CWE-79
46,037 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (46,037)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Pwrplugins 1Magic Buttons For Elementor Jun 17, 2026 Jul 2, 2025 N/A· v4 5.4 MEDIUM· v3 N/A· v2 The Magic Buttons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's magic-button shortcode in all versions up to, and including, 1.0 due to insufficient input sanitization a...Show more |
1Pwrplugins 1Magic Buttons For Elementor Jun 17, 2026 Jul 2, 2025 N/A· v4 5.4 MEDIUM· v3 N/A· v2 The Magic Buttons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's magic-button shortcode in all versions up to, and including, 1.0 due to insufficient input sanitization a...Show more |
1Hellomohsinkhan 1Wp Front End Login And Register Jun 17, 2026 Jul 2, 2025 N/A· v4 6.1 MEDIUM· v3 N/A· v2 The WP Front-end login and register plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the email and wpmp_reset_password_token parameters in all versions up to, and including, 2.1.0 due to insuffici...Show more |
1Contec 1Conprosys Hmi System Jun 17, 2026 Jul 1, 2025 5.1 MEDIUM· v4 6.1 MEDIUM· v3 N/A· v2 The Contec Co.,Ltd. CONPROSYS HMI System (CHS) is vulnerable to Cross-Site Scripting (XSS) in the getqsetting.php functionality that could allow reflected execution of scripts in the browser on interaction.This issue aff...Show more |
The Dear Flipbook – PDF Flipbook, 3D Flipbook, PDF embed, PDF viewer plugin for WordPress is vulnerable to DOM-Based Reflected Cross-Site Scripting via the ‘pdf-source’ parameter in all versions up to, and including, 2.3...Show more |
1Themefic 1Ultimate Addons For Contact Form 7 Jun 17, 2026 Jul 1, 2025 N/A· v4 5.4 MEDIUM· v3 N/A· v2 The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's UACF7_CUSTOM_FIELDS shortcode in all versions up to, and including, 3.5.21 due to insufficient input...Show more |
A stored cross-site scripting vulnerability in ENS HX 10.0.4 allows a malicious user to inject arbitrary HTML into the ENS HX Malware Scan Name field, resulting in the exposure of sensitive data. |
1Ibm 33948 Ved Firmware 3948 Vef Firmware3957 Ved FirmwareJun 17, 2026 Jul 1, 2025 N/A· v4 5.4 MEDIUM· v3 N/A· v2 IBM System Storage Virtualization Engine TS7700 3957 VED R5.4 8.54.2.17, R6.0 8.60.0.115, 3948 VED R5.4 8.54.2.17, R6.0 8.60.0.115, and 3948 VEF R6.0 8.60.0.115 is vulnerable to cross-site scripting. This vulnerability a...Show more |
1Ibm 33948 Ved Firmware 3948 Vef Firmware3957 Ved FirmwareJun 17, 2026 Jul 1, 2025 N/A· v4 6.1 MEDIUM· v3 N/A· v2 IBM System Storage Virtualization Engine TS7700 3957 VED R5.4 8.54.2.17, R6.0 8.60.0.115, 3948 VED R5.4 8.54.2.17, R6.0 8.60.0.115, and 3948 VEF R6.0 8.60.0.115 is vulnerable to cross-site scripting. This vulnerability a...Show more |
Frappe is a full-stack web application framework. Prior to versions 14.94.2 and 15.57.0, authenticated users could upload carefully crafted malicious files via Data Import, leading to cross-site scripting (XSS). This iss...Show more |
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Devinim Software Library Software allows Reflected XSS.
This issue affects Library Software: before 24.11.02. |
IBM Cloud Pak System 2.3.3.6, 2.3.36 iFix1, 2.3.3.7, 2.3.3.7 iFix1, 2.3.4.0, 2.3.4.1, and 2.3.4.1 iFix1 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be exe...Show more |
A reflected cross-site scripting vulnerability via a specific parameter exists in SLNX Help Documentation of RICOH Streamline NX. If this vulnerability is exploited, an arbitrary script may be executed in the web browser...Show more |
1Code Projects 1Daily Expense Manager Jun 17, 2026 Jun 30, 2025 5.1 MEDIUM· v4 6.1 MEDIUM· v3 N/A· v2 Reflected Cross-Site Scripting (XSS) vulnerability in Daily Expense Manager v1.0. This vulnerability allows an attacker to execute JavaScript code by sending a POST request through the password and confirm_password param...Show more |
1Code Projects 1Daily Expense Manager Jun 17, 2026 Jun 30, 2025 5.1 MEDIUM· v4 6.1 MEDIUM· v3 N/A· v2 Reflected Cross-Site Scripting (XSS) vulnerability in Daily Expense Manager v1.0. This vulnerability allows an attacker to execute JavaScript code by sending a POST request through the username parameter in /login.php. |
The Contact Form Plugin WordPress plugin before 1.1.29 does not sanitise and escape some of its settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting attacks. |
The WP Lightbox 2 WordPress plugin before 3.0.6.8 does not correctly sanitize the value of the title attribute of links before using them, which may allow malicious users to conduct XSS attacks. |
A vulnerability, which was classified as problematic, was found in code-projects Simple Forum 1.0. Affected is an unknown function of the file /forum_edit1.php. The manipulation of the argument text leads to cross site s...Show more |
1Ieonly 1Ez Sql Reports Shortcode Widget And Db Backup Jun 17, 2026 Jun 29, 2025 N/A· v4 5.4 MEDIUM· v3 N/A· v2 The EZ SQL Reports Shortcode Widget and DB Backup plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's SQLREPORT shortcode in all versions up to, and including, 5.25.11 due to insufficient i...Show more |
1Qodeinteractive 1Qi Addons For Elementor Jun 17, 2026 Jun 28, 2025 N/A· v4 5.4 MEDIUM· v3 N/A· v2 The Qi Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in all versions up to, and including, 1.9.1 due to insufficient input sanitization and output escaping....Show more |