CWE-79
48,003 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (48,003)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Online Examination System Project 1Online Examination System Jun 17, 2026 May 24, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Project Worlds Online Examination System 1.0 is affected by Cross Site Scripting (XSS) via account.php. |
In ArangoDB, versions v2.2.6.2 through v3.7.10 are vulnerable to Cross-Site Scripting (XSS), since there is no validation of the .zip file name and filtering of potential abusive characters which zip files can be named t...Show more |
The Autoptimize WordPress plugin before 2.8.4 was missing proper escaping and sanitisation in some of its settings, allowing high privilege users to set XSS payloads in them, leading to stored Cross-Site Scripting issues |
The 'State' field of the Edit profile page of the LMS by LifterLMS – Online Course, Membership & Learning Management System Plugin for WordPress plugin before 4.21.1 is not properly sanitised when output in the About sec...Show more |
1Ultimatemember 1Ultimate Member Jun 17, 2026 May 24, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 The Ultimate Member – User Profile, User Registration, Login & Membership Plugin WordPress plugin before 2.1.20 did not properly sanitise, validate or encode the query string when generating a link to edit user's own pro...Show more |
The Target First WordPress Plugin v2.0, also previously known as Watcheezy, suffers from a critical unauthenticated stored XSS vulnerability. An attacker could change the licence key value through a POST on any URL with...Show more |
The Hana Flv Player WordPress plugin through 3.1.3 is vulnerable to an Authenticated Stored Cross-Site Scripting (XSS) vulnerability within the 'Default Skin' field. |
1Bluemedicinelabs 1Hotjar Connecticator Jun 17, 2026 May 24, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 The Hotjar Connecticator WordPress plugin through 1.1.1 is vulnerable to Stored Cross-Site Scripting (XSS) in the 'hotjar script' textarea. The request did include a CSRF nonce that was properly verified by the server an...Show more |
1Pickplugins 1Product Slider For Woocommerce Jun 17, 2026 May 24, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The slider import search feature of the PickPlugins Product Slider for WooCommerce WordPress plugin before 1.13.22 did not properly sanitised the keyword GET parameter, leading to reflected Cross-Site Scripting issue |
The method and share GET parameters of the Giveaway pages were not sanitised, validated or escaped before being output back in the pages, thus leading to reflected XSS |
The Goto WordPress theme before 2.1 did not properly sanitize the formvalue JSON POST parameter in its tl_filter AJAX action, leading to an unauthenticated Reflected Cross-site Scripting (XSS) vulnerability. |
1Gowebsolutions 1Wp Customer Reviews Jun 17, 2026 May 24, 2021 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 The WP Customer Reviews WordPress plugin before 3.5.6 did not sanitise some of its settings, allowing high privilege users such as administrators to set XSS payloads in them which will then be triggered in pages where re...Show more |
1Mlfactory 1Dsgvo All In One For Wp Jun 17, 2026 May 24, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The dsgvoaio_write_log AJAX action of the DSGVO All in one for WP WordPress plugin before 4.0 did not sanitise or escape some POST parameter submitted before outputting them in the Log page in the administrator dashboard...Show more |
Dutchcoders transfer.sh before 1.2.4 allows XSS via an inline view. |
1Calendar01 Project 1Calendar01 Jun 17, 2026 May 24, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Reflected cross-site scripting vulnerability in the admin page of [Calendar01] free edition ver1.0.1 and earlier allows a remote attacker to inject an arbitrary script via unspecified vectors. |
Reflected cross-site scripting vulnerability in the admin page of [Telop01] free edition ver1.0.1 and earlier allows a remote attacker to inject an arbitrary script via unspecified vectors. |
1Mailform01 Project 1Mailform01 Jun 17, 2026 May 24, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Reflected cross-site scripting vulnerability in [MailForm01] free edition (versions which the last updated date listed at the top of descriptions in the program file is from 2014 December 12 to 2018 July 27) allows a rem...Show more |
Multiple vulnerabilities in the web-based management interface of Cisco Finesse could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. These vulnerab...Show more |
Plone through 5.2.4 allows XSS via the inline_diff methods in Products.CMFDiffTool. |
Plone through 5.2.4 allows stored XSS attacks (by a Contributor) by uploading an SVG or HTML document. |