CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Description
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85
CVEs mapped to this weakness (46,817)
page 2044 of 2,341| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-9148 | Hig | 0.00 | 7.2 | 0.01 | Jul 3, 2026 | The Comments – wpDiscuz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the guest commenter 'Website' field in versions up to, and including, 7.6.56 This is due to insufficient output escaping in the getCommentAuthor() function, which interpolates the… | ||
| CVE-2026-8351 | Med | 0.00 | 6.4 | 0.00 | Jul 3, 2026 | The RTMKit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Advanced Heading widget's 'Background Text' parameter in versions up to, and including, 2.0.7 This is due to insufficient output escaping on the 'background_text_heading' setting in the render()… | ||
| CVE-2026-9626 | Med | 0.00 | 6.4 | 0.00 | Jul 3, 2026 | The JSON API User plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'content' parameter of the post_comment API endpoint in versions up to, and including, 4.1.0 This is due to insufficient input sanitization in the post_comment() function, which passes… | ||
| CVE-2026-8892 | Med | 0.00 | 6.4 | 0.00 | Jul 3, 2026 | The CM Business Directory – Optimise and showcase local business plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Business Address Meta Fields in all versions up to, and including, 1.5.7 due to insufficient input sanitization and output escaping. This… | ||
| CVE-2026-8489 | Med | 0.00 | 6.4 | 0.00 | Jul 3, 2026 | The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'about_me' parameter in all versions up to, and including, 2.11.4 due to insufficient… | ||
| CVE-2026-13040 | Hig | 0.00 | 7.2 | 0.01 | Jul 3, 2026 | The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'real_val__' parameter in all versions up to, and including, 9.2.2 due to insufficient input sanitization and output escaping. This makes it possible… | ||
| CVE-2026-12734 | Med | 0.00 | 6.4 | 0.00 | Jul 3, 2026 | The weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'connectorWidth' Block Attribute in all versions up to, and including, 2.3.0 due to insufficient input sanitization and output… | ||
| CVE-2026-12731 | Med | 0.00 | 6.4 | 0.00 | Jul 3, 2026 | The weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'sectionTitleTag' and 'articleTitleTag' Block Attributes in all versions up to, and including, 2.3.0 due to insufficient input… | ||
| CVE-2026-59102 | Med | 0.00 | 5.4 | 0.00 | Jul 2, 2026 | Forgejo before 15.0.3 contains a stored cross-site scripting vulnerability that allows authenticated attackers to execute arbitrary JavaScript in other users' browsers by setting a full name containing an HTML payload and triggering an Actions run. When the… | ||
| CVE-2026-58579 | Med | 0.00 | 5.4 | 0.00 | Jul 2, 2026 | RAGFlow before 0.26.3 stores an agent pipeline (DSL) node name without sanitization: the agent update endpoint normalizes the submitted DSL via normalize_dsl, which only performs JSON serialization validation and preserves the node name verbatim. The dataflow-result web UI then… | ||
| CVE-2026-8699 | Hig | 0.00 | — | 0.00 | Jul 2, 2026 | A stored Cross-Site Scripting (XSS) vulnerability has been identified in the web-based management interface of Archer C5 v6.8 routers, due to insufficient server-side validation and lack of proper output encoding of user-controlled input in a certain field. An attacker with… | ||
| CVE-2026-4772 | Med | 0.00 | 5.4 | 0.00 | Jul 2, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in TR7 Cyber Defense Inc. WAF-ASP allows Stored XSS. This issue affects WAF-ASP: from v1.0.324.900 before v1.4.0.117. | ||
| CVE-2026-4770 | Med | 0.00 | 4.6 | 0.00 | Jul 2, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in TR7 Cyber Defense Inc. Web Application Firewall allows DOM-Based XSS. This issue affects Web Application Firewall: from v1.0.42.239 before v1.4.0.117. | ||
| CVE-2026-57764 | Med | 0.00 | 6.5 | 0.00 | Jul 2, 2026 | Contributor Cross Site Scripting (XSS) in Surbma | Yoast SEO Breadcrumb Shortcode <= 1.2 versions. | ||
| CVE-2026-57763 | Med | 0.00 | 6.5 | 0.00 | Jul 2, 2026 | Contributor Cross Site Scripting (XSS) in Structured Content <= 1.7.0 versions. | ||
| CVE-2026-57762 | Med | 0.00 | 5.9 | 0.00 | Jul 2, 2026 | Author Cross Site Scripting (XSS) in Simple URLs <= 151 versions. | ||
| CVE-2026-57755 | Med | 0.00 | 6.5 | 0.00 | Jul 2, 2026 | Contributor Cross Site Scripting (XSS) in Mosaic Gallery – Advanced Gallery <= 1.2.0 versions. | ||
