VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (46,817)

page 2020 of 2,341
  • CVE-2025-65342MedJul 30, 2026
    risk 0.00cvss 6.1epss 0.00

    code-projects Blood System 1.0 is vulnerable to Cross Site Scripting (XSS) in /don.php via the city field.

  • CVE-2025-65341MedJul 30, 2026
    risk 0.00cvss 6.1epss 0.00

    Ecommerce Fruits Bazar 1.0 is vulnerable to Cross Site Scripting (XSS) in admin/edit_product.php.

  • CVE-2025-51684MedJul 30, 2026
    risk 0.00cvss 6.1epss 0.00

    CleverTap Web SDK v1.15.1 is vulnerable to Cross Site Scripting (XSS). The application does not sanitize untrusted data received via window.postMessage before injecting it into the page DOM. An attacker can craft a malicious message that, when processed by renderCustomHtml,…

  • CVE-2026-18361HigJul 30, 2026
    risk 0.00cvss 7.6epss 0.00

    The IRIS web application in version 2.4.26 and possibly others is vulnerable to stored cross-site scripting (XSS) in the datastore upload function.

  • CVE-2026-18360HigJul 30, 2026
    risk 0.00cvss 7.6epss 0.00

    The IRIS web application in version 2.4.26 and possibly others is vulnerable to stored cross-site scripting (XSS) in the custom attributes function.

  • CVE-2026-16969HigJul 30, 2026
    risk 0.00cvss 7.6epss 0.00

    The IRIS web application in version 2.4.26 and possibly others is vulnerable to stored cross-site scripting (XSS) in the assets function.

  • CVE-2026-59328MedJul 30, 2026
    risk 0.00cvss 4.2epss 0.00

    Spring Tools for Eclipse renders Spring Boot starter wizard dependency tooltips in a native embedded browser (SWT Browser) with JavaScript enabled. Using untrusted and compromised Initializr endpoints for the Spring Boot starter wizard can result in arbitrary script execution…

  • CVE-2026-14592MedJul 30, 2026
    risk 0.00cvss 6.1epss 0.00

    The WP Real IP-based Access Control WordPress plugin through 1.3.1 does not perform any capability or nonce checks before storing one of its option values, and does not escape that value on output on its settings page, allowing unauthenticated users to store arbitrary JavaScript…

  • CVE-2026-14318MedJul 30, 2026
    risk 0.00cvss 6.8epss 0.00

    The GiveWP WordPress plugin before 4.16.3 does not escape a donation-form template setting before outputting it in an HTML attribute, allowing users with the GiveWP Worker role and above to inject arbitrary web scripts that execute on the public donation form viewed by any…

  • CVE-2026-14239HigJul 30, 2026
    risk 0.00cvss 7.1epss 0.00

    The tourmaster WordPress plugin before 5.4.8 does not perform a nonce check when storing a custom-filter label taken from a request parameter, and does not escape that label when echoing it on the filter admin page, allowing an unauthenticated attacker to trick a logged-in…

  • CVE-2026-14207MedJul 30, 2026
    risk 0.00cvss 6.1epss 0.00

    The LifterLMS WordPress plugin before 10.0.10 does not strip event-handler attributes from a course pricing field before storing and rendering it, allowing users with a course-editing role to inject JavaScript that executes in the session of an administrator who views the…

  • CVE-2026-13344MedJul 30, 2026
    risk 0.00cvss 4.8epss 0.00

    The Essential Addons for Elementor WordPress plugin before 6.6.10 does not validate the HTML tag name of the Pricing Table widget title before outputting it, allowing users with Contributor-level access and above to inject JavaScript that will be executed (Stored Cross-Site…

  • CVE-2026-13330MedJul 30, 2026
    risk 0.00cvss 6.1epss 0.00

    The Animation Addons for Elementor WordPress plugin before 2.7.0 does not sanitise uploaded SVG/SVGZ files, which it adds to the list of allowed upload types, allowing users with the upload_files capability (Author and above) to upload files containing malicious JavaScript,…

  • CVE-2026-11881MedJul 30, 2026
    risk 0.00cvss 6.1epss 0.00

    The Fluent Forms WordPress plugin before 6.2.6 does not sanitise and escape one of its form field configuration settings before outputting it inside an inline script when a form is rendered, which could allow users with a role as low as Contributor (with delegated…

  • CVE-2025-65337MedJul 29, 2026
    risk 0.00cvss 6.1epss 0.00

    Sourcecodester Fantastic Blog CMS 1.0 is vulnerable to Cross Site Scripting (XSS) in pageEditMember.php via the address field.

  • CVE-2026-3093MedJul 29, 2026
    risk 0.00cvss 4.7epss 0.00

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 14.0 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an attacker to execute arbitrary JavaScript in another user's browser via a crafted URL, due…

  • CVE-2026-8791MedJul 29, 2026
    risk 0.00cvss 6.4epss 0.00

    The Booking System Trafft plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `bookingWebsiteUrl` setting in all versions up to, and including, 1.0.17 due to a missing capability check on the `set_options` AJAX action when the plugin is operating in agency…

  • CVE-2026-7436MedJul 29, 2026
    risk 0.00cvss 6.4epss 0.00

    The WPC Badge Management for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'text' attribute of the `wpcbm_best_seller` shortcode in all versions up to, and including, 3.1.6 due to insufficient input sanitization and output escaping on user…

  • CVE-2026-16655HigJul 29, 2026
    risk 0.00cvss 7.2epss 0.00

    The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Name Field Nested `password` Member in all versions up to, and including, 6.2.7 due to insufficient input…

  • CVE-2026-16597HigJul 29, 2026
    risk 0.00cvss 7.2epss 0.00

    The GTM4WP – A Google Tag Manager (GTM) plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via WooCommerce Billing Fields in all versions up to, and including, 1.22.3 due to insufficient input sanitization and output escaping. This makes it…