← Back
CWE-79

46,318 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (46,318)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Display Widgets Project
1Display Widgets
Nov 21, 2024
Sep 26, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The display-widgets plugin before 2.04 for WordPress has XSS via the wp-admin/admin-ajax.php?action=dw_show_widget id_base, widget_number, or instance parameter.
1Vivwebsolutions
1Dynamic Widgets
Nov 27, 2024
Sep 26, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The dynamic-widgets plugin before 1.5.11 for WordPress has XSS via the wp-admin/admin-ajax.php?action=term_tree prefix or widget_id parameter.
1Crazy Bone Project
1Crazy Bone
Nov 21, 2024
Sep 26, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The crazy-bone plugin before 0.6.0 for WordPress has XSS via the User-Agent HTTP header.
1Manual Image Crop Project
1Manual Image Crop
Nov 21, 2024
Sep 26, 2019
N/A· v4
4.6 MEDIUM· v3
3.5 LOW· v2
The manual-image-crop plugin before 1.11 for WordPress has CSRF with resultant XSS via the wp-admin/admin-ajax.php?action=mic_editor_window postId parameter.
1Simplysymphony
1Plugnedit
Nov 21, 2024
Sep 26, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The PlugNedit Adaptive Editor plugin before 6.2.0 for WordPress has XSS via wp-admin/admin-ajax.php?action=simple_fields_field_type_post_dialog_load PlugneditBGColor, PlugneditEditorMargin, plugnedit_width, pnemedcount,...Show more
The PlugNedit Adaptive Editor plugin before 6.2.0 for WordPress has XSS via wp-admin/admin-ajax.php?action=simple_fields_field_type_post_dialog_load PlugneditBGColor, PlugneditEditorMargin, plugnedit_width, pnemedcount, or plugneditcontent parameters.Show less
1Mightymess
1Soundcloud Is Gold
Nov 21, 2024
Sep 26, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The soundcloud-is-gold plugin before 2.3.2 for WordPress has XSS via the wp-admin/admin-ajax.php?action=get_soundcloud_player id parameter.
1Captain Slider Project
1Captain Slider
Nov 21, 2024
Sep 26, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The captain-slider plugin 1.0.6 for WordPress has XSS via a Title or Caption section.
1Onthegosystems
1Sitepress Multilingual Cms
Nov 21, 2024
Sep 26, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The sitepress-multilingual-cms (WPML) plugin 2.9.3 to 3.2.6 for WordPress has XSS via the Accept-Language HTTP header.
1Wpsymposiumpro
1Wp Symposium
Nov 21, 2024
Sep 26, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The wp-symposium plugin through 15.8.1 for WordPress has XSS via the wp-content/plugins/wp-symposium/get_album_item.php?size parameter.
1Royal Slider Project
1Royal Slider
Nov 21, 2024
Sep 26, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Royal-Slider plugin before 3.2.7 for WordPress has XSS via the rstype parameter.
1Gopostmatic
1Replyable
Nov 21, 2024
Sep 26, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Postmatic plugin before 1.4.6 for WordPress has XSS.
1Blubrry
1Powerpress
Nov 21, 2024
Sep 26, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The Blubrry PowerPress Podcasting plugin 6.0.4 for WordPress has XSS via the tab parameter.
4Canonical
DebianNovnc+1 more
4Debian Linux
NovncOpenstack+1 more
Nov 21, 2024
Sep 25, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An XSS vulnerability was discovered in noVNC before 0.6.2 in which the remote VNC server could inject arbitrary HTML into the noVNC web page via the messages propagated to the status field, such as the VNC server name.
1Halo
1Halo
Jun 17, 2026
Sep 25, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Halo 1.1.0 has XSS via a crafted authorUrl in JSON data to api/content/posts/comments.
1Cisco
2Ios
Ios Xe
Jun 17, 2026
Sep 25, 2019
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
A vulnerability in the web framework code of Cisco IOS and Cisco IOS XE Software could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the web interface of...Show more
A vulnerability in the web framework code of Cisco IOS and Cisco IOS XE Software could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the web interface of the affected software using the banner parameter. The vulnerability is due to insufficient input validation of the banner parameters that are passed to the web server of the affected software. An attacker could exploit this vulnerability by crafting a banner parameter and saving it. The attacker could then convince a user of the web interface to access a malicious link or could intercept a user request for the affected web interface and inject malicious code into the request. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected web interface or allow the attacker to access sensitive browser-based information.Show less
1Cisco
1Ios Xe
Jun 17, 2026
Sep 25, 2019
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
A vulnerability in the web framework code of Cisco IOS XE Software could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the web interface of the affected s...Show more
A vulnerability in the web framework code of Cisco IOS XE Software could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the web interface of the affected software. The vulnerability is due to insufficient input validation of some parameters that are passed to the web server of the affected software. An attacker could exploit this vulnerability by convincing a user of the web interface to access a malicious link or by intercepting a user request for the affected web interface and injecting malicious code into the request. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected web interface or allow the attacker to access sensitive browser-based information.Show less
1Ibm
1Content Navigator
Jun 17, 2026
Sep 25, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM Content Navigator 3.0CD is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credenti...Show more
IBM Content Navigator 3.0CD is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 166721.Show less
1Silverstripe
1Silverstripe
Jun 17, 2026
Sep 25, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
SilverStripe through 4.3.3 has Flash Clipboard Reflected XSS.
1F5
1Big Iq Centralized Management
Jun 17, 2026
Sep 25, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
There is a Stored Cross Site Scripting vulnerability in the undisclosed page of a BIG-IQ 6.0.0-6.1.0 or 5.2.0-5.4.0 system. The attack can be stored by users granted the Device Manager and Administrator roles.
1Jenkins
1Log Parser
Jun 17, 2026
Sep 25, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Jenkins Log Parser Plugin 2.0 and earlier did not escape an error message, resulting in a cross-site scripting vulnerability exploitable by users able to define log parsing rules.