← Back
CWE-79

46,318 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (46,318)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Supportflow Project
1Supportflow
Nov 21, 2024
Sep 16, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The supportflow plugin before 0.7 for WordPress has XSS via a discussion ticket title.
1Creativeinteractivemedia
1Real3d Flipbook
Nov 21, 2024
Sep 16, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The real3d-flipbook-lite plugin 1.0 for WordPress has XSS via the wp-content/plugins/real3d-flipbook/includes/flipbooks.php bookId parameter.
1Findshorty
1Dwnldr
Nov 21, 2024
Sep 16, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The dwnldr plugin before 1.01 for WordPress has XSS via the User-Agent HTTP header.
1Icegram
1Icegram Engage
Nov 21, 2024
Sep 16, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The icegram plugin before 1.9.19 for WordPress has XSS.
1Inkthemes
1Colorway
Nov 21, 2024
Sep 16, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The colorway theme before 3.4.2 for WordPress has XSS via the contactName parameter.
1Akal Project
1Akal
Nov 21, 2024
Sep 16, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Akal theme through 2016-08-22 for WordPress has XSS via the framework/brad-shortcodes/tinymce/preview.php sc parameter.
1Bludit
1Bludit
Jun 17, 2026
Sep 15, 2019
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
In Bludit v3.9.2, there is a persistent XSS vulnerability in the Categories -> Add New Category -> Name field. NOTE: this may overlap CVE-2017-16636.
1Get Simple
1Getsimple Cms
Jun 17, 2026
Sep 15, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
GetSimple CMS v3.3.15 has Persistent Cross-Site Scripting (XSS) in admin/theme-edit.php.
1Api Bearer Auth Project
1Api Bearer Auth
Jun 17, 2026
Sep 15, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In the api-bearer-auth plugin before 20190907 for WordPress, the server parameter is not correctly filtered in the swagger-config.yaml.php file, and it is possible to inject JavaScript code, aka XSS.
1Scadabr
1Scadabr
Jun 17, 2026
Sep 15, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
ScadaBR 1.0CE, and 1.1.x through 1.1.0-RC, has XSS via a request for a nonexistent resource, as demonstrated by the dwr/test/ PATH_INFO.
1Fujixerox
1Docushare
Jun 17, 2026
Sep 14, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A Reflected Cross-Site Scripting (XSS) vulnerability in the webEx module in webExMeetingLogin.jsp and deleteWebExMeetingCheck.jsp in Fuji Xerox DocuShare through 7.0.0.C1.609 allows remote attackers to inject arbitrary w...Show more
A Reflected Cross-Site Scripting (XSS) vulnerability in the webEx module in webExMeetingLogin.jsp and deleteWebExMeetingCheck.jsp in Fuji Xerox DocuShare through 7.0.0.C1.609 allows remote attackers to inject arbitrary web script or HTML via the handle parameter (webExMeetingLogin.jsp) and meetingKey parameter (deleteWebExMeetingCheck.jsp).Show less
1S Cms
1S Cms
Jun 17, 2026
Sep 14, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
s-cms V3.0 has XSS in index.php?type=text via the S_id parameter.
1Niushop
1Niushop
Jun 17, 2026
Sep 14, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
NIUSHOP V1.11 has XSS via the index.php?s=/admin URI.
1Siemens
1Ie/wsn Pa Link Wirelesshart Gateway Firmware
Jun 17, 2026
Sep 13, 2019
N/A· v4
9.6 CRITICAL· v3
4.3 MEDIUM· v2
A vulnerability has been identified in IE/WSN-PA Link WirelessHART Gateway (All versions). The integrated configuration web server of the affected device could allow Cross-Site Scripting (XSS) attacks if unsuspecting use...Show more
A vulnerability has been identified in IE/WSN-PA Link WirelessHART Gateway (All versions). The integrated configuration web server of the affected device could allow Cross-Site Scripting (XSS) attacks if unsuspecting users are tricked into accessing a malicious link. User interaction is required for a successful exploitation. The user must be logged into the web interface in order for the exploitation to succeed. At the stage of publishing this security advisory no public exploitation is known.Show less
1Webcraftic
1Woody Ad Snippets
Jun 17, 2026
Sep 13, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The insert-php (aka Woody ad snippets) plugin before 2.2.8 for WordPress allows authenticated XSS via the winp_item parameter.
1Piwigo
1Piwigo
Jun 17, 2026
Sep 13, 2019
N/A· v4
9.6 CRITICAL· v3
6.8 MEDIUM· v2
admin.php?page=account_billing in Piwigo 2.9.5 has XSS via the vat_number, billing_name, company, or billing_address parameter. This is exploitable via CSRF.
1Piwigo
1Piwigo
Jun 17, 2026
Sep 13, 2019
N/A· v4
9.6 CRITICAL· v3
6.8 MEDIUM· v2
admin.php?page=notification_by_mail in Piwigo 2.9.5 has XSS via the nbm_send_html_mail, nbm_send_mail_as, nbm_send_detailed_content, nbm_complementary_mail_content, nbm&#95...Show more
admin.php?page=notification_by_mail in Piwigo 2.9.5 has XSS via the nbm_send_html_mail, nbm_send_mail_as, nbm_send_detailed_content, nbm_complementary_mail_content, nbm_send_recent_post_dates, or param_submit parameter. This is exploitable via CSRF.Show less
1Slickquiz Project
1Slickquiz
Jun 17, 2026
Sep 13, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An XSS issue was discovered in the slickquiz plugin through 1.3.7.1 for WordPress. The save_quiz_score functionality available via the /wp-admin/admin-ajax.php endpoint allows unauthenticated users to submit quiz solutio...Show more
An XSS issue was discovered in the slickquiz plugin through 1.3.7.1 for WordPress. The save_quiz_score functionality available via the /wp-admin/admin-ajax.php endpoint allows unauthenticated users to submit quiz solutions/answers, which are stored in the database and later shown in the WordPress backend for all users with at least Subscriber rights. Because the plugin does not properly validate and sanitize this data, a malicious payload in either the name or email field is executed directly within the backend at /wp-admin/admin.php?page=slickquiz across all users with the privileges of at least Subscriber.Show less
1Headwaythemes
1Headway
Nov 21, 2024
Sep 13, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The Headway theme before 3.8.9 for WordPress has XSS via the license key field.
1Quotes Collection Project
1Quotes Collection
Nov 21, 2024
Sep 13, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The quotes-collection plugin before 2.0.6 for WordPress has XSS via the wp-admin/admin.php?page=quotes-collection page parameter.