CWE-79
46,293 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (46,293)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The events-manager plugin before 5.5 for WordPress has XSS via EM_Ticket::get_post. |
The events-manager plugin before 5.5.2 for WordPress has XSS in the booking form. |
The events-manager plugin before 5.1.7 for WordPress has XSS via JSON call links. |
In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.837, XSS in the domain parameter allows a low-privilege user to achieve root access via the email list page. |
REDCap before 9.3.0 allows XSS attacks against non-administrator accounts on the Data Import Tool page via a CSV data import file. |
The Timeline feature in my_view_page.php in MantisBT through 2.21.1 has a stored cross-site scripting (XSS) vulnerability, allowing execution of arbitrary code (if CSP settings permit it) after uploading an attachment wi...Show more |
1Cisco 1Unified Contact Center Express Jun 17, 2026 Aug 21, 2019 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 A vulnerability in the web-based management interface of Cisco Unified Contact Center Express (Unified CCX) could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a us...Show more |
The all-in-one-schemaorg-rich-snippets plugin before 1.5.0 for WordPress has XSS on the settings page. |
The pdf-print plugin before 2.0.3 for WordPress has multiple XSS issues. |
1Bestwebsoft 1Error Log Viewer Nov 21, 2024 Aug 21, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The error-log-viewer plugin before 1.0.6 for WordPress has multiple XSS issues. |
1Embed Images In Comments Project 1Embed Images In Comments Nov 21, 2024 Aug 21, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The embed-comment-images plugin before 0.6 for WordPress has XSS. |
The cforms2 plugin before 14.13.3 for WordPress has multiple XSS issues. |
1Smokesignal Project 1Smokesignal Nov 21, 2024 Aug 21, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The smokesignal plugin before 1.2.7 for WordPress has XSS. |
The megamenu plugin before 2.4 for WordPress has XSS. |
The bws-linkedin plugin before 1.0.5 for WordPress has multiple XSS issues. |
The aryo-activity-log plugin before 2.3.3 for WordPress has XSS. |
The aryo-activity-log plugin before 2.3.2 for WordPress has XSS. |
1Duplicate Post Project 1Duplicate Post Nov 21, 2024 Aug 21, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The duplicate-post plugin before 2.6 for WordPress has XSS. |
The cforms2 plugin before 13.2 for WordPress has XSS in lib_ajax.php. |
1Count Per Day Project 1Count Per Day Nov 21, 2024 Aug 21, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The count-per-day plugin before 3.2.3 for WordPress has XSS via search words. |