← Back
CWE-79

46,293 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (46,293)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Gowebsolutions
1Wp Customer Reviews
Nov 21, 2024
Aug 21, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The wp-customer-reviews plugin before 3.0.9 for WordPress has XSS in the admin tools.
1Wpmanage
1Uji Countdown
Nov 21, 2024
Aug 21, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The uji-countdown plugin before 2.0.7 for WordPress has XSS.
1Stellarwp
1The Events Calendar
Jun 17, 2026
Aug 21, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The the-events-calendar plugin before 4.8.2 for WordPress has XSS via the tribe_paged URL parameter.
1Deepsoft
1Weblibrarian
Nov 21, 2024
Aug 21, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The weblibrarian plugin before 3.4.8.7 for WordPress has XSS via front-end short codes.
1Deepsoft
1Weblibrarian
Nov 21, 2024
Aug 21, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The weblibrarian plugin before 3.4.8.6 for WordPress has XSS via front-end short codes.
1Deepsoft
1Weblibrarian
Nov 21, 2024
Aug 21, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The weblibrarian plugin before 3.4.8.5 for WordPress has XSS via front-end short codes.
1Bestwebsoft
1Visitors Online
Nov 21, 2024
Aug 21, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The visitors-online plugin before 1.0.0 for WordPress has multiple XSS issues.
1Fullworksplugins
1Stop User Enumeration
Jan 23, 2026
Aug 21, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The stop-user-enumeration plugin before 1.3.8 for WordPress has XSS.
1Share On Diaspora Project
1Share On Diaspora
Nov 21, 2024
Aug 21, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The share-on-diaspora plugin before 0.7.2 for WordPress has reflected XSS in share URL parameters.
1Fabrix
1Total Security
Nov 21, 2024
Aug 21, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The total-security plugin before 3.4.1 for WordPress has XSS.
1Sermon Browser Project
1Sermon Browser
Nov 21, 2024
Aug 21, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The sermon-browser plugin before 0.45.16 for WordPress has multiple XSS issues.
1Clogica
1Seo Redirection
Nov 21, 2024
Aug 21, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The seo-redirection plugin before 4.3 for WordPress has stored XSS.
1Wpmadeeasy
1Shortcode Factory
Nov 21, 2024
Aug 21, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The shortcode-factory plugin before 1.1.1 for WordPress has XSS via add_query_arg.
1Ibm
1Emptoris Spend Analysis
Jun 17, 2026
Aug 20, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM Emptoris Spend Analysis 10.1.0 through 10.1.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potential...Show more
IBM Emptoris Spend Analysis 10.1.0 through 10.1.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 164066.Show less
1Ibm
1Cloud Private
Jun 17, 2026
Aug 20, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM Cloud Private 3.1.1 and 3.1.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to cr...Show more
IBM Cloud Private 3.1.1 and 3.1.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 158146.Show less
1Open Emr
1Openemr
Jun 17, 2026
Aug 20, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In OpenEMR 5.0.1 and earlier, controller.php contains a reflected XSS vulnerability in the foreign_id parameter. This could allow an attacker to execute arbitrary code in the context of a user's session.
1Open Emr
1Openemr
Jun 17, 2026
Aug 20, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In OpenEMR 5.0.1 and earlier, controller.php contains a reflected XSS vulnerability in the document_id parameter. This could allow an attacker to execute arbitrary code in the context of a user's session.
1Open Emr
1Openemr
Jun 17, 2026
Aug 20, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In OpenEMR 5.0.1 and earlier, controller.php contains a reflected XSS vulnerability in the doc_id parameter. This could allow an attacker to execute arbitrary code in the context of a user's session.
1Open Emr
1Openemr
Jun 17, 2026
Aug 20, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In OpenEMR 5.0.1 and earlier, controller.php contains a reflected XSS vulnerability in the patient_id parameter. This could allow an attacker to execute arbitrary code in the context of a user's session.
1Soflyy
1Wp All Import
Nov 21, 2024
Aug 20, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The wp-all-import plugin before 3.4.7 for WordPress has XSS.