CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Description
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85
CVEs mapped to this weakness (46,817)
page 2023 of 2,341| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-66395 | Cri | 0.00 | 9.6 | 0.00 | Jul 27, 2026 | SiYuan desktop before v3.7.2 contains a reflected cross-site scripting vulnerability in the bazaar plugin readme handler that allows attackers to execute arbitrary code by crafting a malicious siyuan:// deep link. Attackers can inject HTML payloads via the plugin name parameter… | ||
| CVE-2026-66394 | Hig | 0.00 | 8.7 | 0.00 | Jul 27, 2026 | SiYuan before v3.7.3 contains stored and reflected cross-site scripting vulnerabilities in SVG sanitization that allows authenticated attackers to execute scripts by bypassing the HTML parser-based cleaner. Attackers can hide script tags within desc, style, or noscript elements… | ||
| CVE-2026-66475 | Med | 0.00 | 5.9 | 0.00 | Jul 27, 2026 | Shop manager Cross Site Scripting (XSS) in Checkout Field Editor for WooCommerce – Checkout Manager <= 3.0.5 versions. | ||
| CVE-2026-66448 | Med | 0.00 | 6.5 | 0.00 | Jul 27, 2026 | Contributor Cross Site Scripting (XSS) in Gallery PhotoBlocks <= 1.3.3 versions. | ||
| CVE-2026-66445 | Med | 0.00 | 6.5 | 0.00 | Jul 27, 2026 | Contributor Cross Site Scripting (XSS) in Open User Map <= 1.4.46 versions. | ||
| CVE-2026-66434 | Med | 0.00 | 6.5 | 0.00 | Jul 27, 2026 | Contributor Cross Site Scripting (XSS) in Photonic Gallery & Lightbox for Flickr, SmugMug & Others <= 3.33 versions. | ||
| CVE-2026-66433 | Med | 0.00 | 6.5 | 0.00 | Jul 27, 2026 | Contributor Cross Site Scripting (XSS) in Location Weather <= 3.0.6 versions. | ||
| CVE-2026-65563 | Med | 0.00 | 5.9 | 0.00 | Jul 27, 2026 | Author Cross Site Scripting (XSS) in Orbit Fox by ThemeIsle <= 3.0.7 versions. | ||
| CVE-2026-65562 | Med | 0.00 | 6.5 | 0.00 | Jul 27, 2026 | Contributor Cross Site Scripting (XSS) in BetterDocs <= 4.6.2 versions. | ||
| CVE-2026-65561 | Med | 0.00 | 6.5 | 0.00 | Jul 27, 2026 | Contributor Cross Site Scripting (XSS) in WordPress Social Login and Register <= 7.8.0 versions. | ||
| CVE-2026-65557 | Med | 0.00 | 5.9 | 0.00 | Jul 27, 2026 | Shop manager Cross Site Scripting (XSS) in Abandoned Cart Lite for WooCommerce <= 6.8.0 versions. | ||
| CVE-2026-59559 | Med | 0.00 | 6.5 | 0.00 | Jul 27, 2026 | Subscriber Cross Site Scripting (XSS) in RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg <= 1.5.1 versions. | ||
| CVE-2026-59558 | Hig | 0.00 | 7.1 | 0.00 | Jul 27, 2026 | Unauthenticated Cross Site Scripting (XSS) in Booking Calendar <= 11.4.2 versions. | ||
| CVE-2026-59556 | Hig | 0.00 | 7.1 | 0.00 | Jul 27, 2026 | Unauthenticated Cross Site Scripting (XSS) in Dynamic Pricing With Discount Rules for WooCommerce <= 4.5.11 versions. | ||
| CVE-2026-59553 | Hig | 0.00 | 7.1 | 0.00 | Jul 27, 2026 | Unauthenticated Cross Site Scripting (XSS) in Product Feed Manager <= 7.6.1 versions. | ||
| CVE-2026-14856 | Med | 0.00 | — | 0.00 | Jul 27, 2026 | A stored Cross-Site Scripting (XSS) vulnerability in the file upload functionality of the Media Manager in TastyIgniter v4.3.0, caused by insufficient validation and sanitization of SVG files. An authenticated user with low privileges can upload a malicious SVG file containing… | ||
| CVE-2026-65764 | Med | 0.00 | — | 0.00 | Jul 27, 2026 | Joomla Extension - phoca.cz - Reflected XSS vulnerability in Phoca Commander 5.0.0-6.1.1 - Improper validation of user inputs lead to a reflective XSS vulnerability. | ||
| CVE-2026-14827 | Med | 0.00 | 6.8 | 0.00 | Jul 27, 2026 | The Calendar WordPress plugin before 1.3.18 does not properly escape a user-supplied event field before outputting it inside an HTML attribute on a public-facing page, allowing users with the Contributor role to inject arbitrary JavaScript that executes in the browser of anyone… | ||
| CVE-2026-14203 | Med | 0.00 | 4.8 | 0.00 | Jul 27, 2026 | The Smart Manager WordPress plugin before 8.92.0 does not properly encode a post field before rendering it into an HTML attribute in its management grid, allowing users with the Contributor role or above to inject JavaScript that executes in the browser session of an… | ||
