CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Description
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85
CVEs mapped to this weakness (46,608)
page 118 of 2,331| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-28177 | Hig | 0.46 | 7.1 | 0.00 | Aug 6, 2026 | Unauthenticated Cross Site Scripting (XSS) in Popup Maker <= 1.23.0 versions. | ||
| CVE-2026-28143 | Hig | 0.46 | 7.1 | 0.00 | Aug 6, 2026 | Unauthenticated Cross Site Scripting (XSS) in Forminator <= 1.56.0 versions. | ||
| CVE-2026-28141 | Hig | 0.46 | 7.1 | 0.00 | Aug 6, 2026 | Unauthenticated Cross Site Scripting (XSS) in NextGEN Gallery <= 4.2.3 versions. | ||
| CVE-2026-28082 | Hig | 0.46 | 7.1 | 0.00 | Aug 6, 2026 | Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.13.1 versions. | ||
| CVE-2026-70486 | Hig | 0.46 | 8.2 | 0.00 | Aug 4, 2026 | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.0, the terminal file-preview serveUrl iframe branch always granted allow-same-origin together with allow-scripts for HTML files served from the application origin. Any… | ||
| CVE-2026-67328 | Hig | 0.46 | 8.1 | 0.00 | Aug 1, 2026 | @better-auth/sso versions before 1.6.21 contain multiple authentication bypass vulnerabilities in SSO provider handling that allow attackers to sign in as arbitrary users. Attackers can exploit domain verification parsing mismatches, orphaned provider accounts, unbound SAML… | ||
| CVE-2026-13725 | Hig | 0.46 | 7.1 | 0.00 | Aug 1, 2026 | The Dynamic Pricing With Discount Rules for WooCommerce WordPress plugin before 5.0.0 does not validate a nonce or user capabilities on one of its AJAX actions and reflects unsanitised user input in the response, allowing unauthenticated attackers to perform Reflected Cross-Site… | ||
| CVE-2026-56672 | Hig | 0.46 | 8.2 | 0.00 | Jul 31, 2026 | ComfyUI is a node-based diffusion model GUI, API, and backend. Prior to 0.28.0, GET /userdata/{file} served user-controlled HTML and SVG files with extension-derived content types, allowing stored cross-site scripting in the ComfyUI origin and access to browser-stored API… | ||
| CVE-2026-56670 | Hig | 0.46 | 8.2 | 0.00 | Jul 31, 2026 | ComfyUI is a modular diffusion model GUI, api and backend with a graph/nodes interface. Prior to 0.28.0, the /view endpoint served uploaded SVG files inline because image/svg+xml and related XML content types were absent from the dangerous-content-type handling, allowing stored… | ||
| CVE-2026-48060 | Hig | 0.46 | 8.1 | 0.00 | Jul 28, 2026 | Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. Prior to version 2.20.0, Litestar instances which use a template engine in conjunction with CSRF protection are vulnerable to HTML Injection which can be escalated to Cross Site Scripting due to the contents… | ||
| CVE-2026-47423 | Hig | 0.46 | 8.2 | 0.00 | Jul 14, 2026 | DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. In 3.4.4, DOMPurify allowed selectedcontent by default, allowing browsers to re-clone an XSS payload after sanitization so that unsanitized markup inside is returned. This issue… | ||
| CVE-2026-56785 | Hig | 0.46 | 8.2 | 0.00 | Jun 23, 2026 | FlatPress contains a stored cross-site scripting vulnerability in comment and contact forms where name, URL, and email fields are rendered without proper output encoding in Smarty templates. Attackers can inject arbitrary HTML and JavaScript through these fields to execute… | ||
| CVE-2026-50146 | Hig | 0.46 | 7.1 | 0.00 | Jun 22, 2026 | Astro is a web framework. Prior to 6.3.3, when a component uses a client:* directive, Astro inserts named slot content into a data-astro-template attribute without HTML escaping the slot name allowing an attacker to break out of the attribute context and inject arbitrary HTML,… | ||
| CVE-2026-6858 | Hig | 0.46 | 7.1 | 0.00 | Jun 22, 2026 | The Transbank Webpay WordPress plugin before 1.14.0 does not sanitize and escape logs to be displayed, allowing unauthenticated users to perform Stored XSS attacks against logged in administrator | ||
| CVE-2026-4259 | Hig | 0.46 | 7.1 | 0.00 | Jun 22, 2026 | The ultimate-woocommerce-auction-pro WordPress plugin through 2.4.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin | ||
| CVE-2026-9570 | Hig | 0.46 | 7.1 | 0.00 | Jun 17, 2026 | The Taskbuilder WordPress plugin before 5.0.8 does not properly sanitise a URL parameter before echoing it into inline JavaScript on a frontend page containing one of its shortcodes, leading to a Reflected Cross-Site Scripting vulnerability that can be triggered against any… | ||
| CVE-2026-8089 | Hig | 0.46 | 7.1 | 0.00 | Jun 17, 2026 | The weMail: Email Marketing, Email Automation, Newsletters, Subscribers & Email Optins for WooCommerce WordPress plugin before 2.1.3 does not properly escape a user-supplied parameter before reflecting it into an HTML attribute on a non-nonce-protected AJAX response, allowing… | ||
| CVE-2026-54195 | Hig | 0.46 | 7.1 | 0.00 | Jun 17, 2026 | Unauthenticated Cross Site Scripting (XSS) in JetFormBuilder <= 3.6.0.1 versions. | ||
| CVE-2026-54192 | Hig | 0.46 | 7.1 | 0.00 | Jun 17, 2026 | Unauthenticated Cross Site Scripting (XSS) in Popup box <= 6.2.9 versions. | ||
| CVE-2026-54189 | Hig | 0.46 | 7.1 | 0.00 | Jun 17, 2026 | Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.10 versions. |
- risk 0.46cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in Popup Maker <= 1.23.0 versions.
