CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Description
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85
CVEs mapped to this weakness (46,817)
page 2022 of 2,341| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-14870 | Hig | 0.00 | 7.1 | 0.00 | Jul 28, 2026 | The Database for Contact Form 7, WPforms, Elementor forms WordPress plugin before 1.5.3 does not properly sanitise and escape a parameter before reflecting it back in an admin page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such… | ||
| CVE-2026-14819 | Low | 0.00 | 3.5 | 0.00 | Jul 28, 2026 | The Event Tickets and Registration WordPress plugin before 5.28.4 does not properly escape event titles before outputting them in a ticket history log, allowing users with the Editor role and above to perform Stored Cross-Site Scripting attacks that execute against… | ||
| CVE-2026-17528 | Med | 0.00 | 6.1 | 0.00 | Jul 28, 2026 | Versions of the package nice-select2 before 2.4.1 are vulnerable to Cross-site Scripting (XSS) via the element. An attacker can supply a malicious payload that is rendered directly into the DOM without proper sanitization, causing arbitrary script execution in a… | ||
| CVE-2026-65448 | Med | 0.00 | 6.5 | 0.00 | Jul 27, 2026 | Unauthenticated Cross Site Scripting (XSS) in Anti Spam and list cleaner – AcyChecker <= 1.8.1 versions. | ||
| CVE-2026-65447 | Hig | 0.00 | 7.1 | 0.00 | Jul 27, 2026 | Unauthenticated Cross Site Scripting (XSS) in Contest Gallery <= 30.0.6 versions. | ||
| CVE-2026-65446 | Hig | 0.00 | 7.1 | 0.00 | Jul 27, 2026 | Unauthenticated Cross Site Scripting (XSS) in Kali Forms <= 2.4.18 versions. | ||
| CVE-2026-65443 | Hig | 0.00 | 7.1 | 0.00 | Jul 27, 2026 | Unauthenticated Cross Site Scripting (XSS) in BackWPup <= 5.7.4 versions. | ||
| CVE-2026-65441 | Hig | 0.00 | 7.1 | 0.00 | Jul 27, 2026 | Unauthenticated Cross Site Scripting (XSS) in GiveWP <= 4.16.3 versions. | ||
| CVE-2026-65440 | Hig | 0.00 | 7.1 | 0.00 | Jul 27, 2026 | Unauthenticated Cross Site Scripting (XSS) in GetGenie <= 4.4.3 versions. | ||
| CVE-2026-65439 | Hig | 0.00 | 7.1 | 0.00 | Jul 27, 2026 | Unauthenticated Cross Site Scripting (XSS) in Ultimate Addons for Contact Form 7 <=3.5.45 versions. | ||
| CVE-2026-65438 | Hig | 0.00 | 7.1 | 0.00 | Jul 27, 2026 | Unauthenticated Cross Site Scripting (XSS) in Message Filter for Contact Form 7 <= 1.6.3.9 versions. | ||
| CVE-2026-65437 | Hig | 0.00 | 7.1 | 0.00 | Jul 27, 2026 | Unauthenticated Cross Site Scripting (XSS) in Spam protection, AntiSpam, FireWall by CleanTalk <= 6.82 versions. | ||
| CVE-2026-61957 | Hig | 0.00 | 7.1 | 0.00 | Jul 27, 2026 | Unauthenticated Cross Site Scripting (XSS) in miniorange otp verification <= 5.5.1 versions. | ||
| CVE-2026-51565 | Med | 0.00 | 6.1 | 0.00 | Jul 27, 2026 | Cross-site scripting (XSS) vulnerability in Modules/Docs/DocsController.php in Milk admin <=0.9.8 allows remote attackers to inject arbitrary web script or HTML via the action parameter in a crafted request | ||
| CVE-2026-66825 | Med | 0.00 | — | 0.00 | Jul 27, 2026 | Pivotick contains a cross-site scripting vulnerability in the sidebar property-list component. Values associated with link-like properties, such as url, uri, href, link, website, or homepage, were rendered as hyperlinks without validating their URL scheme. An attacker able to… | ||
| CVE-2026-66824 | Cri | 0.00 | — | 0.00 | Jul 27, 2026 | A stored cross-site scripting vulnerability existed in the capture tree visualization page. The application embedded the serialized capture tree directly into an inline JavaScript block using the Jinja safe filter. Because the tree data can contain values derived from captured… | ||
| CVE-2026-66031 | Med | 0.00 | 5.4 | 0.00 | Jul 27, 2026 | Ekushey Project Manager CRM through version 5.0 contains a stored cross-site scripting vulnerability that allows authenticated client users to inject arbitrary HTML and JavaScript by entering malicious payloads into the Reply Ticket field. Attackers can craft and store malicious… | ||
| CVE-2026-66030 | Med | 0.00 | 5.4 | 0.00 | Jul 27, 2026 | Ekushey Project Manager CRM through version 5.0 ccontains a stored cross-site scripting vulnerability that allows authenticated client users to inject arbitrary HTML and JavaScript by entering malicious payloads into the Ticket Title field on the Create New Ticket page.… | ||
| CVE-2026-66029 | Med | 0.00 | 5.4 | 0.00 | Jul 27, 2026 | Ekushey Project Manager CRM through version 5.0 contains a stored cross-site scripting vulnerability that allows authenticated client users to inject arbitrary HTML and JavaScript by entering malicious payloads into the client Name field on the Edit Profile page without… | ||
