VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (46,817)

page 2042 of 2,341
  • CVE-2026-8315MedJul 8, 2026
    risk 0.00cvss 5.4epss 0.00

    Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Webbeyaz Web Design Mediküm Web allows Stored XSS. This issue affects Mediküm Web: through 08072026. NOTE: The vendor was contacted and it was learned that the product is…

  • CVE-2026-8310MedJul 8, 2026
    risk 0.00cvss 6.1epss 0.00

    Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Webbeyaz Web Design Mediküm Web allows Reflected XSS. This issue affects Mediküm Web: through 08072026. NOTE: The vendor was contacted and it was learned that the product is…

  • CVE-2026-6820HigJul 8, 2026
    risk 0.00cvss 7.2epss 0.00

    The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'email' parameter in all versions up to, and including, 1.8.8 due to insufficient input sanitization and output escaping. This makes it possible for…

  • CVE-2026-6740MedJul 8, 2026
    risk 0.00cvss 6.4epss 0.00

    The Nexter Blocks – Gutenberg Blocks, Page Builder & AI Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'commentIcon' parameter in all versions up to, and including, 4.7.4 due to insufficient input sanitization and output escaping.…

  • CVE-2026-6459MedJul 8, 2026
    risk 0.00cvss 6.4epss 0.00

    The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Event Calendar widget in all versions up to, and including, 6.6.2 due to insufficient input sanitization and output escaping on…

  • CVE-2026-6818HigJul 8, 2026
    risk 0.00cvss 7.2epss 0.00

    The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'special_requests' parameter in all versions up to, and including, 1.8.8 due to insufficient input sanitization and output escaping. This makes it possible for…

  • CVE-2026-6742MedJul 8, 2026
    risk 0.00cvss 6.4epss 0.00

    The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'additional' parameter in all versions up to, and including, 2026.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…

  • CVE-2026-6371MedJul 8, 2026
    risk 0.00cvss 4.8epss 0.00

    Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Limatek System Inc. LimRAD NAC allows Stored XSS. This issue affects LimRAD NAC: before 5.5.7.3.9.

  • CVE-2026-12041MedJul 8, 2026
    risk 0.00cvss 4.4epss 0.00

    The Chatra Live Chat + ChatBot + Cart Saver plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.0.12 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…

  • CVE-2026-11798MedJul 8, 2026
    risk 0.00cvss 6.1epss 0.00

    The Social Share, Social Login and Social Comments Plugin – Super Socializer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'heateor_mastodon_share' parameter in all versions up to, and including, 7.14.5 due to insufficient input sanitization and…

  • CVE-2026-10570MedJul 8, 2026
    risk 0.00cvss 6.4epss 0.00

    The Sympl Repeater for ACF and Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ACF repeater field values in all versions up to, and including, 2.3. This is due to insufficient input sanitization and output escaping in the…

  • CVE-2026-55437MedJul 8, 2026
    risk 0.00cvss 5.4epss 0.00

    Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.17, 2.32.7, 2.33.8, and 2.34.2, the `AgentLogLine` dashboard component instantiated `ansi-to-html` without `escapeXML: true` and inserted the result via…

  • CVE-2026-36163MedJul 7, 2026
    risk 0.00cvss 5.4epss 0.00

    An HTML injection vulnerability in the file view endpoint of LiquidFiles v4.2.7 allows authenticated attackers to execute arbitrary JavaScript in the context of the victim's browser via the uploading of and user interaction with a crafted HTML file.

  • CVE-2026-36162MedJul 7, 2026
    risk 0.00cvss 5.4epss 0.00

    An authenticated stored cross-site scripting (XSS) vulnerability in the Upload File Shares API of LiquidFiles v4.2.7 allows attackers to execute arbitrary Javascript or HTML via injecting a crafted payload into the Name parameter.

  • CVE-2026-55647MedJul 7, 2026
    risk 0.00cvss epss 0.00

    DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, dashboard text components render stored component content with Vue v-html without server-side HTML sanitization, allowing an authenticated user who can edit dashboard component data to inject HTML…

  • CVE-2026-55592LowJul 7, 2026
    risk 0.00cvss 3.9epss 0.00

    Dashy is a self-hostable personal dashboard. Prior to 4.3.7, Dashy's workspace view trusts the url query parameter and assigns it directly to an iframe source without scheme validation. If a logged-in user opens a crafted workspace link containing a javascript: URL, JavaScript…

  • CVE-2026-48954MedJul 7, 2026
    risk 0.00cvss 6.1epss 0.00

    Improper validation leads to a generic XSS vector in the language override feature.

  • CVE-2026-48953MedJul 7, 2026
    risk 0.00cvss 6.1epss 0.00

    Lack of escaping leads to an XSS vulnerability in the generic image output layout.

  • CVE-2026-48952MedJul 7, 2026
    risk 0.00cvss 6.1epss 0.00

    Lack of escaping leads to an XSS vulnerability in the update list view of com_installer.

  • CVE-2026-48951MedJul 7, 2026
    risk 0.00cvss 6.1epss 0.00

    Lack of escaping leads to XSS vulnerabilities in modalreturn layouts of various components.