VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (46,608)

page 118 of 2,331
  • CVE-2026-28177HigAug 6, 2026
    risk 0.46cvss 7.1epss 0.00

    Unauthenticated Cross Site Scripting (XSS) in Popup Maker <= 1.23.0 versions.

  • CVE-2026-28143HigAug 6, 2026
    risk 0.46cvss 7.1epss 0.00

    Unauthenticated Cross Site Scripting (XSS) in Forminator <= 1.56.0 versions.

  • CVE-2026-28141HigAug 6, 2026
    risk 0.46cvss 7.1epss 0.00

    Unauthenticated Cross Site Scripting (XSS) in NextGEN Gallery <= 4.2.3 versions.

  • CVE-2026-28082HigAug 6, 2026
    risk 0.46cvss 7.1epss 0.00

    Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.13.1 versions.

  • CVE-2026-70486HigAug 4, 2026
    risk 0.46cvss 8.2epss 0.00

    Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.0, the terminal file-preview serveUrl iframe branch always granted allow-same-origin together with allow-scripts for HTML files served from the application origin. Any…

  • CVE-2026-67328HigAug 1, 2026
    risk 0.46cvss 8.1epss 0.00

    @better-auth/sso versions before 1.6.21 contain multiple authentication bypass vulnerabilities in SSO provider handling that allow attackers to sign in as arbitrary users. Attackers can exploit domain verification parsing mismatches, orphaned provider accounts, unbound SAML…

  • CVE-2026-13725HigAug 1, 2026
    risk 0.46cvss 7.1epss 0.00

    The Dynamic Pricing With Discount Rules for WooCommerce WordPress plugin before 5.0.0 does not validate a nonce or user capabilities on one of its AJAX actions and reflects unsanitised user input in the response, allowing unauthenticated attackers to perform Reflected Cross-Site…

  • CVE-2026-56672HigJul 31, 2026
    risk 0.46cvss 8.2epss 0.00

    ComfyUI is a node-based diffusion model GUI, API, and backend. Prior to 0.28.0, GET /userdata/{file} served user-controlled HTML and SVG files with extension-derived content types, allowing stored cross-site scripting in the ComfyUI origin and access to browser-stored API…

  • CVE-2026-56670HigJul 31, 2026
    risk 0.46cvss 8.2epss 0.00

    ComfyUI is a modular diffusion model GUI, api and backend with a graph/nodes interface. Prior to 0.28.0, the /view endpoint served uploaded SVG files inline because image/svg+xml and related XML content types were absent from the dangerous-content-type handling, allowing stored…

  • CVE-2026-48060HigJul 28, 2026
    risk 0.46cvss 8.1epss 0.00

    Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. Prior to version 2.20.0, Litestar instances which use a template engine in conjunction with CSRF protection are vulnerable to HTML Injection which can be escalated to Cross Site Scripting due to the contents…

  • CVE-2026-47423HigJul 14, 2026
    risk 0.46cvss 8.2epss 0.00

    DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. In 3.4.4, DOMPurify allowed selectedcontent by default, allowing browsers to re-clone an XSS payload after sanitization so that unsanitized markup inside is returned. This issue…

  • CVE-2026-56785HigJun 23, 2026
    risk 0.46cvss 8.2epss 0.00

    FlatPress contains a stored cross-site scripting vulnerability in comment and contact forms where name, URL, and email fields are rendered without proper output encoding in Smarty templates. Attackers can inject arbitrary HTML and JavaScript through these fields to execute…

  • CVE-2026-50146HigJun 22, 2026
    risk 0.46cvss 7.1epss 0.00

    Astro is a web framework. Prior to 6.3.3, when a component uses a client:* directive, Astro inserts named slot content into a data-astro-template attribute without HTML escaping the slot name allowing an attacker to break out of the attribute context and inject arbitrary HTML,…

  • CVE-2026-6858HigJun 22, 2026
    risk 0.46cvss 7.1epss 0.00

    The Transbank Webpay WordPress plugin before 1.14.0 does not sanitize and escape logs to be displayed, allowing unauthenticated users to perform Stored XSS attacks against logged in administrator

  • CVE-2026-4259HigJun 22, 2026
    risk 0.46cvss 7.1epss 0.00

    The ultimate-woocommerce-auction-pro WordPress plugin through 2.4.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

  • CVE-2026-9570HigJun 17, 2026
    risk 0.46cvss 7.1epss 0.00

    The Taskbuilder WordPress plugin before 5.0.8 does not properly sanitise a URL parameter before echoing it into inline JavaScript on a frontend page containing one of its shortcodes, leading to a Reflected Cross-Site Scripting vulnerability that can be triggered against any…

  • CVE-2026-8089HigJun 17, 2026
    risk 0.46cvss 7.1epss 0.00

    The weMail: Email Marketing, Email Automation, Newsletters, Subscribers & Email Optins for WooCommerce WordPress plugin before 2.1.3 does not properly escape a user-supplied parameter before reflecting it into an HTML attribute on a non-nonce-protected AJAX response, allowing…

  • CVE-2026-54195HigJun 17, 2026
    risk 0.46cvss 7.1epss 0.00

    Unauthenticated Cross Site Scripting (XSS) in JetFormBuilder <= 3.6.0.1 versions.

  • CVE-2026-54192HigJun 17, 2026
    risk 0.46cvss 7.1epss 0.00

    Unauthenticated Cross Site Scripting (XSS) in Popup box <= 6.2.9 versions.

  • CVE-2026-54189HigJun 17, 2026
    risk 0.46cvss 7.1epss 0.00

    Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.10 versions.