CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Description
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85
CVEs mapped to this weakness (46,608)
page 113 of 2,331| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-66610 | Hig | 0.46 | 7.1 | 0.00 | Aug 24, 2026 | Unauthenticated Cross Site Scripting (XSS) in Urna <= 2.6.2 versions. | ||
| CVE-2026-66599 | Hig | 0.46 | 7.1 | 0.00 | Aug 24, 2026 | Unauthenticated Cross Site Scripting (XSS) in WPComplete <= 2.9.5.6 versions. | ||
| CVE-2026-66584 | Hig | 0.46 | 7.1 | 0.00 | Aug 24, 2026 | Unauthenticated Cross Site Scripting (XSS) in 12 Step Meeting List <= 3.19.16 versions. | ||
| CVE-2026-32476 | Hig | 0.46 | 7.1 | 0.00 | Aug 24, 2026 | Unauthenticated Cross Site Scripting (XSS) in Brave Conversion Engine (PRO) <= 0.8.6 versions. | ||
| CVE-2026-28166 | Hig | 0.46 | 7.1 | 0.00 | Aug 24, 2026 | Unauthenticated Cross Site Scripting (XSS) in Tourmaster <= 5.4.9 versions. | ||
| CVE-2026-28162 | Hig | 0.46 | 7.1 | 0.00 | Aug 24, 2026 | Unauthenticated Cross Site Scripting (XSS) in Events Made Easy <= 3.2.5 versions. | ||
| CVE-2026-77115 | Hig | 0.46 | 7.1 | 0.00 | Aug 23, 2026 | Brave Popup Builder (brave-popup-builder) up to version 0.8.5 reflects UTM query parameters into popup form HTML without escaping them. | ||
| CVE-2026-63135 | Hig | 0.46 | 8.2 | 0.00 | Aug 21, 2026 | YOURLS is a self-hosted, customizable URL shortener written in PHP. From 1.5.1 until 1.10.4, YOURLS stores the HTTP Referer header through yourls_get_referrer(), yourls_sanitize_url_safe(), and yourls_log_redirect(), then aggregates the value in yourls-infos.php and passes the… | ||
| CVE-2026-61824 | Hig | 0.46 | 8.2 | 0.00 | Aug 21, 2026 | Defuddle cleans up HTML pages. Prior to 0.19.1, site extractors interpolate page-derived image alt and src values, og:image values, and video descriptions into HTML strings without context-appropriate escaping, and buildExtractorResponse() returns this contentHtml without the… | ||
| CVE-2026-54682 | Hig | 0.46 | 8.2 | 0.00 | Aug 21, 2026 | DiscordChatExporter saves Discord chat logs to a file. Prior to 2.47.2, HTML exports generated with markdown formatting disabled pass attacker-controlled content through FormatMarkdownAsync and FormatEmbedMarkdownAsync in DiscordChatExporter.Core/Exporting/MessageGroupTemplate.cs… | ||
| CVE-2026-49825 | Hig | 0.46 | 8.2 | 0.00 | Aug 20, 2026 | lxml is a library for processing XML and HTML in the Python language. Prior to 6.1.1, link attributes in ``lxml.html.defs.link_attrs`` were missing ``xlink:href``, which can be used for URL bypass attacks in embedded SVG/MathML/etc. content. This vulnerability was fixed in lxml… | ||
| CVE-2026-68564 | Hig | 0.46 | 7.1 | 0.00 | Aug 20, 2026 | Unauthenticated Cross Site Scripting (XSS) in NotificationX Pro <= 3.1.4 versions. | ||
| CVE-2026-66673 | Hig | 0.46 | 7.1 | 0.00 | Aug 20, 2026 | Unauthenticated Cross Site Scripting (XSS) in Flatastic <= 2.0 versions. | ||
| CVE-2026-66616 | Hig | 0.46 | 7.1 | 0.00 | Aug 20, 2026 | Unauthenticated Cross Site Scripting (XSS) in Form Maker by 10Web <= 1.15.46 versions. | ||
| CVE-2026-66614 | Hig | 0.46 | 7.1 | 0.00 | Aug 20, 2026 | Unauthenticated Cross Site Scripting (XSS) in SEO Plugin by Squirrly SEO <= 14.2.2 versions. | ||
| CVE-2026-66612 | Hig | 0.46 | 7.1 | 0.00 | Aug 20, 2026 | Unauthenticated Cross Site Scripting (XSS) in Aora <= 1.3.19 versions. | ||
| CVE-2026-66611 | Hig | 0.46 | 7.1 | 0.00 | Aug 20, 2026 | Unauthenticated Cross Site Scripting (XSS) in Paymob for WooCommerce <= 4.1.10 versions. | ||
