CWE-79
46,318 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (46,318)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Display Widgets Project 1Display Widgets Nov 21, 2024 Sep 26, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 The display-widgets plugin before 2.04 for WordPress has XSS via the wp-admin/admin-ajax.php?action=dw_show_widget id_base, widget_number, or instance parameter. |
1Vivwebsolutions 1Dynamic Widgets Nov 27, 2024 Sep 26, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 The dynamic-widgets plugin before 1.5.11 for WordPress has XSS via the wp-admin/admin-ajax.php?action=term_tree prefix or widget_id parameter. |
1Crazy Bone Project 1Crazy Bone Nov 21, 2024 Sep 26, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The crazy-bone plugin before 0.6.0 for WordPress has XSS via the User-Agent HTTP header. |
1Manual Image Crop Project 1Manual Image Crop Nov 21, 2024 Sep 26, 2019 N/A· v4 4.6 MEDIUM· v3 3.5 LOW· v2 The manual-image-crop plugin before 1.11 for WordPress has CSRF with resultant XSS via the wp-admin/admin-ajax.php?action=mic_editor_window postId parameter. |
The PlugNedit Adaptive Editor plugin before 6.2.0 for WordPress has XSS via wp-admin/admin-ajax.php?action=simple_fields_field_type_post_dialog_load PlugneditBGColor, PlugneditEditorMargin, plugnedit_width, pnemedcount,...Show more |
1Mightymess 1Soundcloud Is Gold Nov 21, 2024 Sep 26, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The soundcloud-is-gold plugin before 2.3.2 for WordPress has XSS via the wp-admin/admin-ajax.php?action=get_soundcloud_player id parameter. |
1Captain Slider Project 1Captain Slider Nov 21, 2024 Sep 26, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The captain-slider plugin 1.0.6 for WordPress has XSS via a Title or Caption section. |
1Onthegosystems 1Sitepress Multilingual Cms Nov 21, 2024 Sep 26, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The sitepress-multilingual-cms (WPML) plugin 2.9.3 to 3.2.6 for WordPress has XSS via the Accept-Language HTTP header. |
1Wpsymposiumpro 1Wp Symposium Nov 21, 2024 Sep 26, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The wp-symposium plugin through 15.8.1 for WordPress has XSS via the wp-content/plugins/wp-symposium/get_album_item.php?size parameter. |
1Royal Slider Project 1Royal Slider Nov 21, 2024 Sep 26, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The Royal-Slider plugin before 3.2.7 for WordPress has XSS via the rstype parameter. |
The Postmatic plugin before 1.4.6 for WordPress has XSS. |
The Blubrry PowerPress Podcasting plugin 6.0.4 for WordPress has XSS via the tab parameter. |
4Canonical DebianNovnc+1 more4Debian Linux NovncOpenstack+1 moreNov 21, 2024 Sep 25, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 An XSS vulnerability was discovered in noVNC before 0.6.2 in which the remote VNC server could inject arbitrary HTML into the noVNC web page via the messages propagated to the status field, such as the VNC server name. |
Halo 1.1.0 has XSS via a crafted authorUrl in JSON data to api/content/posts/comments. |
A vulnerability in the web framework code of Cisco IOS and Cisco IOS XE Software could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the web interface of...Show more |
A vulnerability in the web framework code of Cisco IOS XE Software could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the web interface of the affected s...Show more |
IBM Content Navigator 3.0CD is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credenti...Show more |
SilverStripe through 4.3.3 has Flash Clipboard Reflected XSS. |
1F5 1Big Iq Centralized Management Jun 17, 2026 Sep 25, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 There is a Stored Cross Site Scripting vulnerability in the undisclosed page of a BIG-IQ 6.0.0-6.1.0 or 5.2.0-5.4.0 system. The attack can be stored by users granted the Device Manager and Administrator roles. |
Jenkins Log Parser Plugin 2.0 and earlier did not escape an error message, resulting in a cross-site scripting vulnerability exploitable by users able to define log parsing rules. |