2021
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The User Registration, User Profiles, Login & Membership – ProfilePress (Formerly WP User Avatar) WordPress plugin before 3.1.8 did not sanitise or escape some of its settings before saving them and outputting them back...Show more
The User Registration, User Profiles, Login & Membership – ProfilePress (Formerly WP User Avatar) WordPress plugin before 3.1.8 did not sanitise or escape some of its settings before saving them and outputting them back in the page, allowing high privilege users such as admin to set JavaScript payloads in them even when the unfiltered_html capability is disallowed, leading to an authenticated Stored Cross-Site Scripting issueShow less
1Cozmoslabs
1Profile Builder
Jun 17, 2026
Aug 2, 2021
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The User Registration & User Profile – Profile Builder WordPress plugin before 3.4.8 does not sanitise or escape its 'Modify default Redirect Delay timer' setting, allowing high privilege users to use JavaScript code in...Show more
The User Registration & User Profile – Profile Builder WordPress plugin before 3.4.8 does not sanitise or escape its 'Modify default Redirect Delay timer' setting, allowing high privilege users to use JavaScript code in it, even when the unfiltered_html capability is disallowed, leading to an authenticated Stored Cross-Site Scripting issueShow less
1Taxopress
1Taxopress
Jun 17, 2026
Aug 2, 2021
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The TaxoPress – Create and Manage Taxonomies, Tags, Categories WordPress plugin before 3.0.7.2 does not sanitise its Taxonomy description field, allowing high privilege users to set JavaScript payload in them even when t...Show more
The TaxoPress – Create and Manage Taxonomies, Tags, Categories WordPress plugin before 3.0.7.2 does not sanitise its Taxonomy description field, allowing high privilege users to set JavaScript payload in them even when the unfiltered_html capability is disallowed, leading to an authenticated Stored Cross-Site Scripting issue.Show less
1Kainelabs
1Youzify
Jun 17, 2026
Aug 2, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The About Me widget of the Youzify – BuddyPress Community, User Profile, Social Network & Membership WordPress plugin before 1.0.7 does not properly sanitise its Biography field, allowing any authenticated user to set Cr...Show more
The About Me widget of the Youzify – BuddyPress Community, User Profile, Social Network & Membership WordPress plugin before 1.0.7 does not properly sanitise its Biography field, allowing any authenticated user to set Cross-Site Scripting payloads in it, which will be executed when viewing the affected user profile. This could allow a low privilege user to gain unauthorised access to the admin side of the blog by targeting an admin, inducing them to view their profile with a malicious payload adding a rogue account for example.Show less
1Yandex
1Yandex Turbo
Jun 17, 2026
Aug 2, 2021
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The RSS for Yandex Turbo WordPress plugin through 1.30 does not sanitise or escape some of its settings before saving and outputing them in the admin dashboard, leading to an Authenticated Stored Cross-Site Scripting iss...Show more
The RSS for Yandex Turbo WordPress plugin through 1.30 does not sanitise or escape some of its settings before saving and outputing them in the admin dashboard, leading to an Authenticated Stored Cross-Site Scripting issue even when the unfiltered_html capability is disallowed.Show less
1Premio
1Mystickymenu
Jun 17, 2026
Aug 2, 2021
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The Floating Notification Bar, Sticky Menu on Scroll, and Sticky Header for Any Theme – myStickymenu WordPress plugin before 2.5.2 does not sanitise or escape its Bar Text settings, allowing hight privilege users to use...Show more
The Floating Notification Bar, Sticky Menu on Scroll, and Sticky Header for Any Theme – myStickymenu WordPress plugin before 2.5.2 does not sanitise or escape its Bar Text settings, allowing hight privilege users to use malicious JavaScript in it, leading to a Stored Cross-Site Scripting issue, which will be triggered in the plugin's setting, as well as all front-page of the blog (when the Welcome bar is active)Show less
1Openplcproject
1Openplc
Jun 17, 2026
Aug 2, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
OpenPLC runtime V3 through 2016-03-14 allows stored XSS via the Device Name to the web server's Add New Device page.
1Gtranslate
1Gtranslate
Jun 17, 2026
Jul 30, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In the Pro and Enterprise versions of GTranslate < 2.8.65, the gtranslate_request_uri_var function runs at the top of all pages and echoes out the contents of $_SERVER['REQUEST_URI']. Although this uses addslashes, and m...Show more
In the Pro and Enterprise versions of GTranslate < 2.8.65, the gtranslate_request_uri_var function runs at the top of all pages and echoes out the contents of $_SERVER['REQUEST_URI']. Although this uses addslashes, and most modern browsers automatically URLencode requests, this plugin is still vulnerable to Reflected XSS in older browsers such as Internet Explorer 9 or below, or in cases where an attacker is able to modify the request en route between the client and the server, or in cases where the user is using an atypical browsing solution.Show less
2Misp
Misp Project
2Misp
Misp
Jun 22, 2026
Jul 30, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
app/View/GalaxyElements/ajax/index.ctp in MISP 2.4.147 allows Stored XSS when viewing galaxy cluster elements in JSON format.