VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (46,817)

page 2028 of 2,341
  • CVE-2026-57370HigJul 23, 2026
    risk 0.00cvss 7.1epss 0.00

    Unauthenticated Cross Site Scripting (XSS) in Visitor Traffic Real Time Statistics Pro <= 11.9.1 versions.

  • CVE-2026-27403MedJul 23, 2026
    risk 0.00cvss 6.5epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NerdPress Hubbub Lite allows Stored XSS. This issue affects Hubbub Lite: from n/a through 1.36.3.

  • CVE-2026-24628MedJul 23, 2026
    risk 0.00cvss 5.9epss 0.00

    Administrator Cross Site Scripting (XSS) in Photo Gallery by Supsystic <= 1.16.3 versions.

  • CVE-2025-68081MedJul 23, 2026
    risk 0.00cvss 5.9epss 0.00

    Administrator Cross Site Scripting (XSS) in WP-Polls <= 2.77.3 versions.

  • CVE-2026-65756MedJul 23, 2026
    risk 0.00cvss 6.1epss 0.00

    Joomla Extension - regularlabs.com - XSS vector in Keyboard Shortcuts extension - Shortcut configuration accepted arbitrary inline JavaScript.

  • CVE-2026-15794MedJul 23, 2026
    risk 0.00cvss 6.4epss 0.00

    The Grid/List View for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'position' Shortcode Attribute in all versions up to, and including, 3.0.9 due to insufficient input sanitization and output escaping. This makes it possible for…

  • CVE-2026-15647MedJul 23, 2026
    risk 0.00cvss 4.4epss 0.00

    The Brands for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'br_brand_tooltip' Term Meta Field in all versions up to, and including, 3.8.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…

  • CVE-2026-15646MedJul 23, 2026
    risk 0.00cvss 6.4epss 0.00

    The Brands for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'style' Shortcode Attribute in all versions up to, and including, 3.8.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…

  • CVE-2026-15404MedJul 23, 2026
    risk 0.00cvss 6.4epss 0.00

    The Lpagery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via post titles in versions up to, and including, 2.5.7. This is due to insufficient input sanitization and output escaping in the lpagery_add_filter_text_template_post() function, which is hooked to…

  • CVE-2026-15394MedJul 23, 2026
    risk 0.00cvss 6.4epss 0.00

    The Header Footer Script Adder – Insert Code in Header, Body & Footer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'asm_code' Snippet Meta in all versions up to, and including, 2.1 due to insufficient input sanitization and output escaping. This makes…

  • CVE-2026-14481MedJul 23, 2026
    risk 0.00cvss 6.4epss 0.00

    The Equalize Digital Accessibility Checker – WCAG, ADA, EAA and Section 508 compliance plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'html' parameter in all versions up to, and including, 1.46.0 due to insufficient input sanitization and output…

  • CVE-2026-9729MedJul 23, 2026
    risk 0.00cvss 6.4epss 0.00

    The Webpushr Push Notifications plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'webpushr_notification_title' and 'webpushr_notification_body' parameters in versions up to, and including, 4.39.0. This is due to insufficient input sanitization in the…

  • CVE-2026-9635MedJul 23, 2026
    risk 0.00cvss 6.4epss 0.00

    The WP Shortcode by MyThemeShop plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' parameter of the [tab] shortcode in versions up to, and including, 1.4.17. This is due to insufficient input sanitization and output escaping in the mts_tabs()…

  • CVE-2026-12421HigJul 23, 2026
    risk 0.00cvss 7.2epss 0.00

    The ARforms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'password' Field Values in all versions up to, and including, 7.2.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject…

  • CVE-2026-9577MedJul 23, 2026
    risk 0.00cvss 4.8epss 0.00

    The Post Status Notifier Lite WordPress plugin before 1.13.0 does not properly escape the `mod` URL parameter before reflecting it into the admin settings page (`admin.php?page=post-status-notifier-lite`), leading to a Reflected Cross-Site Scripting vulnerability that fires in…

  • CVE-2026-9066MedJul 23, 2026
    risk 0.00cvss 6.1epss 0.00

    The WP Compress WordPress plugin before 7.10.04 does not validate the value of a query parameter that controls the asset CDN host before using it to build the URLs of JavaScript files emitted on the page, leading to Reflected XSS. When a visitor follows a crafted link, the WP…

  • CVE-2026-7534HigJul 23, 2026
    risk 0.00cvss 7.2epss 0.00

    The SUMO Reward Points plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting via the REST API endpoint `/wp-json/wc-srp/v1/earning` in versions up to, and including, 32.7.0. This is due to the `user_has_cap` filter in the `SRP_REST_Earning_Controller`…

  • CVE-2026-7232HigJul 23, 2026
    risk 0.00cvss 7.2epss 0.00

    The FormCraft plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '[parameter name]' parameter in all versions up to, and including, 3.9.14 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to…

  • CVE-2026-64795MedJul 22, 2026
    risk 0.00cvss 5.4epss 0.00

    Joomla Extension - regularlabs.com - XSS vectors in tag-provided inputs in various Regular Labs extensions - Tag-provided custom HTML, module content/title overrides and decoded modal or tooltip values could execute unsafe markup. A content author could inject JavaScript that…

  • CVE-2026-63281MedJul 22, 2026
    risk 0.00cvss 4.8epss 0.00

    Joomla Extension - regularlabs.com - XSS vulnerability in Regular Labs conditions manager - Stored condition values could also execute HTML/JavaScript in administrator summaries.