← Back
CWE-79

48,000 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (48,000)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Content Copy Protection & Prevent Image Save Project
1Content Copy Protection & Prevent Image Save
Jun 17, 2026
Jun 1, 2021
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
The Content Copy Protection & Prevent Image Save WordPress plugin through 1.3 does not check for CSRF when saving its settings, not perform any validation and sanitisation on them, allowing attackers to make a logged in...Show more
The Content Copy Protection & Prevent Image Save WordPress plugin through 1.3 does not check for CSRF when saving its settings, not perform any validation and sanitisation on them, allowing attackers to make a logged in administrator set arbitrary XSS payloads in them.Show less
1Smooth Scroll Page Up/down Buttons Project
1Smooth Scroll Page Up/down Buttons
Jun 17, 2026
Jun 1, 2021
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The Smooth Scroll Page Up/Down Buttons WordPress plugin before 1.4 did not properly sanitise and validate its settings, such as psb_distance, psb_buttonsize, psb_speed, only validating them client side. This could allow...Show more
The Smooth Scroll Page Up/Down Buttons WordPress plugin before 1.4 did not properly sanitise and validate its settings, such as psb_distance, psb_buttonsize, psb_speed, only validating them client side. This could allow high privilege users (such as admin) to set XSS payloads in themShow less
1Cartflows
1Cartflows
Jun 17, 2026
Jun 1, 2021
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The Funnel Builder by CartFlows – Create High Converting Sales Funnels For WordPress plugin before 1.6.13 did not sanitise its facebook_pixel_id and google_analytics_id settings, allowing high privilege users to set XSS...Show more
The Funnel Builder by CartFlows – Create High Converting Sales Funnels For WordPress plugin before 1.6.13 did not sanitise its facebook_pixel_id and google_analytics_id settings, allowing high privilege users to set XSS payload in them, which will either be executed on pages generated by the plugin, or the whole website depending on the settings used.Show less
1Automattic
1Wp Super Cache
Jun 17, 2026
Jun 1, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The WP Super Cache WordPress plugin before 1.7.3 did not properly sanitise its wp_cache_location parameter in its settings, which could lead to a Stored Cross-Site Scripting issue.
1Clogica
1Wp Login Security And History
Jun 17, 2026
Jun 1, 2021
N/A· v4
6.2 MEDIUM· v3
3.5 LOW· v2
The WP Login Security and History WordPress plugin through 1.0 did not have CSRF check when saving its settings, not any sanitisation or validation on them. This could allow attackers to make logged in administrators cha...Show more
The WP Login Security and History WordPress plugin through 1.0 did not have CSRF check when saving its settings, not any sanitisation or validation on them. This could allow attackers to make logged in administrators change the plugin's settings to arbitrary values, and set XSS payloads on them as wellShow less
1Deliciousbrains
1Database Backup
Jun 17, 2026
Jun 1, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The Database Backup for WordPress plugin before 2.4 did not escape the backup_recipient POST parameter in before output it back in the attribute of an HTML tag, leading to a Stored Cross-Site Scripting issue.
1Bold Themes
1Bello
Jun 17, 2026
Jun 1, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Bello - Directory & Listing WordPress theme before 1.6.0 did not properly sanitise and escape its listing_list_view, bt_bb_listing_field_my_lat, bt_bb_listing_field_my_lng, bt_bb_listing_field_distance_value, bt_bb_l...Show more
The Bello - Directory & Listing WordPress theme before 1.6.0 did not properly sanitise and escape its listing_list_view, bt_bb_listing_field_my_lat, bt_bb_listing_field_my_lng, bt_bb_listing_field_distance_value, bt_bb_listing_field_my_lat_default, bt_bb_listing_field_keyword, bt_bb_listing_field_location_autocomplete, bt_bb_listing_field_price_range_from and bt_bb_listing_field_price_range_to parameter in ints listing page, leading to reflected Cross-Site Scripting issues.Show less
1Bold Themes
1Bello
Jun 17, 2026
Jun 1, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The Bello - Directory & Listing WordPress theme before 1.6.0 did not properly sanitise its post_excerpt parameter before outputting it back in the shop/my-account/bello-listing-endpoint/ page, leading to a Cross-Site Scr...Show more
The Bello - Directory & Listing WordPress theme before 1.6.0 did not properly sanitise its post_excerpt parameter before outputting it back in the shop/my-account/bello-listing-endpoint/ page, leading to a Cross-Site Scripting issueShow less
1Purethemes
1Listeo
Jun 17, 2026
Jun 1, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Listeo WordPress theme before 1.6.11 did not properly sanitise some parameters in its Search, Booking Confirmation and Personal Message pages, leading to Cross-Site Scripting issues
1Wowthemes
1Mediumish
Jun 17, 2026
Jun 1, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The search feature of the Mediumish WordPress theme through 1.0.47 does not properly sanitise it's 's' GET parameter before output it back the page, leading to the Cross-SIte Scripting issue.
