← Back
CWE-79

48,003 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (48,003)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Online Examination System Project
1Online Examination System
Jun 17, 2026
May 24, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Project Worlds Online Examination System 1.0 is affected by Cross Site Scripting (XSS) via account.php.
1Arangodb
1Arangodb
Jun 17, 2026
May 24, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In ArangoDB, versions v2.2.6.2 through v3.7.10 are vulnerable to Cross-Site Scripting (XSS), since there is no validation of the .zip file name and filtering of potential abusive characters which zip files can be named t...Show more
In ArangoDB, versions v2.2.6.2 through v3.7.10 are vulnerable to Cross-Site Scripting (XSS), since there is no validation of the .zip file name and filtering of potential abusive characters which zip files can be named to. There is no X-Frame-Options Header set, which makes it more susceptible for leveraging self XSS by attackers.Show less
1Autoptimize
1Autoptimize
Jun 17, 2026
May 24, 2021
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The Autoptimize WordPress plugin before 2.8.4 was missing proper escaping and sanitisation in some of its settings, allowing high privilege users to set XSS payloads in them, leading to stored Cross-Site Scripting issues
1Lifterlms
1Lifterlms
Jun 17, 2026
May 24, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The 'State' field of the Edit profile page of the LMS by LifterLMS – Online Course, Membership & Learning Management System Plugin for WordPress plugin before 4.21.1 is not properly sanitised when output in the About sec...Show more
The 'State' field of the Edit profile page of the LMS by LifterLMS – Online Course, Membership & Learning Management System Plugin for WordPress plugin before 4.21.1 is not properly sanitised when output in the About section of the profile page, leading to a stored Cross-Site Scripting issue. This could allow low privilege users (such as students) to elevate their privilege via an XSS attack when an admin will view their profile.Show less
1Ultimatemember
1Ultimate Member
Jun 17, 2026
May 24, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The Ultimate Member – User Profile, User Registration, Login & Membership Plugin WordPress plugin before 2.1.20 did not properly sanitise, validate or encode the query string when generating a link to edit user's own pro...Show more
The Ultimate Member – User Profile, User Registration, Login & Membership Plugin WordPress plugin before 2.1.20 did not properly sanitise, validate or encode the query string when generating a link to edit user's own profile, leading to an authenticated reflected Cross-Site Scripting issue. Knowledge of the targeted username is required to exploit this, and attackers would then need to make the related logged in user open a malicious link.Show less
1Targetfirst
1Watcheezy
Jun 17, 2026
May 24, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Target First WordPress Plugin v2.0, also previously known as Watcheezy, suffers from a critical unauthenticated stored XSS vulnerability. An attacker could change the licence key value through a POST on any URL with...Show more
The Target First WordPress Plugin v2.0, also previously known as Watcheezy, suffers from a critical unauthenticated stored XSS vulnerability. An attacker could change the licence key value through a POST on any URL with the 'weeWzKey' parameter that will be save as the 'weeID option and is not sanitized.Show less
1Neox
1Hana Flv Player
Jun 17, 2026
May 24, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The Hana Flv Player WordPress plugin through 3.1.3 is vulnerable to an Authenticated Stored Cross-Site Scripting (XSS) vulnerability within the 'Default Skin' field.
1Bluemedicinelabs
1Hotjar Connecticator
Jun 17, 2026
May 24, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The Hotjar Connecticator WordPress plugin through 1.1.1 is vulnerable to Stored Cross-Site Scripting (XSS) in the 'hotjar script' textarea. The request did include a CSRF nonce that was properly verified by the server an...Show more
The Hotjar Connecticator WordPress plugin through 1.1.1 is vulnerable to Stored Cross-Site Scripting (XSS) in the 'hotjar script' textarea. The request did include a CSRF nonce that was properly verified by the server and this vulnerability could only be exploited by administrator users.Show less
1Pickplugins
1Product Slider For Woocommerce
Jun 17, 2026
May 24, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The slider import search feature of the PickPlugins Product Slider for WooCommerce WordPress plugin before 1.13.22 did not properly sanitised the keyword GET parameter, leading to reflected Cross-Site Scripting issue
1Ibenic
1Simple Giveaways
Jun 17, 2026
May 24, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The method and share GET parameters of the Giveaway pages were not sanitised, validated or escaped before being output back in the pages, thus leading to reflected XSS
1Boostifythemes
1Goto
Jun 17, 2026
May 24, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Goto WordPress theme before 2.1 did not properly sanitize the formvalue JSON POST parameter in its tl_filter AJAX action, leading to an unauthenticated Reflected Cross-site Scripting (XSS) vulnerability.
