CWE-79
46,282 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (46,282)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
studio/polyglot.php?page=etemplates in UNA 10.0.0-RC1 allows XSS via the System Name field under Emails during template editing. |
The 10Web Photo Gallery plugin before 1.5.23 for WordPress has authenticated stored XSS. |
1Mq Woocommerce Products Price Bulk Edit Project 1Mq Woocommerce Products Price Bulk Edit Jun 17, 2026 Aug 9, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 The mq-woocommerce-products-price-bulk-edit (aka Woocommerce Products Price Bulk Edit) plugin 2.0 for WordPress allows XSS via the wp-admin/admin-ajax.php?action=update_options show_products_page_limit parameter. |
1Codepeople 1Appointment Booking Calendar Jun 17, 2026 Aug 9, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The Appointment Booking Calendar plugin 1.3.18 for WordPress allows XSS via the wp-admin/admin-post.php editionarea parameter. |
1Foliovision 1Fv Flowplayer Video Player Jun 17, 2026 Aug 9, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The FV Flowplayer Video Player plugin before 7.3.14.727 for WordPress allows email subscription XSS. |
The WP Google Maps plugin before 7.11.35 for WordPress allows XSS via the wp-admin/ rectangle_name or rectangle_opacity parameter. |
The Tribulant Newsletters plugin before 4.6.19 for WordPress allows XSS via the wp-admin/admin-ajax.php?action=newsletters_load_new_editor contentarea parameter. |
1Codepeople 1Cp Contact Form With Paypal Jun 17, 2026 Aug 9, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 The "CP Contact Form with PayPal" plugin before 1.2.99 for WordPress has XSS in the publishing wizard via the wp-admin/admin.php?page=cp_contact_form_paypal.php&pwizard=1 cp_contactformpp_id parameter. |
1Elementalpath 1Cognitoys Dino Firmware Nov 21, 2024 Aug 8, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Cognitoys Dino devices allow XSS via the SSID. |
1Getwooplugins 1Woo Variation Swatches Jun 17, 2026 Aug 8, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The woo-variation-swatches (aka Variation Swatches for WooCommerce) plugin 1.0.61 for WordPress allows XSS via the wp-admin/admin.php?page=woo-variation-swatches-settings tab parameter. |
1Backpackforlaravel 1Backpack\crud Nov 21, 2024 Aug 8, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The Backpack\CRUD Backpack component before 3.4.9 for Laravel allows XSS via the select field type. |
Policy import functionality in Apache Ranger 0.7.0 to 1.2.0 is vulnerable to a cross-site scripting issue. Upgrade to 2.0.0 or later version of Apache Ranger with the fix. |
verdaccio before 3.12.0 allows XSS. |
1CRM On-Premise Software 8.5.7 allows XSS via a payload that is mishandled during a Run Report operation. |
NETGEAR EX7000 V1.0.0.42_1.0.94 devices allow XSS via the SSID. |
1Cisco 2Enterprise Network Function Virtualization Infrastructure Enterprise Nfv Infrastructure SoftwareAug 24, 2026 Aug 8, 2019 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 A vulnerability in the web portal framework of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-b...Show more |
1Cisco 1Spa112 2 Port Phone Adapter Firmware Jun 17, 2026 Aug 8, 2019 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 A vulnerability in the web-based interface of the Cisco SPA112 2-Port Phone Adapter could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against another user of the device. The vul...Show more |
1Cisco 1Secure Firewall Management Center Jun 17, 2026 Aug 8, 2019 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 A vulnerability in the web-based management interface of Cisco Firepower Management Center could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based mana...Show more |
In Backdrop CMS 1.12.x before 1.12.8 and 1.13.x before 1.13.3, some menu links within the administration bar may be crafted to execute JavaScript when the administrator is logged in and uses the search functionality. (Th...Show more |
Backdrop CMS 1.12.x before 1.12.8 and 1.13.x before 1.13.3 doesn't sufficiently filter output when displaying certain block labels created by administrators. An attacker could potentially craft a specialized label, then...Show more |