CWE-79
46,311 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (46,311)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Multiple stored XSS vulnerabilities in Sentrifugo 3.2 could allow authenticated users to inject arbitrary web script or HTML. |
Rancher 2 through 2.2.4 is vulnerable to a Cross-Site Websocket Hijacking attack that allows an exploiter to gain access to clusters managed by Rancher. The attack requires a victim to be logged into a Rancher server, an...Show more |
Nagios Log Server before 2.0.8 allows Reflected XSS via the username on the Login page. |
1Lenovo 1Xclarity Administrator Jun 17, 2026 Sep 3, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 A reflected cross-site scripting (XSS) vulnerability was reported in Lenovo XClarity Administrator (LXCA) versions prior to 2.5.0 that could allow a crafted URL, if visited, to cause JavaScript code to be executed in the...Show more |
A stored cross-site scripting (XSS) vulnerability was reported in Lenovo XClarity Administrator (LXCA) versions prior to 2.5.0 that could allow an administrative user to cause JavaScript code to be stored in LXCA which m...Show more |
The download-manager plugin before 2.9.94 for WordPress has XSS via the category shortcode feature, as demonstrated by the orderby or search[publish_date] parameter. |
1Dell 3Emc Unity Operating Environment Emc Unityvsa Operating EnvironmentEmc Vnxe3200 FirmwareJun 17, 2026 Sep 3, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Dell EMC Unity Operating Environment versions prior to 5.0.0.0.5.116, Dell EMC UnityVSA versions prior to 5.0.0.0.5.116 and Dell EMC VNXe3200 versions prior to 3.1.10.9946299 contain a reflected cross-site scripting vuln...Show more |
The CarSpot theme before 2.1.7 for WordPress has stored XSS via the Phone Number field. |
The JobCareer theme before 2.5.1 for WordPress has stored XSS. |
The breadcrumbs-by-menu plugin before 1.0.3 for WordPress has XSS. |
1Easy Pdf Restaurant Menu Upload Project 1Easy Pdf Restaurant Menu Upload Jun 17, 2026 Aug 30, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The easy-pdf-restaurant-menu-upload plugin before 1.1.2 for WordPress has XSS. |
The custom-404-pro plugin before 3.2.8 for WordPress has reflected XSS, a different vulnerability than CVE-2019-14789. |
The webp-express plugin before 0.14.8 for WordPress has stored XSS. |
1Bootstrapped 1Wp Ultimate Recipe Jun 17, 2026 Aug 30, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 The wp-ultimate-recipe plugin before 3.12.7 for WordPress has stored XSS. |
1Simple Mail Address Encoder Project 1Simple Mail Address Encoder Jun 17, 2026 Aug 30, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The simple-mail-address-encoder plugin before 1.7 for WordPress has reflected XSS. |
The icegram plugin before 1.10.29 for WordPress has ig_cat_list XSS. |
1Greentreelabs 1Gallery Photoblocks Jun 17, 2026 Aug 30, 2019 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 The photoblocks-grid-gallery plugin before 1.1.33 for WordPress has wp-admin/admin.php?page=photoblocks-edit&id= XSS. |
1Onesignal 1Onesignal Free Web Push Notifications Jun 17, 2026 Aug 30, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 The onesignal-free-web-push-notifications plugin before 1.17.8 for WordPress has XSS via the subdomain parameter. |
1Realestateconnected 1Easy Property Listings Jun 17, 2026 Aug 30, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The easy-property-listings plugin before 3.4 for WordPress has XSS. |
1Wpexpertdeveloper 1Wp Private Content Plus Jun 17, 2026 Aug 30, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The wp-private-content-plus plugin before 2.0 for WordPress has no protection against option changes via save_settings_page and other save_ functions. |