| CVE-2026-57754 | Med | 0.00 | 6.5 | 0.00 | Jul 2, 2026 | Contributor Cross Site Scripting (XSS) in Livemesh Addons for WPBakery Page Builder <= 3.9.4 versions. | ||
| CVE-2026-57686 | Hig | 0.00 | 7.1 | 0.00 | Jul 2, 2026 | Unauthenticated Cross Site Scripting (XSS) in WowAddons <= 1.6.14 versions. | ||
| CVE-2026-57684 | Med | 0.00 | 6.5 | 0.00 | Jul 2, 2026 | Contributor Cross Site Scripting (XSS) in TheFox <= 3.9.70 versions. |
- risk 0.00cvss 7.2epss 0.01
The Comments – wpDiscuz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the guest commenter 'Website' field in versions up to, and including, 7.6.56 This is due to insufficient output escaping in the getCommentAuthor() function, which interpolates the…
- risk 0.00cvss 6.4epss 0.00
The RTMKit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Advanced Heading widget's 'Background Text' parameter in versions up to, and including, 2.0.7 This is due to insufficient output escaping on the 'background_text_heading' setting in the render()…
- risk 0.00cvss 6.4epss 0.00
The JSON API User plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'content' parameter of the post_comment API endpoint in versions up to, and including, 4.1.0 This is due to insufficient input sanitization in the post_comment() function, which passes…
- risk 0.00cvss 6.4epss 0.00
The CM Business Directory – Optimise and showcase local business plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Business Address Meta Fields in all versions up to, and including, 1.5.7 due to insufficient input sanitization and output escaping. This…
- risk 0.00cvss 6.4epss 0.00
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'about_me' parameter in all versions up to, and including, 2.11.4 due to insufficient…
- risk 0.00cvss 7.2epss 0.01
The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'real_val__' parameter in all versions up to, and including, 9.2.2 due to insufficient input sanitization and output escaping. This makes it possible…
- risk 0.00cvss 6.4epss 0.00
The weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'connectorWidth' Block Attribute in all versions up to, and including, 2.3.0 due to insufficient input sanitization and output…
- risk 0.00cvss 6.4epss 0.00
The weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'sectionTitleTag' and 'articleTitleTag' Block Attributes in all versions up to, and including, 2.3.0 due to insufficient input…
- risk 0.00cvss 5.4epss 0.00
Forgejo before 15.0.3 contains a stored cross-site scripting vulnerability that allows authenticated attackers to execute arbitrary JavaScript in other users' browsers by setting a full name containing an HTML payload and triggering an Actions run. When the…
- risk 0.00cvss 5.4epss 0.00
RAGFlow before 0.26.3 stores an agent pipeline (DSL) node name without sanitization: the agent update endpoint normalizes the submitted DSL via normalize_dsl, which only performs JSON serialization validation and preserves the node name verbatim. The dataflow-result web UI then…
- risk 0.00cvss —epss 0.00
A stored Cross-Site Scripting (XSS) vulnerability has been identified in the web-based management interface of Archer C5 v6.8 routers, due to insufficient server-side validation and lack of proper output encoding of user-controlled input in a certain field. An attacker with…
- risk 0.00cvss 5.4epss 0.00
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in TR7 Cyber Defense Inc. WAF-ASP allows Stored XSS. This issue affects WAF-ASP: from v1.0.324.900 before v1.4.0.117.
- risk 0.00cvss 4.6epss 0.00
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in TR7 Cyber Defense Inc. Web Application Firewall allows DOM-Based XSS. This issue affects Web Application Firewall: from v1.0.42.239 before v1.4.0.117.
- risk 0.00cvss 6.5epss 0.00
Contributor Cross Site Scripting (XSS) in Surbma | Yoast SEO Breadcrumb Shortcode <= 1.2 versions.
- risk 0.00cvss 6.5epss 0.00
Contributor Cross Site Scripting (XSS) in Structured Content <= 1.7.0 versions.
- risk 0.00cvss 5.9epss 0.00
Author Cross Site Scripting (XSS) in Simple URLs <= 151 versions.
- risk 0.00cvss 6.5epss 0.00
Contributor Cross Site Scripting (XSS) in Mosaic Gallery – Advanced Gallery <= 1.2.0 versions.
- risk 0.00cvss 6.5epss 0.00
Contributor Cross Site Scripting (XSS) in Livemesh Addons for WPBakery Page Builder <= 3.9.4 versions.
- risk 0.00cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in WowAddons <= 1.6.14 versions.
- risk 0.00cvss 6.5epss 0.00
Contributor Cross Site Scripting (XSS) in TheFox <= 3.9.70 versions.