VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (46,817)

page 2049 of 2,341
  • CVE-2026-57337HigJun 29, 2026
    risk 0.00cvss 7.1epss 0.00

    Unauthenticated Cross Site Scripting (XSS) in Landing Page Builder <= 1.5.3.5 versions.

  • CVE-2026-57336HigJun 29, 2026
    risk 0.00cvss 7.1epss 0.00

    Unauthenticated Cross Site Scripting (XSS) in Jobify <= 4.3.2 versions.

  • CVE-2026-57333HigJun 29, 2026
    risk 0.00cvss 7.1epss 0.00

    Unauthenticated Cross Site Scripting (XSS) in Link Whisper Free <= 0.9.4 versions.

  • CVE-2026-57330MedJun 29, 2026
    risk 0.00cvss 6.5epss 0.00

    Subscriber Cross Site Scripting (XSS) in MasterStudy LMS <= 3.7.27 versions.

  • CVE-2026-57329MedJun 29, 2026
    risk 0.00cvss 6.5epss 0.00

    Subscriber Cross Site Scripting (XSS) in WooCommerce Designer Pro <= 1.9.34 versions.

  • CVE-2026-57328MedJun 29, 2026
    risk 0.00cvss 6.5epss 0.00

    Subscriber Cross Site Scripting (XSS) in Business Directory <= 6.4.22 versions.

  • CVE-2026-57326MedJun 29, 2026
    risk 0.00cvss 6.1epss 0.00

    Unauthenticated Cross Site Scripting (XSS) in Business Directory <= 6.4.22 versions.

  • CVE-2026-57320HigJun 29, 2026
    risk 0.00cvss 7.1epss 0.00

    Unauthenticated Cross Site Scripting (XSS) in BEAR <= 1.1.8 versions.

  • CVE-2026-13570LowJun 29, 2026
    risk 0.00cvss 3.5epss 0.00

    A vulnerability was detected in SourceCodester Inventory Management System 1.0. Impacted is an unknown function of the file /api/users_handler.php of the component User Registration Endpoint. Performing a manipulation of the argument full_name results in cross site scripting.…

  • CVE-2026-13567MedJun 29, 2026
    risk 0.00cvss 4.3epss 0.00

    A security flaw has been discovered in code-projects Online Music Site 1.0. This affects an unknown part of the file /Frontend/Feedback.php of the component POST Request Handler. The manipulation of the argument fname/femail/faddress/fmessage results in cross site scripting. The…

  • CVE-2026-13558LowJun 29, 2026
    risk 0.00cvss 3.5epss 0.00

    A security flaw has been discovered in CodeAstro Complaint Management System 1.0. This issue affects some unknown processing of the file /report/addreport of the component Report Handler. Performing a manipulation of the argument Report Title results in cross site scripting.…

  • CVE-2026-13557MedJun 29, 2026
    risk 0.00cvss 4.3epss 0.00

    A vulnerability was identified in itsourcecode Online Hotel Management System 1.0. This vulnerability affects unknown code of the file /admin/mod_room/controller.php?action=add of the component POST Request Handler. Such manipulation of the argument Name leads to cross site…

  • CVE-2026-13556MedJun 29, 2026
    risk 0.00cvss 4.3epss 0.00

    A vulnerability was determined in itsourcecode Online Hotel Management System 1.0. This affects an unknown part of the file /admin/mod_users/controller.php?action=edit of the component POST Request Handler. This manipulation of the argument Name causes cross site scripting. The…

  • CVE-2026-13554MedJun 29, 2026
    risk 0.00cvss 4.3epss 0.00

    A vulnerability has been found in itsourcecode Online Hotel Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/mod_amenities/controller.php?action=add of the component POST Request Handler. The manipulation of the argument Name…

  • CVE-2026-13536MedJun 29, 2026
    risk 0.00cvss 4.3epss 0.00

    A vulnerability has been found in GotoHTTP up to 10.2. This issue affects some unknown processing of the file /reg.12x. The manipulation of the argument sn leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may…

  • CVE-2026-13504LowJun 28, 2026
    risk 0.00cvss 3.5epss 0.00

    A vulnerability has been found in code-projects Project Management System 1.0. This vulnerability affects unknown code of the file /mail.php of the component Mail Compose Page. Such manipulation leads to cross site scripting. The attack may be performed from remote. The exploit…

  • CVE-2026-13499MedJun 28, 2026
    risk 0.00cvss 4.3epss 0.00

    A security flaw has been discovered in yashpokharna2555 restaurent-management-system. This impacts an unknown function of the file login_register.php of the component Registration Handler. Performing a manipulation of the argument Username results in cross site scripting. The…

  • CVE-2026-13295MedJun 27, 2026
    risk 0.00cvss 6.4epss 0.00

    The Page Builder by SiteOrigin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via panels_data Parameter in all versions up to, and including, 2.34.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,…

  • CVE-2026-12399MedJun 27, 2026
    risk 0.00cvss 4.4epss 0.00

    The Gutenverse – WordPress Blocks, Page Builder & Site Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.8.0 due to insufficient input sanitization and output escaping. This makes it possible for…

  • CVE-2026-11783MedJun 27, 2026
    risk 0.00cvss 6.4epss 0.00

    The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Product SKU in all versions up to, and including, 5.0.4 due to insufficient input sanitization and…