1Gowebsolutions
1Wp Customer Reviews
Jun 17, 2026
May 24, 2021
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The WP Customer Reviews WordPress plugin before 3.5.6 did not sanitise some of its settings, allowing high privilege users such as administrators to set XSS payloads in them which will then be triggered in pages where re...Show more
The WP Customer Reviews WordPress plugin before 3.5.6 did not sanitise some of its settings, allowing high privilege users such as administrators to set XSS payloads in them which will then be triggered in pages where reviews are enabledShow less
1Mlfactory
1Dsgvo All In One For Wp
Jun 17, 2026
May 24, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The dsgvoaio_write_log AJAX action of the DSGVO All in one for WP WordPress plugin before 4.0 did not sanitise or escape some POST parameter submitted before outputting them in the Log page in the administrator dashboard...Show more
The dsgvoaio_write_log AJAX action of the DSGVO All in one for WP WordPress plugin before 4.0 did not sanitise or escape some POST parameter submitted before outputting them in the Log page in the administrator dashboard (wp-admin/admin.php?page=dsgvoaiofree-show-log). This could allow unauthenticated attackers to gain unauthorised access by using an XSS payload to create a rogue administrator account, which will be trigged when an administrator will view the logs.Show less
1Dutchcoders
1Transfer.sh
Jun 17, 2026
May 24, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Dutchcoders transfer.sh before 1.2.4 allows XSS via an inline view.
1Calendar01 Project
1Calendar01
Jun 17, 2026
May 24, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Reflected cross-site scripting vulnerability in the admin page of [Calendar01] free edition ver1.0.1 and earlier allows a remote attacker to inject an arbitrary script via unspecified vectors.
1Telop01 Project
1Telop01
Jun 17, 2026
May 24, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Reflected cross-site scripting vulnerability in the admin page of [Telop01] free edition ver1.0.1 and earlier allows a remote attacker to inject an arbitrary script via unspecified vectors.
1Mailform01 Project
1Mailform01
Jun 17, 2026
May 24, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Reflected cross-site scripting vulnerability in [MailForm01] free edition (versions which the last updated date listed at the top of descriptions in the program file is from 2014 December 12 to 2018 July 27) allows a rem...Show more
Reflected cross-site scripting vulnerability in [MailForm01] free edition (versions which the last updated date listed at the top of descriptions in the program file is from 2014 December 12 to 2018 July 27) allows a remote attacker to inject an arbitrary script via unspecified vectors.Show less
1Cisco
1Finesse
Jun 17, 2026
May 22, 2021
N/A· v4
4.8 MEDIUM· v3
4.3 MEDIUM· v2
Multiple vulnerabilities in the web-based management interface of Cisco Finesse could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. These vulnerab...Show more
Multiple vulnerabilities in the web-based management interface of Cisco Finesse could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. These vulnerabilities are due to insufficient validation of user-supplied input by the web-based management interface of the affected software. An attacker could exploit these vulnerabilities by injecting malicious code into the web-based management interface and persuading a user to click a malicious link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information. An attacker needs valid administrator credentials to inject the malicious script code.Show less
1Plone
1Plone
Jun 17, 2026
May 21, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Plone through 5.2.4 allows XSS via the inline_diff methods in Products.CMFDiffTool.
1Plone
1Plone
Jun 17, 2026
May 21, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Plone through 5.2.4 allows stored XSS attacks (by a Contributor) by uploading an SVG or HTML document.