CWE-79
46,770 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (46,770)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Contributor Cross Site Scripting (XSS) in Wufoo Shortcode <= 1.55 versions. |
Contributor Cross Site Scripting (XSS) in Video Conferencing with Zoom <= 4.6.8 versions. |
Contributor Cross Site Scripting (XSS) in Login With Ajax <= 4.5.1 versions. |
Contributor Cross Site Scripting (XSS) in WPZOOM Forms – Contact Form Plugin for Gutenberg <= 2.0.4 versions. |
Contributor Cross Site Scripting (XSS) in Frontend Admin by DynamiApps <= 3.29.10 versions. |
Contributor Cross Site Scripting (XSS) in Featured Video Plus <= 2.3.3 versions. |
Contributor Cross Site Scripting (XSS) in Wise Chat <= 3.4 versions. |
Unauthenticated Cross Site Scripting (XSS) in Fluent Forms Pro Add On Pack < 6.2.12 versions. |
Unauthenticated Cross Site Scripting (XSS) in Kirki <= 6.2.3 versions. |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MapSteps UG Ultimate Dashboard Pro allows DOM-Based XSS. This issue affects Ultimate Dashboard Pro: from n/a through...Show more |
Trilium Notes is a cross-platform, hierarchical note taking application focused on building large personal knowledge bases. Prior to 0.103.0, the #iconClass label value is returned raw by getNoteIcon() and inserted witho...Show more |
Unauthenticated Cross Site Scripting (XSS) in BP Better Messages <= 2.15.22 versions. |
Unauthenticated Cross Site Scripting (XSS) in Mayosis Core <= 5.4.7 versions. |
Unauthenticated Cross Site Scripting (XSS) in SSL Zen <= 4.7.43 versions. |
Unauthenticated Cross Site Scripting (XSS) in Quill Forms <= 5.7.1 versions. |
DOMPurify before 3.4.13 contains a cross-site scripting vulnerability in IN_PLACE sanitization where element-removal hooks fail to neutralize detached subtrees. Attackers can supply HTML with event handlers on descendant...Show more |
Grav before 2.0.14 contains a stored cross-site scripting vulnerability in the Security::detectXss() function (system/src/Grav/Common/Security.php). All XSS detection patterns use the PCRE /u (UTF-8) modifier, so a singl...Show more |
Grav before 2.0.15 contains a stored cross-site scripting vulnerability in the audio and video media rendering through the sourceParsedownElement method. The media URL fragment is concatenated unescaped into rawHtml sour...Show more |
Grav before 2.0.15 contains a stored cross-site scripting vulnerability in the detectXss() function where unpaired quotes in unquoted attribute values bypass event-handler detection. Authenticated editors can inject even...Show more |
Grav Form Plugin before 9.1.19 fails to escape field-definition properties including prepend, append, spacer text, section text, and select option labels in form templates. Attackers with form authoring privileges can in...Show more |