- risk 0.46cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in Forminator <= 1.56.0 versions.
- risk 0.46cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in NextGEN Gallery <= 4.2.3 versions.
- risk 0.46cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.13.1 versions.
- risk 0.46cvss 8.2epss 0.00
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.0, the terminal file-preview serveUrl iframe branch always granted allow-same-origin together with allow-scripts for HTML files served from the application origin. Any…
- risk 0.46cvss 8.1epss 0.00
@better-auth/sso versions before 1.6.21 contain multiple authentication bypass vulnerabilities in SSO provider handling that allow attackers to sign in as arbitrary users. Attackers can exploit domain verification parsing mismatches, orphaned provider accounts, unbound SAML…
- risk 0.46cvss 7.1epss 0.00
The Dynamic Pricing With Discount Rules for WooCommerce WordPress plugin before 5.0.0 does not validate a nonce or user capabilities on one of its AJAX actions and reflects unsanitised user input in the response, allowing unauthenticated attackers to perform Reflected Cross-Site…
- risk 0.46cvss 8.2epss 0.00
ComfyUI is a node-based diffusion model GUI, API, and backend. Prior to 0.28.0, GET /userdata/{file} served user-controlled HTML and SVG files with extension-derived content types, allowing stored cross-site scripting in the ComfyUI origin and access to browser-stored API…
- risk 0.46cvss 8.2epss 0.00
ComfyUI is a modular diffusion model GUI, api and backend with a graph/nodes interface. Prior to 0.28.0, the /view endpoint served uploaded SVG files inline because image/svg+xml and related XML content types were absent from the dangerous-content-type handling, allowing stored…
- risk 0.46cvss 8.1epss 0.00
Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. Prior to version 2.20.0, Litestar instances which use a template engine in conjunction with CSRF protection are vulnerable to HTML Injection which can be escalated to Cross Site Scripting due to the contents…
- risk 0.46cvss 8.2epss 0.00
DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. In 3.4.4, DOMPurify allowed selectedcontent by default, allowing browsers to re-clone an XSS payload after sanitization so that unsanitized markup inside is returned. This issue…
- risk 0.46cvss 8.2epss 0.00
FlatPress contains a stored cross-site scripting vulnerability in comment and contact forms where name, URL, and email fields are rendered without proper output encoding in Smarty templates. Attackers can inject arbitrary HTML and JavaScript through these fields to execute…
- risk 0.46cvss 7.1epss 0.00
Astro is a web framework. Prior to 6.3.3, when a component uses a client:* directive, Astro inserts named slot content into a data-astro-template attribute without HTML escaping the slot name allowing an attacker to break out of the attribute context and inject arbitrary HTML,…
- risk 0.46cvss 7.1epss 0.00
The Transbank Webpay WordPress plugin before 1.14.0 does not sanitize and escape logs to be displayed, allowing unauthenticated users to perform Stored XSS attacks against logged in administrator
- risk 0.46cvss 7.1epss 0.00
The ultimate-woocommerce-auction-pro WordPress plugin through 2.4.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
- risk 0.46cvss 7.1epss 0.00
The Taskbuilder WordPress plugin before 5.0.8 does not properly sanitise a URL parameter before echoing it into inline JavaScript on a frontend page containing one of its shortcodes, leading to a Reflected Cross-Site Scripting vulnerability that can be triggered against any…
- risk 0.46cvss 7.1epss 0.00
The weMail: Email Marketing, Email Automation, Newsletters, Subscribers & Email Optins for WooCommerce WordPress plugin before 2.1.3 does not properly escape a user-supplied parameter before reflecting it into an HTML attribute on a non-nonce-protected AJAX response, allowing…
- risk 0.46cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in JetFormBuilder <= 3.6.0.1 versions.
- risk 0.46cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in Popup box <= 6.2.9 versions.
- risk 0.46cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.10 versions.