| CVE-2026-66396 | Hig | 0.00 | 8.4 | 0.00 | Jul 27, 2026 | SiYuan before v3.7.2 fails to escape the title-img Individual Attribute List value when rendering Gallery and Kanban cover images, allowing stored cross-site scripting via unescaped style attribute interpolation. Attackers with editor permissions can inject onload handlers that… |
- risk 0.00cvss 7.1epss 0.00
The Database for Contact Form 7, WPforms, Elementor forms WordPress plugin before 1.5.3 does not properly sanitise and escape a parameter before reflecting it back in an admin page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such…
- risk 0.00cvss 3.5epss 0.00
The Event Tickets and Registration WordPress plugin before 5.28.4 does not properly escape event titles before outputting them in a ticket history log, allowing users with the Editor role and above to perform Stored Cross-Site Scripting attacks that execute against…
- risk 0.00cvss 6.1epss 0.00
Versions of the package nice-select2 before 2.4.1 are vulnerable to Cross-site Scripting (XSS) via the element. An attacker can supply a malicious payload that is rendered directly into the DOM without proper sanitization, causing arbitrary script execution in a…
- risk 0.00cvss 6.5epss 0.00
Unauthenticated Cross Site Scripting (XSS) in Anti Spam and list cleaner – AcyChecker <= 1.8.1 versions.
- risk 0.00cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in Contest Gallery <= 30.0.6 versions.
- risk 0.00cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in Kali Forms <= 2.4.18 versions.
- risk 0.00cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in BackWPup <= 5.7.4 versions.
- risk 0.00cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in GiveWP <= 4.16.3 versions.
- risk 0.00cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in GetGenie <= 4.4.3 versions.
- risk 0.00cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in Ultimate Addons for Contact Form 7 <=3.5.45 versions.
- risk 0.00cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in Message Filter for Contact Form 7 <= 1.6.3.9 versions.
- risk 0.00cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in Spam protection, AntiSpam, FireWall by CleanTalk <= 6.82 versions.
- risk 0.00cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in miniorange otp verification <= 5.5.1 versions.
- risk 0.00cvss 6.1epss 0.00
Cross-site scripting (XSS) vulnerability in Modules/Docs/DocsController.php in Milk admin <=0.9.8 allows remote attackers to inject arbitrary web script or HTML via the action parameter in a crafted request
- risk 0.00cvss —epss 0.00
Pivotick contains a cross-site scripting vulnerability in the sidebar property-list component. Values associated with link-like properties, such as url, uri, href, link, website, or homepage, were rendered as hyperlinks without validating their URL scheme. An attacker able to…
- risk 0.00cvss —epss 0.00
A stored cross-site scripting vulnerability existed in the capture tree visualization page. The application embedded the serialized capture tree directly into an inline JavaScript block using the Jinja safe filter. Because the tree data can contain values derived from captured…
- risk 0.00cvss 5.4epss 0.00
Ekushey Project Manager CRM through version 5.0 contains a stored cross-site scripting vulnerability that allows authenticated client users to inject arbitrary HTML and JavaScript by entering malicious payloads into the Reply Ticket field. Attackers can craft and store malicious…
- risk 0.00cvss 5.4epss 0.00
Ekushey Project Manager CRM through version 5.0 ccontains a stored cross-site scripting vulnerability that allows authenticated client users to inject arbitrary HTML and JavaScript by entering malicious payloads into the Ticket Title field on the Create New Ticket page.…
- risk 0.00cvss 5.4epss 0.00
Ekushey Project Manager CRM through version 5.0 contains a stored cross-site scripting vulnerability that allows authenticated client users to inject arbitrary HTML and JavaScript by entering malicious payloads into the client Name field on the Edit Profile page without…
- risk 0.00cvss 8.4epss 0.00
SiYuan before v3.7.2 fails to escape the title-img Individual Attribute List value when rendering Gallery and Kanban cover images, allowing stored cross-site scripting via unescaped style attribute interpolation. Attackers with editor permissions can inject onload handlers that…