VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (46,817)

page 2039 of 2,341
  • CVE-2026-54714MedJul 10, 2026
    risk 0.00cvss 6.1epss 0.00

    Logto is the modern, open-source auth infrastructure for SaaS and AI apps. Prior to 1.41.0, @logto/core reflected the SAML RelayState, SAMLResponse, and actionUrl into a Logto-origin auto-submit HTML form in packages/core/src/saml-application/SamlApplication/utils.ts without…

  • CVE-2026-56667HigJul 10, 2026
    risk 0.00cvss 7.3epss 0.00

    ZITADEL is an open source identity management platform. Prior to 4.15.3, ZITADEL Login V2 OIDC and SAML FailedPrecondition error paths return loginSettings.defaultRedirectUri to router.push without applying the isSafeRedirectUri check, allowing an organization or instance…

  • CVE-2026-3251MedJul 10, 2026
    risk 0.00cvss 6.4epss 0.00

    Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Webremium Istanbul Web Design Mezunum Satiyorum allows Stored XSS. This issue affects Mezunum Satiyorum: from 1.2.504 through 10072026. NOTE: The vendor was contacted early…

  • CVE-2026-61492LowJul 10, 2026
    risk 0.00cvss 3.5epss 0.01

    In JetBrains YouTrack before 2026.2.17394 stored XSS via article titles in digest emails was possible

  • CVE-2026-61456MedJul 10, 2026
    risk 0.00cvss 4.6epss 0.00

    The Grav API plugin (getgrav/grav-plugin-api) before 1.0.3 fails to sanitize SVG files uploaded through the POST /api/v1/media endpoint. The HandlesMediaUploads::processUploadedFile() method validates only the file extension and never invokes Security::sanitizeSVG(), so an…

  • CVE-2026-59795HigJul 10, 2026
    risk 0.00cvss 8.1epss 0.00

    In JetBrains TeamCity before 2026.1.2 stored XSS via unauthenticated agent registration was possible

  • CVE-2026-59794HigJul 10, 2026
    risk 0.00cvss 7.3epss 0.00

    In JetBrains TeamCity before 2026.1.2 stored XSS on the cloud profile page was possible via agent-reported data

  • CVE-2026-56354MedJul 10, 2026
    risk 0.00cvss 4.1epss 0.00

    n8n before 1.123.24, 2.10.4, and 2.12.0 (across its 1.x and 2.x branches) contains cross-site scripting and open redirect vulnerabilities in the Form Node due to unsanitized HTML description fields and overly permissive iframe sandbox policies. Authenticated users with workflow…

  • CVE-2026-29519HigJul 10, 2026
    risk 0.00cvss 8.2epss 0.00

    Lucee CFML Server versions across the 5.3.x, 6.1.x, 6.2.x, and 7.0.x release lines contain a reflected cross-site scripting vulnerability in URL path parsing that allows unauthenticated remote attackers to execute arbitrary JavaScript in a victim's browser by embedding HTML or…

  • CVE-2026-41877MedJul 10, 2026
    risk 0.00cvss epss 0.00

    R-SOFT DMS is vulnerable to Stored XSS in file upload functionality. Authenticated attacker can inject arbitrary HTML and JS into the name of the file being uploaded, which will be executed when visiting file list or upload status by other users. This issue was fixed in…

  • CVE-2026-13710MedJul 10, 2026
    risk 0.00cvss 6.4epss 0.00

    The Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Box widget's 'sg_body_description' parameter in versions up to, and including, 3.2.6. This is due to…

  • CVE-2026-13247MedJul 10, 2026
    risk 0.00cvss 6.4epss 0.00

    The Logo Slider – Logo Carousel, Client Logo Slider & Brand Showcase for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'lgx_tooltip_position' parameter in all versions up to, and including, 5.5 due to insufficient input sanitization and…

  • CVE-2026-9838MedJul 10, 2026
    risk 0.00cvss 6.1epss 0.01

    The ICS Calendar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'htmltagtitle' parameter in all versions up to, and including, 12.0.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to…

  • CVE-2026-3907MedJul 10, 2026
    risk 0.00cvss 6.4epss 0.00

    The Hostel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wphostel-book' shortcode in all versions up to and including 1.1.7. This is due to insufficient input sanitization and output escaping on user-supplied shortcode attributes. Specifically, the…

  • CVE-2026-12924MedJul 10, 2026
    risk 0.00cvss 6.4epss 0.00

    The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'etn_faq_content' parameter in all versions up to, and including, 4.1.15 due to insufficient input sanitization and output…

  • CVE-2026-12108MedJul 10, 2026
    risk 0.00cvss 4.4epss 0.00

    The Highlighting Code Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.2.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…

  • CVE-2026-15301MedJul 10, 2026
    risk 0.00cvss 6.4epss 0.00

    The BuddyHolis TableSearch plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘placeholder’ parameter in all versions up to, and including, 1.1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…

  • CVE-2026-15299MedJul 10, 2026
    risk 0.00cvss 6.4epss 0.00

    The Animation Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'weather_style' and 'move_direction' parameters of the Weather widget in all versions up to, and including, 2.6.3. This is due to insufficient output escaping in the…

  • CVE-2026-15298HigJul 10, 2026
    risk 0.00cvss 7.2epss 0.00

    The TelSender plugin for WordPress is vulnerable to DOM-Based Cross-Site Scripting in all versions up to, and including, 1.14.14. This is due to insufficient input sanitization when processing Telegram API responses containing attacker-controlled chat titles. This makes it…

  • CVE-2026-15297MedJul 10, 2026
    risk 0.00cvss 6.1epss 0.00

    The Newsletter, SMTP, Email marketing and Subscribe forms by Brevo (formely Sendinblue) plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the page parameter in all versions up to, and including, 3.1.77 due to insufficient input sanitization and output…