← Back
CWE-79

46,301 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (46,301)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Fortinet
1Fortiweb
Jun 17, 2026
Aug 28, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The URL part of the report message is not encoded in Fortinet FortiWeb 6.0.2 and below which may allow an attacker to execute unauthorized code or commands (Cross Site Scripting) via attack reports generated in HTML form...Show more
The URL part of the report message is not encoded in Fortinet FortiWeb 6.0.2 and below which may allow an attacker to execute unauthorized code or commands (Cross Site Scripting) via attack reports generated in HTML form.Show less
1Librenms
1Librenms
Jun 17, 2026
Aug 28, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
LibreNMS v1.54 has XSS in the Create User, Inventory, Add Device, Notifications, Alert Rule, Create Maintenance, and Alert Template sections of the admin console. This could lead to cookie stealing and other malicious ac...Show more
LibreNMS v1.54 has XSS in the Create User, Inventory, Add Device, Notifications, Alert Rule, Create Maintenance, and Alert Template sections of the admin console. This could lead to cookie stealing and other malicious actions. This vulnerability can be exploited with an authenticated account.Show less
1Eng
1Knowage
Jun 17, 2026
Aug 28, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In Knowage through 6.1.1, there is XSS via the start_url or user_id field to the ChangePwdServlet page.
3Jenkins
OracleRedhat
3Communications Cloud Native Core Automated Test Suite
JenkinsOpenshift Container Platform
Jun 17, 2026
Aug 28, 2019
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
A stored cross-site scripting vulnerability in Jenkins 2.191 and earlier, LTS 2.176.2 and earlier allowed attackers with Overall/Administer permission to configure the update site URL to inject arbitrary HTML and JavaScr...Show more
A stored cross-site scripting vulnerability in Jenkins 2.191 and earlier, LTS 2.176.2 and earlier allowed attackers with Overall/Administer permission to configure the update site URL to inject arbitrary HTML and JavaScript in update center web pages.Show less
1Automattic
1Jetpack
Nov 21, 2024
Aug 28, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Jetpack plugin before 3.4.3 for WordPress has XSS via add_query_arg() and remove_query_arg().
1Ithemes
1Builder Style Manager
Nov 21, 2024
Aug 28, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
iThemes Builder Style Manager before 0.7.7 for WordPress has XSS via add_query_arg() and remove_query_arg().
1Ithemes
1Builder Theme Market
Nov 21, 2024
Aug 28, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
iThemes Builder Theme Market before 5.1.27 for WordPress has XSS via add_query_arg() and remove_query_arg().
1Ithemes
1Builder Theme Depot
Nov 21, 2024
Aug 28, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
iThemes Builder Theme Depot before 5.0.30 for WordPress has XSS via add_query_arg() and remove_query_arg().
1Ithemes
1Mobile
Nov 21, 2024
Aug 28, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
iThemes Mobile before 1.2.8 for WordPress has XSS via add_query_arg() and remove_query_arg().
1Ithemes
1Table Rate Shipping
Nov 21, 2024
Aug 28, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Table Rate Shipping Add-on for iThemes Exchange before 1.1.0 for WordPress has XSS via add_query_arg() and remove_query_arg().
1Ithemes
1Stripe
Nov 21, 2024
Aug 28, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Stripe Add-on for iThemes Exchange before 1.2.0 for WordPress has XSS via add_query_arg() and remove_query_arg().
1Webdevstudios
1Ithemes Paypal Pro
Nov 21, 2024
Aug 28, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
PayPal Pro Add-on for iThemes Exchange before 1.1.0 for WordPress has XSS via add_query_arg() and remove_query_arg().
1Ithemes
1Membership
Nov 21, 2024
Aug 28, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Membership Add-on for iThemes Exchange before 1.3.0 for WordPress has XSS via add_query_arg() and remove_query_arg().
1Ithemes
1Manual Purchases
Nov 21, 2024
Aug 28, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Manual Purchases Add-on for iThemes Exchange before 1.1.0 for WordPress has XSS via add_query_arg() and remove_query_arg().
1Ithemes
1Invoices
Nov 21, 2024
Aug 28, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Invoices Add-on for iThemes Exchange before 1.4.0 for WordPress has XSS via add_query_arg() and remove_query_arg().
1Ithemes
1Easy Us Sales Taxes
Nov 21, 2024
Aug 28, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Easy US Sales Taxes Add-on for iThemes Exchange before 1.1.0 for WordPress has XSS via add_query_arg() and remove_query_arg().
1My Calendar Project
1My Calendar
Jun 17, 2026
Aug 28, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The my-calendar plugin before 3.1.10 for WordPress has XSS.
1Updraftplus
1Updraftplus
Nov 21, 2024
Aug 28, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The updraftplus plugin before 1.13.5 for WordPress has XSS in rare cases where an attacker controls a string logged to a log file.
1Ithemes
1Easy Eu Value Added (vat) Taxes
Nov 21, 2024
Aug 28, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Easy EU Value Added (VAT) Taxes Add-on for iThemes Exchange before 1.2.0 for WordPress has XSS via add_query_arg() and remove_query_arg().
1Ithemes
1Easy Canadian Sales Taxes
Nov 21, 2024
Aug 28, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Easy Canadian Sales Taxes Add-on for iThemes Exchange before 1.1.0 for WordPress has XSS via add_query_arg() and remove_query_arg().