VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (46,817)

page 2022 of 2,341
  • CVE-2026-14870HigJul 28, 2026
    risk 0.00cvss 7.1epss 0.00

    The Database for Contact Form 7, WPforms, Elementor forms WordPress plugin before 1.5.3 does not properly sanitise and escape a parameter before reflecting it back in an admin page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such…

  • CVE-2026-14819LowJul 28, 2026
    risk 0.00cvss 3.5epss 0.00

    The Event Tickets and Registration WordPress plugin before 5.28.4 does not properly escape event titles before outputting them in a ticket history log, allowing users with the Editor role and above to perform Stored Cross-Site Scripting attacks that execute against…

  • CVE-2026-17528MedJul 28, 2026
    risk 0.00cvss 6.1epss 0.00

    Versions of the package nice-select2 before 2.4.1 are vulnerable to Cross-site Scripting (XSS) via the element. An attacker can supply a malicious payload that is rendered directly into the DOM without proper sanitization, causing arbitrary script execution in a…

  • CVE-2026-65448MedJul 27, 2026
    risk 0.00cvss 6.5epss 0.00

    Unauthenticated Cross Site Scripting (XSS) in Anti Spam and list cleaner – AcyChecker <= 1.8.1 versions.

  • CVE-2026-65447HigJul 27, 2026
    risk 0.00cvss 7.1epss 0.00

    Unauthenticated Cross Site Scripting (XSS) in Contest Gallery <= 30.0.6 versions.

  • CVE-2026-65446HigJul 27, 2026
    risk 0.00cvss 7.1epss 0.00

    Unauthenticated Cross Site Scripting (XSS) in Kali Forms <= 2.4.18 versions.

  • CVE-2026-65443HigJul 27, 2026
    risk 0.00cvss 7.1epss 0.00

    Unauthenticated Cross Site Scripting (XSS) in BackWPup <= 5.7.4 versions.

  • CVE-2026-65441HigJul 27, 2026
    risk 0.00cvss 7.1epss 0.00

    Unauthenticated Cross Site Scripting (XSS) in GiveWP <= 4.16.3 versions.

  • CVE-2026-65440HigJul 27, 2026
    risk 0.00cvss 7.1epss 0.00

    Unauthenticated Cross Site Scripting (XSS) in GetGenie <= 4.4.3 versions.

  • CVE-2026-65439HigJul 27, 2026
    risk 0.00cvss 7.1epss 0.00

    Unauthenticated Cross Site Scripting (XSS) in Ultimate Addons for Contact Form 7 <=3.5.45 versions.

  • CVE-2026-65438HigJul 27, 2026
    risk 0.00cvss 7.1epss 0.00

    Unauthenticated Cross Site Scripting (XSS) in Message Filter for Contact Form 7 <= 1.6.3.9 versions.

  • CVE-2026-65437HigJul 27, 2026
    risk 0.00cvss 7.1epss 0.00

    Unauthenticated Cross Site Scripting (XSS) in Spam protection, AntiSpam, FireWall by CleanTalk <= 6.82 versions.

  • CVE-2026-61957HigJul 27, 2026
    risk 0.00cvss 7.1epss 0.00

    Unauthenticated Cross Site Scripting (XSS) in miniorange otp verification <= 5.5.1 versions.

  • CVE-2026-51565MedJul 27, 2026
    risk 0.00cvss 6.1epss 0.00

    Cross-site scripting (XSS) vulnerability in Modules/Docs/DocsController.php in Milk admin <=0.9.8 allows remote attackers to inject arbitrary web script or HTML via the action parameter in a crafted request

  • CVE-2026-66825MedJul 27, 2026
    risk 0.00cvss epss 0.00

    Pivotick contains a cross-site scripting vulnerability in the sidebar property-list component. Values associated with link-like properties, such as url, uri, href, link, website, or homepage, were rendered as hyperlinks without validating their URL scheme. An attacker able to…

  • CVE-2026-66824CriJul 27, 2026
    risk 0.00cvss epss 0.00

    A stored cross-site scripting vulnerability existed in the capture tree visualization page. The application embedded the serialized capture tree directly into an inline JavaScript block using the Jinja safe filter. Because the tree data can contain values derived from captured…

  • CVE-2026-66031MedJul 27, 2026
    risk 0.00cvss 5.4epss 0.00

    Ekushey Project Manager CRM through version 5.0 contains a stored cross-site scripting vulnerability that allows authenticated client users to inject arbitrary HTML and JavaScript by entering malicious payloads into the Reply Ticket field. Attackers can craft and store malicious…

  • CVE-2026-66030MedJul 27, 2026
    risk 0.00cvss 5.4epss 0.00

    Ekushey Project Manager CRM through version 5.0 ccontains a stored cross-site scripting vulnerability that allows authenticated client users to inject arbitrary HTML and JavaScript by entering malicious payloads into the Ticket Title field on the Create New Ticket page.…

  • CVE-2026-66029MedJul 27, 2026
    risk 0.00cvss 5.4epss 0.00

    Ekushey Project Manager CRM through version 5.0 contains a stored cross-site scripting vulnerability that allows authenticated client users to inject arbitrary HTML and JavaScript by entering malicious payloads into the client Name field on the Edit Profile page without…

  • CVE-2026-66396HigJul 27, 2026
    risk 0.00cvss 8.4epss 0.00

    SiYuan before v3.7.2 fails to escape the title-img Individual Attribute List value when rendering Gallery and Kanban cover images, allowing stored cross-site scripting via unescaped style attribute interpolation. Attackers with editor permissions can inject onload handlers that…