CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Description
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85
CVEs mapped to this weakness (46,608)
page 112 of 2,331| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2015-8256 | Med | 0.47 | 6.1 | 0.51 | Apr 17, 2017 | Multiple cross-site scripting (XSS) vulnerabilities in Axis network cameras. | ||
| CVE-2016-1000119 | Hig | 0.47 | 7.2 | 0.02 | Oct 21, 2016 | SQLi and XSS in Huge IT catalog extension v1.0.4 for Joomla | ||
| CVE-2016-1000118 | Hig | 0.47 | 7.2 | 0.02 | Oct 21, 2016 | XSS & SQLi in HugeIT slideshow v1.0.4 | ||
| CVE-2016-1000117 | Hig | 0.47 | 7.2 | 0.02 | Oct 21, 2016 | XSS & SQLi in HugeIT slideshow v1.0.4 | ||
| CVE-2016-1000116 | Hig | 0.47 | 7.2 | 0.02 | Oct 21, 2016 | Huge-IT Portfolio Gallery manager v1.1.0 SQL Injection and XSS | ||
| CVE-2016-1000115 | Hig | 0.47 | 7.2 | 0.03 | Oct 21, 2016 | Huge-IT Portfolio Gallery manager v1.1.0 SQL Injection and XSS | ||
| CVE-2026-81760 | Hig | 0.46 | 7.1 | 0.00 | Aug 28, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetEngine allows Reflected XSS. This issue affects JetEngine: from n/a through 3.8.14.2. | ||
| CVE-2026-78293 | Hig | 0.46 | 7.1 | 0.00 | Aug 27, 2026 | Unauthenticated Cross Site Scripting (XSS) in WP w3all phpBB <= 3.0.6 versions. | ||
| CVE-2026-78289 | Hig | 0.46 | 7.1 | 0.00 | Aug 27, 2026 | Unauthenticated Cross Site Scripting (XSS) in CozyStay <= 1.10.0 versions. | ||
| CVE-2026-78283 | Hig | 0.46 | 7.1 | 0.00 | Aug 27, 2026 | Unauthenticated Cross Site Scripting (XSS) in Music Player for WooCommerce <= 1.8.9 versions. | ||
| CVE-2026-78281 | Hig | 0.46 | 7.1 | 0.00 | Aug 27, 2026 | Unauthenticated Cross Site Scripting (XSS) in CP Media Player <= 1.3.0 versions. | ||
| CVE-2026-78261 | Hig | 0.46 | 7.1 | 0.00 | Aug 27, 2026 | Unauthenticated Cross Site Scripting (XSS) in Realtyna Organic IDX plugin <= 5.4.1 versions. | ||
| CVE-2026-32258 | Hig | 0.46 | 8.1 | 0.00 | Aug 26, 2026 | Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. From 1.2.10 through 1.2.12, authenticated backend users with the backend.manage_editor permission can store custom Markup Styles that are compiled by the LESS parser and rendered… | ||
| CVE-2026-32257 | Hig | 0.46 | 8.1 | 0.00 | Aug 26, 2026 | Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. Prior to 1.2.13, custom CSS supplied through the Brand Settings Styles field by a backend user with the backend.manage_branding permission is compiled by the LESS parser and… | ||
| CVE-2026-16231 | Hig | 0.46 | 8.1 | 0.00 | Aug 25, 2026 | hbs is an Express view engine that wraps Handlebars. Its registerAsyncHelper API bypasses Handlebars' automatic HTML escaping: an async helper returns an opaque placeholder during the first render pass, so the double-brace expression escapes only the placeholder, and after… | ||
| CVE-2026-78282 | Hig | 0.46 | 7.1 | 0.00 | Aug 24, 2026 | Unauthenticated Cross Site Scripting (XSS) in Stripe Payments <= 2.1.2 versions. | ||
| CVE-2026-78264 | Hig | 0.46 | 7.1 | 0.00 | Aug 24, 2026 | Unauthenticated Cross Site Scripting (XSS) in Toolset Blocks <= 1.6.26 versions. | ||
| CVE-2026-78263 | Hig | 0.46 | 7.1 | 0.00 | Aug 24, 2026 | Unauthenticated Cross Site Scripting (XSS) in Event Tickets <= 5.29.2.1 versions. | ||
| CVE-2026-32556 | Hig | 0.46 | 7.1 | 0.00 | Aug 24, 2026 | Unauthenticated Cross Site Scripting (XSS) in Boost <= 2.0.4 versions. | ||
| CVE-2026-66623 | Hig | 0.46 | 7.1 | 0.00 | Aug 24, 2026 | Unauthenticated Cross Site Scripting (XSS) in Social Media & Share Icons <= 2.9.9 versions. |
- risk 0.47cvss 6.1epss 0.51
Multiple cross-site scripting (XSS) vulnerabilities in Axis network cameras.
- risk 0.47cvss 7.2epss 0.02
SQLi and XSS in Huge IT catalog extension v1.0.4 for Joomla
- risk 0.47cvss 7.2epss 0.02
XSS & SQLi in HugeIT slideshow v1.0.4
- risk 0.47cvss 7.2epss 0.02
XSS & SQLi in HugeIT slideshow v1.0.4
- risk 0.47cvss 7.2epss 0.02
Huge-IT Portfolio Gallery manager v1.1.0 SQL Injection and XSS
- risk 0.47cvss 7.2epss 0.03
Huge-IT Portfolio Gallery manager v1.1.0 SQL Injection and XSS
- risk 0.46cvss 7.1epss 0.00
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetEngine allows Reflected XSS. This issue affects JetEngine: from n/a through 3.8.14.2.
- risk 0.46cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in WP w3all phpBB <= 3.0.6 versions.
- risk 0.46cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in CozyStay <= 1.10.0 versions.
- risk 0.46cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in Music Player for WooCommerce <= 1.8.9 versions.
- risk 0.46cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in CP Media Player <= 1.3.0 versions.
- risk 0.46cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in Realtyna Organic IDX plugin <= 5.4.1 versions.
- risk 0.46cvss 8.1epss 0.00
Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. From 1.2.10 through 1.2.12, authenticated backend users with the backend.manage_editor permission can store custom Markup Styles that are compiled by the LESS parser and rendered…
- risk 0.46cvss 8.1epss 0.00
Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. Prior to 1.2.13, custom CSS supplied through the Brand Settings Styles field by a backend user with the backend.manage_branding permission is compiled by the LESS parser and…
- risk 0.46cvss 8.1epss 0.00
hbs is an Express view engine that wraps Handlebars. Its registerAsyncHelper API bypasses Handlebars' automatic HTML escaping: an async helper returns an opaque placeholder during the first render pass, so the double-brace expression escapes only the placeholder, and after…
- risk 0.46cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in Stripe Payments <= 2.1.2 versions.
- risk 0.46cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in Toolset Blocks <= 1.6.26 versions.
- risk 0.46cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in Event Tickets <= 5.29.2.1 versions.
- risk 0.46cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in Boost <= 2.0.4 versions.
- risk 0.46cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in Social Media & Share Icons <= 2.9.9 versions.