CWE-79
46,299 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (46,299)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
12checkout 1Ithemes 2checkout Nov 21, 2024 Aug 28, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 2Checkout Add-on for iThemes Exchange before 1.1.0 for WordPress has XSS via add_query_arg() and remove_query_arg(). |
iThemes Exchange before 1.12.0 for WordPress has XSS via add_query_arg() and remove_query_arg(). |
The Post Connector plugin before 1.0.4 for WordPress has XSS via add_query_arg() and remove_query_arg(). |
The Related Posts plugin before 1.8.2 for WordPress has XSS via add_query_arg() and remove_query_arg(). |
The updraftplus plugin before 1.9.64 for WordPress has XSS via add_query_arg() and remove_query_arg(). |
1Feedwordpress Project 1Feedwordpress Nov 21, 2024 Aug 28, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The feedwordpress plugin before 2015.0514 for WordPress has XSS via add_query_arg() and remove_query_arg(). |
The akismet plugin before 3.1.5 for WordPress has XSS. |
1Wp Vipergb Project 1Wp Vipergb Nov 21, 2024 Aug 28, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The wp-vipergb plugin before 1.3.16 for WordPress has XSS via add_query_arg() and remove_query_arg(), a different issue than CVE-2014-9460. |
1Simbahosting 1Two Factor Authentication Nov 21, 2024 Aug 28, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The two-factor-authentication plugin before 1.1.10 for WordPress has XSS in the admin area. |
The gigpress plugin before 2.3.11 for WordPress has XSS. |
The sharebar plugin before 1.2.2 for WordPress has XSS, a different issue than CVE-2013-3491. |
The redirection plugin before 2.2.12 for WordPress has XSS, a different issue than CVE-2011-4562. |
The redirection plugin before 2.2.9 for WordPress has XSS in the admin menu, a different issue than CVE-2011-4562. |
public/js/frappe/form/footer/timeline.js in Frappe Framework 12 through 12.0.8 does not escape HTML in the timeline and thus is affected by crafted "changed value of" text. |
2Debian Xymon2Debian Linux XymonJun 17, 2026 Aug 27, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 In Xymon through 4.3.28, an XSS vulnerability exists in the csvinfo CGI script due to insufficient filtering of the db parameter. |
1Dev4press 1Gd Rating System Apr 23, 2025 Aug 27, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The gd-rating-system plugin before 2.1 for WordPress has XSS in log.php. |
The wp-polls plugin before 2.73.1 for WordPress has XSS via the Poll bar option. |
1Slickremix 1Feed Them Social Nov 21, 2024 Aug 27, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The feed-them-social plugin before 1.7.0 for WordPress has reflected XSS in the Facebook Feeds load more button. |
The zoho-salesiq plugin before 1.0.9 for WordPress has stored XSS. |
1Etoilewebdesign 1Ultimate Faq Jun 17, 2026 Aug 27, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The ultimate-faqs plugin before 1.8.22 for WordPress has XSS. |