CWE-79
46,289 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (46,289)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Getawesomesupport 1Awesome Support Nov 21, 2024 Aug 20, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The awesome-support plugin before 3.1.7 for WordPress has XSS via custom information messages. |
1Oldstreetsolutions 1Live Input Macros Jun 17, 2026 Aug 20, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The Live:Text Box macro in the Old Street Live Input Macros app before 2.11 for Confluence has XSS, leading to theft of the Administrator Session Cookie. |
1Yofla 1360 Product Rotation Jun 17, 2026 Aug 20, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The 360-product-rotation plugin before 1.4.8 for WordPress has reflected XSS. |
1Open Xchange 1Open Xchange Appsuite Jun 17, 2026 Aug 20, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 OX App Suite 7.10.0 to 7.10.2 allows XSS. |
Fat Free CRM before 0.18.1 has XSS in the tags_helper in app/helpers/tags_helper.rb. |
FlightPath 4.8.3 has XSS in the Content, Edit urgent message, and Users sections of the Admin Console. This could lead to cookie stealing and other malicious actions. |
FUEL CMS 1.4.4 has XSS in the Create Blocks section of the Admin console. This could lead to cookie stealing and other malicious actions. This vulnerability can be exploited with an authenticated account but can also imp...Show more |
1Lenovo 15Bladecenter Hs22 Firmware Bladecenter Hs22v FirmwareBladecenter Hx5 Firmware+12 moreJun 17, 2026 Aug 19, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 A stored cross-site scripting (XSS) vulnerability exists in various firmware versions of the legacy IBM System x IMM (IMM v1) embedded Baseboard Management Controller (BMC). This vulnerability could allow an unauthentica...Show more |
1Awesomemotive 1Easy Digital Downloads Jun 17, 2026 Aug 16, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The easy-digital-downloads plugin before 2.9.16 for WordPress has XSS related to IP address logging. |
1Bestwebsoft 1Zendesk Help Center Nov 21, 2024 Aug 16, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The zendesk-help-center plugin before 1.0.5 for WordPress has multiple XSS issues. |
The xo-security plugin before 1.5.3 for WordPress has XSS. |
The Kunena extension before 5.1.14 for Joomla! allows XSS via BBCode. |
An issue was discovered in WSO2 API Manager 2.6.0 before WSO2-CARBON-PATCH-4.4.0-4457. There is XSS via a crafted filename to the file-upload feature of the event simulator component. |
DWSurvey through 2019-07-22 has reflected XSS via the design/qu-multi-fillblank!answers.action surveyId parameter. |
1Prospecta 1Master Data Online Nov 21, 2024 Aug 15, 2019 N/A· v4 5.4 MEDIUM· v3 4.3 MEDIUM· v2 Prospecta Master Data Online (MDO) 2.0 has Stored XSS. |
CMS Clipper 1.3.3 has XSS in the Security tab search, User Groups, Resource Groups, and User/Resource Group Links fields. |
The Custom 404 Pro plugin 3.2.8 for WordPress has XSS via the wp-admin/admin.php?page=c4p-main page parameter. |
1Codepeople 1Cp Contact Form With Paypal Jun 17, 2026 Aug 15, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The "CP Contact Form with PayPal" plugin before 1.2.98 for WordPress has XSS in CSS edition. |
Evolution CMS 2.0.x allows XSS via a description and new category location in a template. NOTE: the vendor states that the behavior is consistent with the "access policy in the administration panel. |
All versions up to V1.1.10P3T18 of ZTE ZXHN F670 product are impacted by cross-site scripting vulnerability (XSS). Due to incomplete input validation, an authorized user can exploit this vulnerability to execute maliciou...Show more |