CWE-79
46,318 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (46,318)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
An issue was discovered in ThinkSAAS 2.91. There is XSS via the index.php?app=group&ac=create&ts=do groupname parameter. |
Ogma CMS 0.5 has XSS via creation of a new blog. |
TuziCMS 2.0.6 has XSS via the PATH_INFO to a group URI, as demonstrated by index.php/article/group/id/2/. |
An issue was discovered in Mautic 2.13.1. It has Stored XSS via the company name field. |
An issue was discovered in ZrLog 2.1.1. There is a Stored XSS vulnerability in the article_edit area. |
1Draytek 1Vigor2925 Firmware Jun 17, 2026 Sep 20, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 On DrayTek Vigor2925 devices with firmware 3.8.4.3, XSS exists via a crafted WAN name on the General Setup screen. NOTE: this is an end-of-life product. |
1Draytek 1Vigor2925 Firmware Jun 17, 2026 Sep 20, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 On DrayTek Vigor2925 devices with firmware 3.8.4.3, Incorrect Access Control exists in loginset.htm, and can be used to trigger XSS. NOTE: this is an end-of-life product. |
The xpinner-lite plugin through 2.2 for WordPress has xpinner-lite.php XSS. |
The wp-piwik plugin before 1.0.5 for WordPress has XSS. |
The neuvoo-jobroll plugin 2.0 for WordPress has neuvoo_keywords XSS. |
The neuvoo-jobroll plugin 2.0 for WordPress has neuvoo_location XSS. |
1Websimon Tables Project 1Websimon Tables Nov 21, 2024 Sep 20, 2019 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 The websimon-tables plugin through 1.3.4 for WordPress has wp-admin/tools.php edit_style id XSS. |
The gocodes plugin through 1.3.5 for WordPress has wp-admin/tools.php deletegc XSS. |
1Attosoft 1Auto Thickbox Plus Nov 21, 2024 Sep 20, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The auto-thickbox-plus plugin through 1.9 for WordPress has wp-content/plugins/auto-thickbox-plus/download.min.php?file= XSS. |
1Usersultra 1Users Ultra Membership Nov 21, 2024 Sep 20, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 The users-ultra plugin before 1.5.63 for WordPress has XSS via the p_desc parameter. |
1Usersultra 1Users Ultra Membership Nov 21, 2024 Sep 20, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 The users-ultra plugin before 1.5.63 for WordPress has XSS via the p_name parameter. |
1Agentevolution 1Impress Listings Nov 21, 2024 Sep 20, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The wp-listings plugin before 2.0.2 for WordPress has includes/views/single-listing.php XSS. |
1Solaplugins 1Sola Support Tickets Nov 21, 2024 Sep 20, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 The sola-support-tickets plugin before 3.13 for WordPress has incorrect access control for /wp-admin with resultant XSS. |
The instalinker plugin before 1.1.2 for WordPress has includes/instalinker-admin-preview.php?client_id= XSS. |
1Plugin Planet 1User Submitted Posts Nov 21, 2024 Sep 20, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The user-submitted-posts plugin before 20160215 for WordPress has XSS via the user-submitted-content field. |