VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (46,817)

page 2023 of 2,341
  • CVE-2026-66395CriJul 27, 2026
    risk 0.00cvss 9.6epss 0.00

    SiYuan desktop before v3.7.2 contains a reflected cross-site scripting vulnerability in the bazaar plugin readme handler that allows attackers to execute arbitrary code by crafting a malicious siyuan:// deep link. Attackers can inject HTML payloads via the plugin name parameter…

  • CVE-2026-66394HigJul 27, 2026
    risk 0.00cvss 8.7epss 0.00

    SiYuan before v3.7.3 contains stored and reflected cross-site scripting vulnerabilities in SVG sanitization that allows authenticated attackers to execute scripts by bypassing the HTML parser-based cleaner. Attackers can hide script tags within desc, style, or noscript elements…

  • CVE-2026-66475MedJul 27, 2026
    risk 0.00cvss 5.9epss 0.00

    Shop manager Cross Site Scripting (XSS) in Checkout Field Editor for WooCommerce – Checkout Manager <= 3.0.5 versions.

  • CVE-2026-66448MedJul 27, 2026
    risk 0.00cvss 6.5epss 0.00

    Contributor Cross Site Scripting (XSS) in Gallery PhotoBlocks <= 1.3.3 versions.

  • CVE-2026-66445MedJul 27, 2026
    risk 0.00cvss 6.5epss 0.00

    Contributor Cross Site Scripting (XSS) in Open User Map <= 1.4.46 versions.

  • CVE-2026-66434MedJul 27, 2026
    risk 0.00cvss 6.5epss 0.00

    Contributor Cross Site Scripting (XSS) in Photonic Gallery & Lightbox for Flickr, SmugMug & Others <= 3.33 versions.

  • CVE-2026-66433MedJul 27, 2026
    risk 0.00cvss 6.5epss 0.00

    Contributor Cross Site Scripting (XSS) in Location Weather <= 3.0.6 versions.

  • CVE-2026-65563MedJul 27, 2026
    risk 0.00cvss 5.9epss 0.00

    Author Cross Site Scripting (XSS) in Orbit Fox by ThemeIsle <= 3.0.7 versions.

  • CVE-2026-65562MedJul 27, 2026
    risk 0.00cvss 6.5epss 0.00

    Contributor Cross Site Scripting (XSS) in BetterDocs <= 4.6.2 versions.

  • CVE-2026-65561MedJul 27, 2026
    risk 0.00cvss 6.5epss 0.00

    Contributor Cross Site Scripting (XSS) in WordPress Social Login and Register <= 7.8.0 versions.

  • CVE-2026-65557MedJul 27, 2026
    risk 0.00cvss 5.9epss 0.00

    Shop manager Cross Site Scripting (XSS) in Abandoned Cart Lite for WooCommerce <= 6.8.0 versions.

  • CVE-2026-59559MedJul 27, 2026
    risk 0.00cvss 6.5epss 0.00

    Subscriber Cross Site Scripting (XSS) in RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg <= 1.5.1 versions.

  • CVE-2026-59558HigJul 27, 2026
    risk 0.00cvss 7.1epss 0.00

    Unauthenticated Cross Site Scripting (XSS) in Booking Calendar <= 11.4.2 versions.

  • CVE-2026-59556HigJul 27, 2026
    risk 0.00cvss 7.1epss 0.00

    Unauthenticated Cross Site Scripting (XSS) in Dynamic Pricing With Discount Rules for WooCommerce <= 4.5.11 versions.

  • CVE-2026-59553HigJul 27, 2026
    risk 0.00cvss 7.1epss 0.00

    Unauthenticated Cross Site Scripting (XSS) in Product Feed Manager <= 7.6.1 versions.

  • CVE-2026-14856MedJul 27, 2026
    risk 0.00cvss epss 0.00

    A stored Cross-Site Scripting (XSS) vulnerability in the file upload functionality of the Media Manager in TastyIgniter v4.3.0, caused by insufficient validation and sanitization of SVG files. An authenticated user with low privileges can upload a malicious SVG file containing…

  • CVE-2026-65764MedJul 27, 2026
    risk 0.00cvss epss 0.00

    Joomla Extension - phoca.cz - Reflected XSS vulnerability in Phoca Commander 5.0.0-6.1.1 - Improper validation of user inputs lead to a reflective XSS vulnerability.

  • CVE-2026-14827MedJul 27, 2026
    risk 0.00cvss 6.8epss 0.00

    The Calendar WordPress plugin before 1.3.18 does not properly escape a user-supplied event field before outputting it inside an HTML attribute on a public-facing page, allowing users with the Contributor role to inject arbitrary JavaScript that executes in the browser of anyone…

  • CVE-2026-14203MedJul 27, 2026
    risk 0.00cvss 4.8epss 0.00

    The Smart Manager WordPress plugin before 8.92.0 does not properly encode a post field before rendering it into an HTML attribute in its management grid, allowing users with the Contributor role or above to inject JavaScript that executes in the browser session of an…

  • CVE-2026-14190MedJul 27, 2026
    risk 0.00cvss 6.1epss 0.00

    The Sina Extension for Elementor WordPress plugin before 3.10.2 does not escape a value reconstructed from request input in one of its unauthenticated AJAX handlers before reflecting it into the HTML response, allowing unauthenticated attackers to execute arbitrary JavaScript in…