CWE-79
46,293 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (46,293)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The wp-retina-2x plugin before 5.2.3 for WordPress has XSS. |
1Time Sheets Project 1Time Sheets Nov 21, 2024 Aug 22, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The time-sheets plugin before 1.5.2 for WordPress has multiple XSS issues. |
1Time Sheets Project 1Time Sheets Nov 21, 2024 Aug 22, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The time-sheets plugin before 1.5.0 for WordPress has XSS via the old timesheet list. |
1Ibericode 1Mailchimp For Wordpress Jan 27, 2026 Aug 22, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The mailchimp-for-wp plugin before 4.1.8 for WordPress has XSS via the return value of add_query_arg. |
1Event Notifier Project 1Event Notifier Nov 21, 2024 Aug 22, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The event-notifier plugin before 1.2.1 for WordPress has XSS via the loading animation. |
The peters-login-redirect plugin before 2.9.1 for WordPress has XSS during the editing of redirect URLs. |
1Memphis Documents Library Project 1Memphis Documents Library Nov 21, 2024 Aug 22, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The memphis-documents-library plugin before 3.0 for WordPress has XSS via $_REQUEST. |
1Reflex Gallery Project 1Reflex Gallery Nov 21, 2024 Aug 22, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The reflex-gallery plugin before 1.4.3 for WordPress has XSS. |
The tubepress plugin before 1.6.5 for WordPress has XSS. |
The give plugin before 2.4.7 for WordPress has XSS via a donor name. |
tiki/tiki-upload_file.php in Tiki 18.4 allows remote attackers to upload JavaScript code that is executed upon visiting a tiki/tiki-download_file.php?display&fileId= URI. |
1Davidlingren 1Media Library Assistant Nov 21, 2024 Aug 22, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The media-library-assistant plugin before 2.74 for WordPress has XSS via the Media/Assistant or Settings/Media Library assistant admin submenu screens. |
1Newstatpress Project 1Newstatpress Nov 21, 2024 Aug 22, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The newstatpress plugin before 1.2.5 for WordPress has multiple stored XSS issues. |
The gnucommerce plugin before 1.4.2 for WordPress has XSS. |
The gnucommerce plugin before 0.5.7-BETA for WordPress has XSS. |
1Wassup Real Time Analytics Project 1Wassup Real Time Analytics Nov 21, 2024 Aug 22, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The wassup plugin before 1.9.1 for WordPress has XSS via the Top stats widget or the wassupURI::add_siteurl method, a different vulnerability than CVE-2012-2633. |
The clean-login plugin before 1.5.1 for WordPress has reflected XSS. |
The contact-form-plugin plugin before 3.3.5 for WordPress has XSS. |
The events-manager plugin before 5.3.6.1 for WordPress has XSS via the booking form and admin areas. |
The events-manager plugin before 5.3.9 for WordPress has XSS in the search form field. |