CWE-79
46,318 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (46,318)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Supportflow Project 1Supportflow Nov 21, 2024 Sep 16, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The supportflow plugin before 0.7 for WordPress has XSS via a discussion ticket title. |
1Creativeinteractivemedia 1Real3d Flipbook Nov 21, 2024 Sep 16, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The real3d-flipbook-lite plugin 1.0 for WordPress has XSS via the wp-content/plugins/real3d-flipbook/includes/flipbooks.php bookId parameter. |
The dwnldr plugin before 1.01 for WordPress has XSS via the User-Agent HTTP header. |
The icegram plugin before 1.9.19 for WordPress has XSS. |
The colorway theme before 3.4.2 for WordPress has XSS via the contactName parameter. |
The Akal theme through 2016-08-22 for WordPress has XSS via the framework/brad-shortcodes/tinymce/preview.php sc parameter. |
In Bludit v3.9.2, there is a persistent XSS vulnerability in the Categories -> Add New Category -> Name field. NOTE: this may overlap CVE-2017-16636. |
GetSimple CMS v3.3.15 has Persistent Cross-Site Scripting (XSS) in admin/theme-edit.php. |
1Api Bearer Auth Project 1Api Bearer Auth Jun 17, 2026 Sep 15, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 In the api-bearer-auth plugin before 20190907 for WordPress, the server parameter is not correctly filtered in the swagger-config.yaml.php file, and it is possible to inject JavaScript code, aka XSS. |
ScadaBR 1.0CE, and 1.1.x through 1.1.0-RC, has XSS via a request for a nonexistent resource, as demonstrated by the dwr/test/ PATH_INFO. |
A Reflected Cross-Site Scripting (XSS) vulnerability in the webEx module in webExMeetingLogin.jsp and deleteWebExMeetingCheck.jsp in Fuji Xerox DocuShare through 7.0.0.C1.609 allows remote attackers to inject arbitrary w...Show more |
s-cms V3.0 has XSS in index.php?type=text via the S_id parameter. |
NIUSHOP V1.11 has XSS via the index.php?s=/admin URI. |
1Siemens 1Ie/wsn Pa Link Wirelesshart Gateway Firmware Jun 17, 2026 Sep 13, 2019 N/A· v4 9.6 CRITICAL· v3 4.3 MEDIUM· v2 A vulnerability has been identified in IE/WSN-PA Link WirelessHART Gateway (All versions). The integrated configuration web server of the affected device could allow Cross-Site Scripting (XSS) attacks if unsuspecting use...Show more |
The insert-php (aka Woody ad snippets) plugin before 2.2.8 for WordPress allows authenticated XSS via the winp_item parameter. |
admin.php?page=account_billing in Piwigo 2.9.5 has XSS via the vat_number, billing_name, company, or billing_address parameter. This is exploitable via CSRF. |
admin.php?page=notification_by_mail in Piwigo 2.9.5 has XSS via the nbm_send_html_mail, nbm_send_mail_as, nbm_send_detailed_content, nbm_complementary_mail_content, nbm_...Show more |
1Slickquiz Project 1Slickquiz Jun 17, 2026 Sep 13, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 An XSS issue was discovered in the slickquiz plugin through 1.3.7.1 for WordPress. The save_quiz_score functionality available via the /wp-admin/admin-ajax.php endpoint allows unauthenticated users to submit quiz solutio...Show more |
The Headway theme before 3.8.9 for WordPress has XSS via the license key field. |
1Quotes Collection Project 1Quotes Collection Nov 21, 2024 Sep 13, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The quotes-collection plugin before 2.0.6 for WordPress has XSS via the wp-admin/admin.php?page=quotes-collection page parameter. |