← Back
CWE-79

46,318 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (46,318)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Videowhisper
1Video Comments Webcam Recorder
Nov 21, 2024
Dec 27, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in comments/videowhisper2/r_logout.php in the Video Comments Webcam Recorder plugin 1.55, as downloaded before 20140116 for WordPress allows remote attackers to inject arbitrary w...Show more
Cross-site scripting (XSS) vulnerability in comments/videowhisper2/r_logout.php in the Video Comments Webcam Recorder plugin 1.55, as downloaded before 20140116 for WordPress allows remote attackers to inject arbitrary web script or HTML via the message parameter.Show less
1Cybercompany
1Swipehq Payment Gateway Woocommerce
Nov 21, 2024
Dec 27, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in test-plugin.php in the Swipe Checkout for WooCommerce plugin 2.7.1 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the api_url para...Show more
Cross-site scripting (XSS) vulnerability in test-plugin.php in the Swipe Checkout for WooCommerce plugin 2.7.1 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the api_url parameter.Show less
1Ruven Toolkit Project
1Ruven Toolkit
Nov 21, 2024
Dec 27, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in tinymce/popup.php in the Ruven Toolkit plugin 1.1 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the popup parameter.
1Podcast Channels Project
1Podcast Channels
Nov 21, 2024
Dec 27, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in the Podcast Channels plugin 0.20 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the Filename parameter to getid3/demos/demo.write....Show more
Cross-site scripting (XSS) vulnerability in the Podcast Channels plugin 0.20 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the Filename parameter to getid3/demos/demo.write.php.Show less
1Movies Project
1Movies
Nov 21, 2024
Dec 27, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in the Movies plugin 0.6 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the filename parameter to getid3/demos/demo.mimeonly.php.
1Czepol
1Wp Planet
Nov 21, 2024
Dec 27, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in rss.class/scripts/magpie_debug.php in the WP-Planet plugin 0.1 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the url parameter.
1Conversador Project
1Conversador
Nov 21, 2024
Dec 27, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in the Conversador plugin 2.61 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the 'page' parameter.
1Xorbin
1Analog Flash Clock
Nov 21, 2024
Dec 27, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Xorbin Analog Flash Clock 1.0 extension for Joomia has XSS
1Xorbin
1Digital Flash Clock
Nov 21, 2024
Dec 27, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
WordPress Xorbin Digital Flash Clock 1.0 has XSS
1Sencha
1Connect
Nov 21, 2024
Dec 27, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Sencha Labs Connect has XSS with connect.methodOverride()
1Spbas
1Business Automation Software
Nov 21, 2024
Dec 27, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
SPBAS Business Automation Software 2012 has XSS.
1Tenable
1Nessus
Nov 21, 2024
Dec 27, 2019
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Tenable Nessus before 6.8 has a stored XSS issue that requires admin-level authentication to the Nessus UI, and would potentially impact other admins (Tenable IDs 5218 and 5269).
1Tenable
1Nessus
Nov 21, 2024
Dec 27, 2019
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Tenable Nessus before 6.8 has a stored XSS issue that requires admin-level authentication to the Nessus UI, and would only potentially impact other admins. (Tenable ID 5198).
1Cybercompay
1Swipehq Payment Gateway Wp E Commerce
Nov 21, 2024
Dec 27, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Multiple cross-site scripting (XSS) vulnerabilities in test-plugin.php in the Swipe Checkout for WP e-Commerce plugin 3.1.0 and earlier for WordPress allow remote attackers to inject arbitrary web script or HTML via the...Show more
Multiple cross-site scripting (XSS) vulnerabilities in test-plugin.php in the Swipe Checkout for WP e-Commerce plugin 3.1.0 and earlier for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) api_key, (2) payment_page_url, (3) merchant_id, (4) api_url, or (5) currency parameter.Show less
1Winwar
1Wp Ebay Product Feeds
Nov 21, 2024
Dec 27, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in magpie/scripts/magpie_slashbox.php in the Ebay Feeds for WordPress plugin 1.1 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the r...Show more
Cross-site scripting (XSS) vulnerability in magpie/scripts/magpie_slashbox.php in the Ebay Feeds for WordPress plugin 1.1 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the rss_url parameter.Show less
1Easy Career Openings Project
1Easy Career Openings
Nov 21, 2024
Dec 27, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in the Easy Career Openings plugin 0.4 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via unspecified parameters.
2Debian
Wordpress
2Debian Linux
Wordpress
Jun 17, 2026
Dec 27, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In wp-includes/formatting.php in WordPress 3.7 to 5.3.0, the function wp_targeted_link_rel() can be used in a particular way to result in a stored cross-site scripting (XSS) vulnerability. This has been patched in WordPr...Show more
In wp-includes/formatting.php in WordPress 3.7 to 5.3.0, the function wp_targeted_link_rel() can be used in a particular way to result in a stored cross-site scripting (XSS) vulnerability. This has been patched in WordPress 5.3.1, along with all the previous WordPress versions from 3.7 to 5.3 via a minor release.Show less
1Archerysec
1Archery
Jun 17, 2026
Dec 26, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
In Archery before 1.3, inserting an XSS payload into a project name (either by creating a new project or editing an existing one) will result in stored XSS on the vulnerability-scan scheduling page.
2Debian
Wordpress
2Debian Linux
Wordpress
Jun 17, 2026
Dec 26, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
In WordPress before 5.3.1, authenticated users with lower privileges (like contributors) can inject JavaScript code in the block editor, which is executed within the dashboard. It can lead to an admin opening the affecte...Show more
In WordPress before 5.3.1, authenticated users with lower privileges (like contributors) can inject JavaScript code in the block editor, which is executed within the dashboard. It can lead to an admin opening the affected post in the editor leading to XSS.Show less
2Debian
Wordpress
2Debian Linux
Wordpress
Jun 17, 2026
Dec 26, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
WordPress users with lower privileges (like contributors) can inject JavaScript code in the block editor using a specific payload, which is executed within the dashboard. This can lead to XSS if an admin opens the post i...Show more
WordPress users with lower privileges (like contributors) can inject JavaScript code in the block editor using a specific payload, which is executed within the dashboard. This can lead to XSS if an admin opens the post in the editor. Execution of this attack does require an authenticated user. This has been patched in WordPress 5.3.1, along with all the previous WordPress versions from 3.7 to 5.3 via a minor release. Automatic updates are enabled by default for minor releases and we strongly recommend that you keep them enabled.Show less