CWE-79
46,286 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (46,286)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Ultimatemember 1Ultimate Member Nov 21, 2024 Aug 12, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The ultimate-member plugin before 1.3.40 for WordPress has XSS on the login form. |
1Ultimatemember 1Ultimate Member Nov 21, 2024 Aug 12, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The ultimate-member plugin before 1.3.18 for WordPress has XSS via text input. |
1Simplesharebuttons 1Simple Share Buttons Adder Nov 21, 2024 Aug 12, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The simple-share-buttons-adder plugin before 6.0.0 for WordPress has XSS. |
The wp-live-chat-support plugin before 8.0.27 for WordPress has XSS via the GDPR page. |
1Wpseeds 1Wp Database Backup Jun 17, 2026 Aug 12, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The wp-database-backup plugin before 5.1.2 for WordPress has XSS. |
1Najeebmedia 1Ppom For Woocommerce Jun 17, 2026 Aug 12, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 The woocommerce-product-addon plugin before 18.4 for WordPress has XSS via an import of a new meta data structure. |
The wp-live-chat-support plugin before 7.1.03 for WordPress has XSS. |
1Wpovernight 1Woocommerce Pdf Invoices& Packing Slips Nov 21, 2024 Aug 12, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The woocommerce-pdf-invoices-packing-slips plugin before 2.0.13 for WordPress has XSS via the tab or section variable on settings screens. |
The wp-live-chat-support plugin before 6.2.02 for WordPress has XSS. |
The wp-google-map-plugin plugin before 3.1.2 for WordPress has XSS. |
1Wp Editor Project 1Wp Editor Nov 21, 2024 Aug 12, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The wp-editor plugin before 1.2.6.3 for WordPress has multiple XSS issues. |
1Wpseeds 1Wp Database Backup Nov 21, 2024 Aug 12, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The wp-database-backup plugin before 4.3.1 for WordPress has XSS. |
1Wpseeds 1Wp Database Backup Nov 21, 2024 Aug 12, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The wp-database-backup plugin before 4.3.3 for WordPress has XSS. |
1Smackcoders 1Import All Pages, Post Types, Products, Orders, And Users As Xml & Csv Nov 21, 2024 Aug 12, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The wp-ultimate-csv-importer plugin before 3.8.1 for WordPress has XSS. |
The wp-google-map-plugin plugin before 2.3.7 for WordPress has XSS related to the add_query_arg() and remove_query_arg() functions. |
In the MobileFrontend extension 1.31 through 1.33 for MediaWiki, XSS exists within the edit summary field in includes/specials/MobileSpecialPageFeed.php. |
1Cloudfoundry 1User Account And Authentication Jun 17, 2026 Aug 9, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Cloud Foundry UAA, versions prior to 74.0.0, is vulnerable to an XSS attack. A remote unauthenticated malicious attacker could craft a URL that contains a SCIM filter that contains malicious JavaScript, which older brows...Show more |
The activity stream gadget in Jira before version 7.13.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the country parameter. |
1Eclipse 1Business Intelligence And Reporting Tools Jun 17, 2026 Aug 9, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 In Eclipse BIRT versions 1.0 to 4.7, the Report Viewer allows Reflected XSS in URL parameter. Attacker can execute the payload in victim's browser context. |
1Hp 13par Storeserv Management Console Jun 17, 2026 Aug 9, 2019 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 A remote multiple cross-site scripting vulnerability was discovered in HPE 3PAR StoreServ Management and Core Software Media version(s): prior to 3.5.0.1. |