← Back
CWE-79

46,282 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (46,282)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Una
1Una
Jun 17, 2026
Aug 9, 2019
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
studio/polyglot.php?page=etemplates in UNA 10.0.0-RC1 allows XSS via the System Name field under Emails during template editing.
110web
1Photo Gallery
Jun 17, 2026
Aug 9, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The 10Web Photo Gallery plugin before 1.5.23 for WordPress has authenticated stored XSS.
1Mq Woocommerce Products Price Bulk Edit Project
1Mq Woocommerce Products Price Bulk Edit
Jun 17, 2026
Aug 9, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The mq-woocommerce-products-price-bulk-edit (aka Woocommerce Products Price Bulk Edit) plugin 2.0 for WordPress allows XSS via the wp-admin/admin-ajax.php?action=update_options show_products_page_limit parameter.
1Codepeople
1Appointment Booking Calendar
Jun 17, 2026
Aug 9, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Appointment Booking Calendar plugin 1.3.18 for WordPress allows XSS via the wp-admin/admin-post.php editionarea parameter.
1Foliovision
1Fv Flowplayer Video Player
Jun 17, 2026
Aug 9, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The FV Flowplayer Video Player plugin before 7.3.14.727 for WordPress allows email subscription XSS.
1Codecabin
1Wp Go Maps
Jun 17, 2026
Aug 9, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The WP Google Maps plugin before 7.11.35 for WordPress allows XSS via the wp-admin/ rectangle_name or rectangle_opacity parameter.
1Tribulant
1Newsletters
Jun 17, 2026
Aug 9, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The Tribulant Newsletters plugin before 4.6.19 for WordPress allows XSS via the wp-admin/admin-ajax.php?action=newsletters_load_new_editor contentarea parameter.
1Codepeople
1Cp Contact Form With Paypal
Jun 17, 2026
Aug 9, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The "CP Contact Form with PayPal" plugin before 1.2.99 for WordPress has XSS in the publishing wizard via the wp-admin/admin.php?page=cp_contact_form_paypal.php&pwizard=1 cp_contactformpp_id parameter.
1Elementalpath
1Cognitoys Dino Firmware
Nov 21, 2024
Aug 8, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cognitoys Dino devices allow XSS via the SSID.
1Getwooplugins
1Woo Variation Swatches
Jun 17, 2026
Aug 8, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The woo-variation-swatches (aka Variation Swatches for WooCommerce) plugin 1.0.61 for WordPress allows XSS via the wp-admin/admin.php?page=woo-variation-swatches-settings tab parameter.
1Backpackforlaravel
1Backpack\crud
Nov 21, 2024
Aug 8, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Backpack\CRUD Backpack component before 3.4.9 for Laravel allows XSS via the select field type.
1Apache
1Ranger
Jun 17, 2026
Aug 8, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Policy import functionality in Apache Ranger 0.7.0 to 1.2.0 is vulnerable to a cross-site scripting issue. Upgrade to 2.0.0 or later version of Apache Ranger with the fix.
1Verdaccio
1Verdaccio
Jun 17, 2026
Aug 8, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
verdaccio before 3.12.0 allows XSS.
11crm
11crm On Premise
Jun 17, 2026
Aug 8, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
1CRM On-Premise Software 8.5.7 allows XSS via a payload that is mishandled during a Run Report operation.
1Netgear
1Ex7000 Firmware
Nov 21, 2024
Aug 8, 2019
N/A· v4
5.2 MEDIUM· v3
2.9 LOW· v2
NETGEAR EX7000 V1.0.0.42_1.0.94 devices allow XSS via the SSID.
1Cisco
2Enterprise Network Function Virtualization Infrastructure
Enterprise Nfv Infrastructure Software
Aug 24, 2026
Aug 8, 2019
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
A vulnerability in the web portal framework of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-b...Show more
A vulnerability in the web portal framework of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based interface. The vulnerability is due to improper input validation of log file content stored on the affected device. An attacker could exploit this vulnerability by modifying a log file with malicious code and getting a user to view the modified log file. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or to access sensitive, browser-based information.Show less
1Cisco
1Spa112 2 Port Phone Adapter Firmware
Jun 17, 2026
Aug 8, 2019
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
A vulnerability in the web-based interface of the Cisco SPA112 2-Port Phone Adapter could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against another user of the device. The vul...Show more
A vulnerability in the web-based interface of the Cisco SPA112 2-Port Phone Adapter could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against another user of the device. The vulnerability is due to insufficient validation of user-supplied input by the web-based interface of the affected device. An attacker could exploit this vulnerability by inserting malicious code in one of the configuration fields. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.Show less
1Cisco
1Secure Firewall Management Center
Jun 17, 2026
Aug 8, 2019
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
A vulnerability in the web-based management interface of Cisco Firepower Management Center could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based mana...Show more
A vulnerability in the web-based management interface of Cisco Firepower Management Center could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected system. The vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of the affected system. An attacker could exploit this vulnerability by persuading a user of the interface to click a malicious link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.Show less
1Backdropcms
1Backdrop Core
Jun 17, 2026
Aug 8, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In Backdrop CMS 1.12.x before 1.12.8 and 1.13.x before 1.13.3, some menu links within the administration bar may be crafted to execute JavaScript when the administrator is logged in and uses the search functionality. (Th...Show more
In Backdrop CMS 1.12.x before 1.12.8 and 1.13.x before 1.13.3, some menu links within the administration bar may be crafted to execute JavaScript when the administrator is logged in and uses the search functionality. (This issue is mitigated by the attacker needing permissions to create administrative menu links, such as by creating a content type or layout. Such permissions are usually restricted to trusted or administrative users.)Show less
1Backdropcms
1Backdrop
Jun 17, 2026
Aug 8, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Backdrop CMS 1.12.x before 1.12.8 and 1.13.x before 1.13.3 doesn't sufficiently filter output when displaying certain block labels created by administrators. An attacker could potentially craft a specialized label, then...Show more
Backdrop CMS 1.12.x before 1.12.8 and 1.13.x before 1.13.3 doesn't sufficiently filter output when displaying certain block labels created by administrators. An attacker could potentially craft a specialized label, then have an administrator execute scripting when administering a layout. (This issue is mitigated by the attacker needing permission to create custom blocks on the site, which is typically an administrative permission.)Show less