| CVE-2026-14190 | Med | 0.00 | 6.1 | 0.00 | Jul 27, 2026 | The Sina Extension for Elementor WordPress plugin before 3.10.2 does not escape a value reconstructed from request input in one of its unauthenticated AJAX handlers before reflecting it into the HTML response, allowing unauthenticated attackers to execute arbitrary JavaScript in… |
- risk 0.00cvss 9.6epss 0.00
SiYuan desktop before v3.7.2 contains a reflected cross-site scripting vulnerability in the bazaar plugin readme handler that allows attackers to execute arbitrary code by crafting a malicious siyuan:// deep link. Attackers can inject HTML payloads via the plugin name parameter…
- risk 0.00cvss 8.7epss 0.00
SiYuan before v3.7.3 contains stored and reflected cross-site scripting vulnerabilities in SVG sanitization that allows authenticated attackers to execute scripts by bypassing the HTML parser-based cleaner. Attackers can hide script tags within desc, style, or noscript elements…
- risk 0.00cvss 5.9epss 0.00
Shop manager Cross Site Scripting (XSS) in Checkout Field Editor for WooCommerce – Checkout Manager <= 3.0.5 versions.
- risk 0.00cvss 6.5epss 0.00
Contributor Cross Site Scripting (XSS) in Gallery PhotoBlocks <= 1.3.3 versions.
- risk 0.00cvss 6.5epss 0.00
Contributor Cross Site Scripting (XSS) in Open User Map <= 1.4.46 versions.
- risk 0.00cvss 6.5epss 0.00
Contributor Cross Site Scripting (XSS) in Photonic Gallery & Lightbox for Flickr, SmugMug & Others <= 3.33 versions.
- risk 0.00cvss 6.5epss 0.00
Contributor Cross Site Scripting (XSS) in Location Weather <= 3.0.6 versions.
- risk 0.00cvss 5.9epss 0.00
Author Cross Site Scripting (XSS) in Orbit Fox by ThemeIsle <= 3.0.7 versions.
- risk 0.00cvss 6.5epss 0.00
Contributor Cross Site Scripting (XSS) in BetterDocs <= 4.6.2 versions.
- risk 0.00cvss 6.5epss 0.00
Contributor Cross Site Scripting (XSS) in WordPress Social Login and Register <= 7.8.0 versions.
- risk 0.00cvss 5.9epss 0.00
Shop manager Cross Site Scripting (XSS) in Abandoned Cart Lite for WooCommerce <= 6.8.0 versions.
- risk 0.00cvss 6.5epss 0.00
Subscriber Cross Site Scripting (XSS) in RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg <= 1.5.1 versions.
- risk 0.00cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in Booking Calendar <= 11.4.2 versions.
- risk 0.00cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in Dynamic Pricing With Discount Rules for WooCommerce <= 4.5.11 versions.
- risk 0.00cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in Product Feed Manager <= 7.6.1 versions.
- risk 0.00cvss —epss 0.00
A stored Cross-Site Scripting (XSS) vulnerability in the file upload functionality of the Media Manager in TastyIgniter v4.3.0, caused by insufficient validation and sanitization of SVG files. An authenticated user with low privileges can upload a malicious SVG file containing…
- risk 0.00cvss —epss 0.00
Joomla Extension - phoca.cz - Reflected XSS vulnerability in Phoca Commander 5.0.0-6.1.1 - Improper validation of user inputs lead to a reflective XSS vulnerability.
- risk 0.00cvss 6.8epss 0.00
The Calendar WordPress plugin before 1.3.18 does not properly escape a user-supplied event field before outputting it inside an HTML attribute on a public-facing page, allowing users with the Contributor role to inject arbitrary JavaScript that executes in the browser of anyone…
- risk 0.00cvss 4.8epss 0.00
The Smart Manager WordPress plugin before 8.92.0 does not properly encode a post field before rendering it into an HTML attribute in its management grid, allowing users with the Contributor role or above to inject JavaScript that executes in the browser session of an…
- risk 0.00cvss 6.1epss 0.00
The Sina Extension for Elementor WordPress plugin before 3.10.2 does not escape a value reconstructed from request input in one of its unauthenticated AJAX handlers before reflecting it into the HTML response, allowing unauthenticated attackers to execute arbitrary JavaScript in…