← Back
CWE-79

46,293 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (46,293)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Pixelite
1Events Manager
Nov 21, 2024
Aug 22, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The events-manager plugin before 5.5 for WordPress has XSS via EM_Ticket::get_post.
1Pixelite
1Events Manager
Nov 21, 2024
Aug 22, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The events-manager plugin before 5.5.2 for WordPress has XSS in the booking form.
1Pixelite
1Events Manager
Nov 21, 2024
Aug 22, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The events-manager plugin before 5.1.7 for WordPress has XSS via JSON call links.
1Control Webpanel
1Webpanel
Jun 17, 2026
Aug 21, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.837, XSS in the domain parameter allows a low-privilege user to achieve root access via the email list page.
1Vanderbilt
1Redcap
Jun 17, 2026
Aug 21, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
REDCap before 9.3.0 allows XSS attacks against non-administrator accounts on the Data Import Tool page via a CSV data import file.
1Mantisbt
1Mantisbt
Jun 17, 2026
Aug 21, 2019
N/A· v4
9.6 CRITICAL· v3
6.8 MEDIUM· v2
The Timeline feature in my_view_page.php in MantisBT through 2.21.1 has a stored cross-site scripting (XSS) vulnerability, allowing execution of arbitrary code (if CSP settings permit it) after uploading an attachment wi...Show more
The Timeline feature in my_view_page.php in MantisBT through 2.21.1 has a stored cross-site scripting (XSS) vulnerability, allowing execution of arbitrary code (if CSP settings permit it) after uploading an attachment with a crafted filename. The code is executed for any user having visibility to the issue, whenever My View Page is displayed.Show less
1Cisco
1Unified Contact Center Express
Jun 17, 2026
Aug 21, 2019
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
A vulnerability in the web-based management interface of Cisco Unified Contact Center Express (Unified CCX) could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a us...Show more
A vulnerability in the web-based management interface of Cisco Unified Contact Center Express (Unified CCX) could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. The vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of the affected software. An attacker could exploit this vulnerability by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information. To exploit this vulnerability, the attacker needs valid administrator credentials.Show less
1Brainstormforce
1Schema
Jun 27, 2025
Aug 21, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The all-in-one-schemaorg-rich-snippets plugin before 1.5.0 for WordPress has XSS on the settings page.
1Bestwebsoft
1Pdf & Print
Nov 21, 2024
Aug 21, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The pdf-print plugin before 2.0.3 for WordPress has multiple XSS issues.
1Bestwebsoft
1Error Log Viewer
Nov 21, 2024
Aug 21, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The error-log-viewer plugin before 1.0.6 for WordPress has multiple XSS issues.
1Embed Images In Comments Project
1Embed Images In Comments
Nov 21, 2024
Aug 21, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The embed-comment-images plugin before 0.6 for WordPress has XSS.
1Cformsii Project
1Cformsii
Nov 21, 2024
Aug 21, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The cforms2 plugin before 14.13.3 for WordPress has multiple XSS issues.
1Smokesignal Project
1Smokesignal
Nov 21, 2024
Aug 21, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The smokesignal plugin before 1.2.7 for WordPress has XSS.
1Megamenu
1Max Mega Menu
Nov 21, 2024
Aug 21, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The megamenu plugin before 2.4 for WordPress has XSS.
1Bestwebsoft
1Linkedin
Nov 21, 2024
Aug 21, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The bws-linkedin plugin before 1.0.5 for WordPress has multiple XSS issues.
1Pojo
1Activity Log
Nov 21, 2024
Aug 21, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The aryo-activity-log plugin before 2.3.3 for WordPress has XSS.
1Pojo
1Activity Log
Nov 21, 2024
Aug 21, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The aryo-activity-log plugin before 2.3.2 for WordPress has XSS.
1Duplicate Post Project
1Duplicate Post
Nov 21, 2024
Aug 21, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The duplicate-post plugin before 2.6 for WordPress has XSS.
1Cformsii Project
1Cformsii
Nov 21, 2024
Aug 21, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The cforms2 plugin before 13.2 for WordPress has XSS in lib_ajax.php.
1Count Per Day Project
1Count Per Day
Nov 21, 2024
Aug 21, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The count-per-day plugin before 3.2.3 for WordPress has XSS via search words.