1Goprayer
1Wp Prayer
Jun 17, 2026
Jun 1, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The WP Prayer WordPress plugin before 1.6.2 provides the functionality to store requested prayers/praises and list them on a WordPress website. These stored prayer/praise requests can be listed by using the WP Prayer eng...Show more
The WP Prayer WordPress plugin before 1.6.2 provides the functionality to store requested prayers/praises and list them on a WordPress website. These stored prayer/praise requests can be listed by using the WP Prayer engine. An authenticated WordPress user with any role can fill in the form to request a prayer. The form to request prayers or praises have several fields. The 'prayer request' and 'praise request' fields do not use proper input validation and can be used to store XSS payloads.Show less
110web
1Photo Gallery
Jun 17, 2026
Jun 1, 2021
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The Photo Gallery by 10Web - Mobile-Friendly Image Gallery WordPress plugin before 1.5.67 did not properly sanitise the gallery title, allowing high privilege users to create one with XSS payload in it, which will be tri...Show more
The Photo Gallery by 10Web - Mobile-Friendly Image Gallery WordPress plugin before 1.5.67 did not properly sanitise the gallery title, allowing high privilege users to create one with XSS payload in it, which will be triggered when another user will view the gallery list or the affected gallery in the admin dashboard. This is due to an incomplete fix of CVE-2019-16117Show less
1Weekly Schedule Project
1Weekly Schedule
Jun 17, 2026
Jun 1, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The "Schedule Name" input in the Weekly Schedule WordPress plugin before 3.4.3 general options did not properly sanitize input, allowing a user to inject javascript code using the <script> HTML tags and cause a stored XS...Show more
The "Schedule Name" input in the Weekly Schedule WordPress plugin before 3.4.3 general options did not properly sanitize input, allowing a user to inject javascript code using the <script> HTML tags and cause a stored XSS issueShow less
2Ibm
Netapp
2Cognos Analytics
Oncommand Insight
Jun 17, 2026
Jun 1, 2021
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
IBM Cognos Analytics 11.0 and 11.1 could allow a remote attacker to inject malicious HTML code that when viewed by the authenticated victim would execute the code. IBM X-Force ID: 182395.
2Ibm
Netapp
2Cognos Analytics
Oncommand Insight
Jun 17, 2026
Jun 1, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM Cognos Analytics 11.0 and 11.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to c...Show more
IBM Cognos Analytics 11.0 and 11.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 178506.Show less
2Ibm
Netapp
2Cognos Analytics
Oncommand Insight
Jun 17, 2026
Jun 1, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM Cognos Analytics 11.0 and 11.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to c...Show more
IBM Cognos Analytics 11.0 and 11.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 170964.Show less
1Opennms
2Meridian
Opennms
Jun 17, 2026
Jun 1, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
In OpenNMS Horizon, versions opennms-1-0-stable through opennms-27.1.0-1; OpenNMS Meridian, versions meridian-foundation-2015.1.0-1 through meridian-foundation-2019.1.18-1; meridian-foundation-2020.1.0-1 through meridian...Show more
In OpenNMS Horizon, versions opennms-1-0-stable through opennms-27.1.0-1; OpenNMS Meridian, versions meridian-foundation-2015.1.0-1 through meridian-foundation-2019.1.18-1; meridian-foundation-2020.1.0-1 through meridian-foundation-2020.1.6-1 are vulnerable to Stored Cross-Site Scripting, since the function `validateFormInput()` performs improper validation checks on the input sent to the `userID` parameter. Due to this flaw an attacker could inject an arbitrary script which will be stored in the database.Show less
11cdn Project
11cdn
Jun 17, 2026
May 28, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
1CDN is open-source file sharing software. In 1CDN before commit f88a2730fa50fc2c2aeab09011f6f142fd90ec25, there is a basic cross-site scripting vulnerability that allows an attacker to inject /<script>//code</script> an...Show more
1CDN is open-source file sharing software. In 1CDN before commit f88a2730fa50fc2c2aeab09011f6f142fd90ec25, there is a basic cross-site scripting vulnerability that allows an attacker to inject /<script>//code</script> and execute JavaScript code on the client side.Show less
1Seacms
1Seacms
Jun 17, 2026
May 28, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A cross-site scripting (XSS) vulnerability has been discovered in the login page of SeaCMS version 11 which allows an attacker to inject arbitrary web script or HTML.
1Dogtagpki
1Dogtagpki
Jun 17, 2026
May 28, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A flaw was found in pki-core 10.9.0. A specially crafted POST request can be used to reflect a DOM-based cross-site scripting (XSS) attack to inject code into the search query form which can get automatically executed. T...Show more
A flaw was found in pki-core 10.9.0. A specially crafted POST request can be used to reflect a DOM-based cross-site scripting (XSS) attack to inject code into the search query form which can get automatically executed. The highest threat from this vulnerability is to data integrity.Show less