| CVE-2026-66607 | Hig | 0.46 | 7.1 | 0.00 | Aug 20, 2026 | Unauthenticated Cross Site Scripting (XSS) in Advance Product Search <= 1.4.8 versions. | ||
| CVE-2026-66606 | Hig | 0.46 | 7.1 | 0.00 | Aug 20, 2026 | Unauthenticated Cross Site Scripting (XSS) in SmartSMTP <= 1.2.0 versions. | ||
| CVE-2026-66605 | Hig | 0.46 | 7.1 | 0.00 | Aug 20, 2026 | Unauthenticated Cross Site Scripting (XSS) in Swatchly – WooCommerce Variation Swatches for Products <= 1.4.13 versions. |
- risk 0.46cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in Urna <= 2.6.2 versions.
- risk 0.46cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in WPComplete <= 2.9.5.6 versions.
- risk 0.46cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in 12 Step Meeting List <= 3.19.16 versions.
- risk 0.46cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in Brave Conversion Engine (PRO) <= 0.8.6 versions.
- risk 0.46cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in Tourmaster <= 5.4.9 versions.
- risk 0.46cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in Events Made Easy <= 3.2.5 versions.
- risk 0.46cvss 7.1epss 0.00
Brave Popup Builder (brave-popup-builder) up to version 0.8.5 reflects UTM query parameters into popup form HTML without escaping them.
- risk 0.46cvss 8.2epss 0.00
YOURLS is a self-hosted, customizable URL shortener written in PHP. From 1.5.1 until 1.10.4, YOURLS stores the HTTP Referer header through yourls_get_referrer(), yourls_sanitize_url_safe(), and yourls_log_redirect(), then aggregates the value in yourls-infos.php and passes the…
- risk 0.46cvss 8.2epss 0.00
Defuddle cleans up HTML pages. Prior to 0.19.1, site extractors interpolate page-derived image alt and src values, og:image values, and video descriptions into HTML strings without context-appropriate escaping, and buildExtractorResponse() returns this contentHtml without the…
- risk 0.46cvss 8.2epss 0.00
DiscordChatExporter saves Discord chat logs to a file. Prior to 2.47.2, HTML exports generated with markdown formatting disabled pass attacker-controlled content through FormatMarkdownAsync and FormatEmbedMarkdownAsync in DiscordChatExporter.Core/Exporting/MessageGroupTemplate.cs…
- risk 0.46cvss 8.2epss 0.00
lxml is a library for processing XML and HTML in the Python language. Prior to 6.1.1, link attributes in ``lxml.html.defs.link_attrs`` were missing ``xlink:href``, which can be used for URL bypass attacks in embedded SVG/MathML/etc. content. This vulnerability was fixed in lxml…
- risk 0.46cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in NotificationX Pro <= 3.1.4 versions.
- risk 0.46cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in Flatastic <= 2.0 versions.
- risk 0.46cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in Form Maker by 10Web <= 1.15.46 versions.
- risk 0.46cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in SEO Plugin by Squirrly SEO <= 14.2.2 versions.
- risk 0.46cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in Aora <= 1.3.19 versions.
- risk 0.46cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in Paymob for WooCommerce <= 4.1.10 versions.
- risk 0.46cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in Advance Product Search <= 1.4.8 versions.
- risk 0.46cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in SmartSMTP <= 1.2.0 versions.
- risk 0.46cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in Swatchly – WooCommerce Variation Swatches for Products <= 1.4.13 versions.