VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (46,817)

page 2044 of 2,341
  • CVE-2026-9148HigJul 3, 2026
    risk 0.00cvss 7.2epss 0.01

    The Comments – wpDiscuz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the guest commenter 'Website' field in versions up to, and including, 7.6.56 This is due to insufficient output escaping in the getCommentAuthor() function, which interpolates the…

  • CVE-2026-8351MedJul 3, 2026
    risk 0.00cvss 6.4epss 0.00

    The RTMKit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Advanced Heading widget's 'Background Text' parameter in versions up to, and including, 2.0.7 This is due to insufficient output escaping on the 'background_text_heading' setting in the render()…

  • CVE-2026-9626MedJul 3, 2026
    risk 0.00cvss 6.4epss 0.00

    The JSON API User plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'content' parameter of the post_comment API endpoint in versions up to, and including, 4.1.0 This is due to insufficient input sanitization in the post_comment() function, which passes…

  • CVE-2026-8892MedJul 3, 2026
    risk 0.00cvss 6.4epss 0.00

    The CM Business Directory – Optimise and showcase local business plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Business Address Meta Fields in all versions up to, and including, 1.5.7 due to insufficient input sanitization and output escaping. This…

  • CVE-2026-8489MedJul 3, 2026
    risk 0.00cvss 6.4epss 0.00

    The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'about_me' parameter in all versions up to, and including, 2.11.4 due to insufficient…

  • CVE-2026-13040HigJul 3, 2026
    risk 0.00cvss 7.2epss 0.01

    The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'real_val__' parameter in all versions up to, and including, 9.2.2 due to insufficient input sanitization and output escaping. This makes it possible…

  • CVE-2026-12734MedJul 3, 2026
    risk 0.00cvss 6.4epss 0.00

    The weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'connectorWidth' Block Attribute in all versions up to, and including, 2.3.0 due to insufficient input sanitization and output…

  • CVE-2026-12731MedJul 3, 2026
    risk 0.00cvss 6.4epss 0.00

    The weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'sectionTitleTag' and 'articleTitleTag' Block Attributes in all versions up to, and including, 2.3.0 due to insufficient input…

  • CVE-2026-59102MedJul 2, 2026
    risk 0.00cvss 5.4epss 0.00

    Forgejo before 15.0.3 contains a stored cross-site scripting vulnerability that allows authenticated attackers to execute arbitrary JavaScript in other users' browsers by setting a full name containing an HTML payload and triggering an Actions run. When the…

  • CVE-2026-58579MedJul 2, 2026
    risk 0.00cvss 5.4epss 0.00

    RAGFlow before 0.26.3 stores an agent pipeline (DSL) node name without sanitization: the agent update endpoint normalizes the submitted DSL via normalize_dsl, which only performs JSON serialization validation and preserves the node name verbatim. The dataflow-result web UI then…

  • CVE-2026-8699HigJul 2, 2026
    risk 0.00cvss epss 0.00

    A stored Cross-Site Scripting (XSS) vulnerability has been identified in the web-based management interface of Archer C5 v6.8 routers, due to insufficient server-side validation and lack of proper output encoding of user-controlled input in a certain field.  An attacker with…

  • CVE-2026-4772MedJul 2, 2026
    risk 0.00cvss 5.4epss 0.00

    Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in TR7 Cyber ​​Defense Inc. WAF-ASP allows Stored XSS. This issue affects WAF-ASP: from v1.0.324.900 before v1.4.0.117.

  • CVE-2026-4770MedJul 2, 2026
    risk 0.00cvss 4.6epss 0.00

    Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in TR7 Cyber ​​Defense Inc. Web Application Firewall allows DOM-Based XSS. This issue affects Web Application Firewall: from v1.0.42.239 before v1.4.0.117.

  • CVE-2026-57764MedJul 2, 2026
    risk 0.00cvss 6.5epss 0.00

    Contributor Cross Site Scripting (XSS) in Surbma | Yoast SEO Breadcrumb Shortcode <= 1.2 versions.

  • CVE-2026-57763MedJul 2, 2026
    risk 0.00cvss 6.5epss 0.00

    Contributor Cross Site Scripting (XSS) in Structured Content <= 1.7.0 versions.

  • CVE-2026-57762MedJul 2, 2026
    risk 0.00cvss 5.9epss 0.00

    Author Cross Site Scripting (XSS) in Simple URLs <= 151 versions.

  • CVE-2026-57755MedJul 2, 2026
    risk 0.00cvss 6.5epss 0.00

    Contributor Cross Site Scripting (XSS) in Mosaic Gallery – Advanced Gallery <= 1.2.0 versions.

  • CVE-2026-57754MedJul 2, 2026
    risk 0.00cvss 6.5epss 0.00

    Contributor Cross Site Scripting (XSS) in Livemesh Addons for WPBakery Page Builder <= 3.9.4 versions.

  • CVE-2026-57686HigJul 2, 2026
    risk 0.00cvss 7.1epss 0.00

    Unauthenticated Cross Site Scripting (XSS) in WowAddons <= 1.6.14 versions.

  • CVE-2026-57684MedJul 2, 2026
    risk 0.00cvss 6.5epss 0.00

    Contributor Cross Site Scripting (XSS) in TheFox <= 3.9.70 versions.