VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (46,817)

page 2043 of 2,341
  • CVE-2026-48950MedJul 7, 2026
    risk 0.00cvss 6.1epss 0.00

    Lack of escaping leads to an XSS vulnerability in the file management view of com_templates.

  • CVE-2026-48949MedJul 7, 2026
    risk 0.00cvss 6.1epss 0.00

    Lack of validation leads to an XSS vulnerability in the MFA management views.

  • CVE-2026-8309MedJul 7, 2026
    risk 0.00cvss 5.4epss 0.00

    Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Armiya Information Technologies Ltd. Co. Access Control System (GKS) allows Reflected XSS. This issue affects Access Control System (GKS): before Version 2.

  • CVE-2026-8306MedJul 7, 2026
    risk 0.00cvss 6.1epss 0.00

    Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Armiya Information Technologies Ltd. Co. Access Control System (GKS) allows Stored XSS. This issue affects Access Control System (GKS): before Version 2.

  • CVE-2026-11328MedJul 7, 2026
    risk 0.00cvss 6.4epss 0.00

    The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the post title parameter in all versions up to, and including, 2.7.9.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…

  • CVE-2026-53641MedJul 6, 2026
    risk 0.00cvss epss 0.00

    FOSSBilling is a free, open-source billing and client management system. Versions 0.6.0 through 0.7.2 have a stored cross-site scripting (XSS) vulnerability in the client-facing email history views of FOSSBilling. Email HTML content (`content_html`) is rendered into a JavaScript…

  • CVE-2026-12154MedJul 6, 2026
    risk 0.00cvss 6.4epss 0.00

    The Reviews Widgets for Google, Yelp & TripAdvisor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'page_id' shortcode attribute of the [fbrev] shortcode in versions up to and including 2.7.3. This is due to insufficient input sanitization and output…

  • CVE-2025-53831HigJul 6, 2026
    risk 0.00cvss 8.2epss 0.00

    DrawIO for ownCloud is an application for using DrawIO with the file storage, synchronization, and sharing application ownCloud Classic. In DrawIO for ownCloud prior to version 1.0.2, which corresponds to ownCloud 10 prior to version 10.15.3, attackers with access to the DrawIO…

  • CVE-2025-8591MedJul 6, 2026
    risk 0.00cvss 6.1epss 0.00

    The software accepts user-supplied input via a URL parameter without adequate output encoding before reflecting it back to the user's browser. This condition allows an attacker to inject malicious script content into pages served by the application. By leveraging this weakness,…

  • CVE-2026-14791LowJul 6, 2026
    risk 0.00cvss 3.5epss 0.00

    A weakness has been identified in crater-invoice-inc crater up to 6.0.6. This affects the function getFormattedString of the file app/Http/Requests/InvoicesRequest.php of the component Invoice Note Handler. Executing a manipulation of the argument notes can lead to cross site…

  • CVE-2026-14752LowJul 5, 2026
    risk 0.00cvss 3.5epss 0.00

    A security vulnerability has been detected in mjperpinosa stumasy up to 327d1b0f2915ba79d7ef8ebb74553e987609d9be. This affects the function add_definition of the file application/PHP/objects/notes/add_into_dictionary.php. Such manipulation of the argument reference leads to…

  • CVE-2026-14704MedJul 5, 2026
    risk 0.00cvss 4.3epss 0.00

    A vulnerability was found in stephen-kruger bluebox up to 4.5.12. Affected by this vulnerability is an unknown functionality. Performing a manipulation of the argument code results in cross site scripting. It is possible to initiate the attack remotely. The exploit has been made…

  • CVE-2026-14656MedJul 4, 2026
    risk 0.00cvss 4.3epss 0.00

    A security vulnerability has been detected in code-projects Assessment Management 1.0. This affects an unknown part of the file /admin/remove-user.php. The manipulation of the argument ID leads to cross site scripting. It is possible to initiate the attack remotely. The exploit…

  • CVE-2026-14655LowJul 4, 2026
    risk 0.00cvss 2.4epss 0.00

    A weakness has been identified in code-projects Assessment Management 1.0. Affected by this issue is some unknown functionality of the file admin/view-users.php. Executing a manipulation of the argument User can lead to cross site scripting. The attack may be performed from…

  • CVE-2026-58524MedJul 3, 2026
    risk 0.00cvss 5.4epss 0.00

    Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

  • CVE-2026-58298HigJul 3, 2026
    risk 0.00cvss 7.2epss 0.00

    Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

  • CVE-2026-57977HigJul 3, 2026
    risk 0.00cvss 7.1epss 0.01

    Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

  • CVE-2026-4322MedJul 3, 2026
    risk 0.00cvss 6.1epss 0.00

    Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Raera - Ankara Web Design and Digital Advertising Agency Destekz allows Reflected XSS. This issue affects Destekz: through 02062026. NOTE: The vendor was contacted and it was…

  • CVE-2026-9756MedJul 3, 2026
    risk 0.00cvss 6.4epss 0.00

    The GenerateBlocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Headline Block 'linkMetaFieldType' Dynamic Link Attribute in all versions up to, and including, 2.2.1 due to insufficient input sanitization and output escaping. This makes it possible for…

  • CVE-2026-4804MedJul 3, 2026
    risk 0.00cvss 6.4epss 0.00

    The Zakra theme for WordPress is vulnerable to Stored Cross-Site Scripting via post meta values in all versions up to, and including, 4.2.0. This is due to the theme registering three post meta fields (zakra_menu_item_color, zakra_menu_item_hover_color, and…