CWE-79
46,286 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (46,286)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The download-monitor plugin before 1.7.1 for WordPress has XSS related to add_query_arg. |
The contact-form-plugin plugin before 3.96 for WordPress has XSS. |
1Tipsandtricks Hq 1All In One Wp Security & Firewall Nov 21, 2024 Aug 13, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The all-in-one-wp-security-and-firewall plugin before 3.9.5 for WordPress has XSS in add_query_arg and remove_query_arg function instances. |
1Tipsandtricks Hq 1All In One Wp Security & Firewall Nov 21, 2024 Aug 13, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The all-in-one-wp-security-and-firewall plugin before 3.9.8 for WordPress has XSS in the unlock request feature. |
The contact-form-plugin plugin before 3.52 for WordPress has XSS. |
The job-manager plugin before 0.7.19 for WordPress has multiple XSS issues. |
Adive Framework through 2.0.7 is affected by XSS in the Create New Table and Create New Navigation Link functions. |
iCMS 7.0.15 allows admincp.php?app=apps XSS via the keywords parameter. |
An issue was discovered in Frappe Framework 10, 11 before 11.1.46, and 12. There exists an XSS vulnerability. |
1Ultimatemember 1Ultimate Member Jun 17, 2026 Aug 12, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 The ultimate-member plugin before 2.0.52 for WordPress has XSS during an account upgrade. |
1Ultimatemember 1Ultimate Member Jun 17, 2026 Aug 12, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 The ultimate-member plugin before 2.0.52 for WordPress has XSS related to UM Roles create and edit operations. |
1Ultimatemember 1Ultimate Member Jun 17, 2026 Aug 12, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 The ultimate-member plugin before 2.0.54 for WordPress has XSS. |
1Booster 1Booster For Woocommerce Nov 21, 2024 Aug 12, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The woocommerce-jetpack plugin before 3.8.0 for WordPress has XSS in the Products Per Page feature. |
1Ultimatemember 1Ultimate Member Nov 21, 2024 Aug 12, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The ultimate-member plugin before 2.0.4 for WordPress has XSS. |
1Bestwebsoft 1Twitter Button Nov 21, 2024 Aug 12, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The twitter-plugin plugin before 2.55 for WordPress has XSS. |
1Wpdeveloper 1Twitter Cards Meta Nov 21, 2024 Aug 12, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The twitter-cards-meta plugin before 2.5.0 for WordPress has XSS. |
The subscriber plugin before 1.3.5 for WordPress has multiple XSS issues. |
The social-login-bws plugin before 0.2 for WordPress has multiple XSS issues. |
1Bestwebsoft 1Social Buttons Pack Nov 21, 2024 Aug 12, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The social-buttons-pack plugin before 1.1.1 for WordPress has multiple XSS issues. |
1Simple Membership Plugin 1Simple Membership Nov 21, 2024 Aug 12, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The simple-membership plugin before 3.5.7 for WordPress has XSS. |