← Back
CWE-79

46,770 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (46,770)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
-
-
Aug 20, 2026
Aug 18, 2026
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Contributor Cross Site Scripting (XSS) in Wufoo Shortcode <= 1.55 versions.
-
-
Aug 20, 2026
Aug 18, 2026
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Contributor Cross Site Scripting (XSS) in Video Conferencing with Zoom <= 4.6.8 versions.
-
-
Aug 20, 2026
Aug 18, 2026
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Contributor Cross Site Scripting (XSS) in Login With Ajax <= 4.5.1 versions.
-
-
Aug 20, 2026
Aug 18, 2026
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Contributor Cross Site Scripting (XSS) in WPZOOM Forms – Contact Form Plugin for Gutenberg <= 2.0.4 versions.
-
-
Aug 20, 2026
Aug 18, 2026
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Contributor Cross Site Scripting (XSS) in Frontend Admin by DynamiApps <= 3.29.10 versions.
-
-
Aug 20, 2026
Aug 18, 2026
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Contributor Cross Site Scripting (XSS) in Featured Video Plus <= 2.3.3 versions.
-
-
Aug 20, 2026
Aug 18, 2026
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Contributor Cross Site Scripting (XSS) in Wise Chat <= 3.4 versions.
-
-
Aug 20, 2026
Aug 18, 2026
N/A· v4
7.1 HIGH· v3
N/A· v2
Unauthenticated Cross Site Scripting (XSS) in Fluent Forms Pro Add On Pack < 6.2.12 versions.
-
-
Aug 20, 2026
Aug 18, 2026
N/A· v4
7.1 HIGH· v3
N/A· v2
Unauthenticated Cross Site Scripting (XSS) in Kirki <= 6.2.3 versions.
-
-
Aug 25, 2026
Aug 18, 2026
N/A· v4
7.1 HIGH· v3
N/A· v2
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MapSteps UG Ultimate Dashboard Pro allows DOM-Based XSS. This issue affects Ultimate Dashboard Pro: from n/a through...Show more
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MapSteps UG Ultimate Dashboard Pro allows DOM-Based XSS. This issue affects Ultimate Dashboard Pro: from n/a through 3.11.2.Show less
-
-
Aug 18, 2026
Aug 18, 2026
N/A· v4
8.3 HIGH· v3
N/A· v2
Trilium Notes is a cross-platform, hierarchical note taking application focused on building large personal knowledge bases. Prior to 0.103.0, the #iconClass label value is returned raw by getNoteIcon() and inserted witho...Show more
Trilium Notes is a cross-platform, hierarchical note taking application focused on building large personal knowledge bases. Prior to 0.103.0, the #iconClass label value is returned raw by getNoteIcon() and inserted without HTML attribute encoding into class attributes in apps/client/src/widgets/quick_search.ts and apps/client/src/services/note_autocomplete.ts, allowing a stored payload to execute automatically when a victim opens a new tab or uses Ctrl+J and, because Electron enables nodeIntegration and disables contextIsolation, run operating-system commands as the victim. This issue is fixed in version 0.103.0.Show less
-
-
Aug 20, 2026
Aug 18, 2026
N/A· v4
7.1 HIGH· v3
N/A· v2
Unauthenticated Cross Site Scripting (XSS) in BP Better Messages <= 2.15.22 versions.
-
-
Aug 20, 2026
Aug 18, 2026
N/A· v4
7.1 HIGH· v3
N/A· v2
Unauthenticated Cross Site Scripting (XSS) in Mayosis Core <= 5.4.7 versions.
-
-
Aug 20, 2026
Aug 18, 2026
N/A· v4
7.1 HIGH· v3
N/A· v2
Unauthenticated Cross Site Scripting (XSS) in SSL Zen <= 4.7.43 versions.
-
-
Aug 20, 2026
Aug 18, 2026
N/A· v4
7.1 HIGH· v3
N/A· v2
Unauthenticated Cross Site Scripting (XSS) in Quill Forms <= 5.7.1 versions.
-
-
Aug 18, 2026
Aug 18, 2026
5.1 MEDIUM· v4
N/A· v3
N/A· v2
DOMPurify before 3.4.13 contains a cross-site scripting vulnerability in IN_PLACE sanitization where element-removal hooks fail to neutralize detached subtrees. Attackers can supply HTML with event handlers on descendant...Show more
DOMPurify before 3.4.13 contains a cross-site scripting vulnerability in IN_PLACE sanitization where element-removal hooks fail to neutralize detached subtrees. Attackers can supply HTML with event handlers on descendant elements that execute after sanitization completes, even though the returned root appears clean.Show less
-
-
Sep 8, 2026
Aug 18, 2026
5.1 MEDIUM· v4
5.4 MEDIUM· v3
N/A· v2
Grav before 2.0.14 contains a stored cross-site scripting vulnerability in the Security::detectXss() function (system/src/Grav/Common/Security.php). All XSS detection patterns use the PCRE /u (UTF-8) modifier, so a singl...Show more
Grav before 2.0.14 contains a stored cross-site scripting vulnerability in the Security::detectXss() function (system/src/Grav/Common/Security.php). All XSS detection patterns use the PCRE /u (UTF-8) modifier, so a single invalid UTF-8 byte anywhere in page content causes preg_match() to return false for every pattern, silently bypassing the save-time XSS safety gate (Validation::checkSafety()). An authenticated attacker with page-edit permissions (without the security.xss_whitelist privilege) can store malicious JavaScript that executes in the browser of a visitor who views the affected page.Show less
-
-
Sep 8, 2026
Aug 18, 2026
5.1 MEDIUM· v4
7.6 HIGH· v3
N/A· v2
Grav before 2.0.15 contains a stored cross-site scripting vulnerability in the audio and video media rendering through the sourceParsedownElement method. The media URL fragment is concatenated unescaped into rawHtml sour...Show more
Grav before 2.0.15 contains a stored cross-site scripting vulnerability in the audio and video media rendering through the sourceParsedownElement method. The media URL fragment is concatenated unescaped into rawHtml source elements, allowing attackers to inject arbitrary HTML and JavaScript that executes in viewers' sessions.Show less
-
-
Sep 8, 2026
Aug 18, 2026
9.3 CRITICAL· v4
8.7 HIGH· v3
N/A· v2
Grav before 2.0.15 contains a stored cross-site scripting vulnerability in the detectXss() function where unpaired quotes in unquoted attribute values bypass event-handler detection. Authenticated editors can inject even...Show more
Grav before 2.0.15 contains a stored cross-site scripting vulnerability in the detectXss() function where unpaired quotes in unquoted attribute values bypass event-handler detection. Authenticated editors can inject event handlers like onerror= that pass validation and execute in visitor browsers when page content is rendered.Show less
-
-
Sep 8, 2026
Aug 18, 2026
5.1 MEDIUM· v4
5.4 MEDIUM· v3
N/A· v2
Grav Form Plugin before 9.1.19 fails to escape field-definition properties including prepend, append, spacer text, section text, and select option labels in form templates. Attackers with form authoring privileges can in...Show more
Grav Form Plugin before 9.1.19 fails to escape field-definition properties including prepend, append, spacer text, section text, and select option labels in form templates. Attackers with form authoring privileges can inject arbitrary HTML and JavaScript that executes for all form visitors through unescaped |raw filters and unquoted attributes.Show less