CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Description
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85
CVEs mapped to this weakness (46,817)
page 2049 of 2,341| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-57337 | Hig | 0.00 | 7.1 | 0.00 | Jun 29, 2026 | Unauthenticated Cross Site Scripting (XSS) in Landing Page Builder <= 1.5.3.5 versions. | ||
| CVE-2026-57336 | Hig | 0.00 | 7.1 | 0.00 | Jun 29, 2026 | Unauthenticated Cross Site Scripting (XSS) in Jobify <= 4.3.2 versions. | ||
| CVE-2026-57333 | Hig | 0.00 | 7.1 | 0.00 | Jun 29, 2026 | Unauthenticated Cross Site Scripting (XSS) in Link Whisper Free <= 0.9.4 versions. | ||
| CVE-2026-57330 | Med | 0.00 | 6.5 | 0.00 | Jun 29, 2026 | Subscriber Cross Site Scripting (XSS) in MasterStudy LMS <= 3.7.27 versions. | ||
| CVE-2026-57329 | Med | 0.00 | 6.5 | 0.00 | Jun 29, 2026 | Subscriber Cross Site Scripting (XSS) in WooCommerce Designer Pro <= 1.9.34 versions. | ||
| CVE-2026-57328 | Med | 0.00 | 6.5 | 0.00 | Jun 29, 2026 | Subscriber Cross Site Scripting (XSS) in Business Directory <= 6.4.22 versions. | ||
| CVE-2026-57326 | Med | 0.00 | 6.1 | 0.00 | Jun 29, 2026 | Unauthenticated Cross Site Scripting (XSS) in Business Directory <= 6.4.22 versions. | ||
| CVE-2026-57320 | Hig | 0.00 | 7.1 | 0.00 | Jun 29, 2026 | Unauthenticated Cross Site Scripting (XSS) in BEAR <= 1.1.8 versions. | ||
| CVE-2026-13570 | Low | 0.00 | 3.5 | 0.00 | Jun 29, 2026 | A vulnerability was detected in SourceCodester Inventory Management System 1.0. Impacted is an unknown function of the file /api/users_handler.php of the component User Registration Endpoint. Performing a manipulation of the argument full_name results in cross site scripting.… | ||
| CVE-2026-13567 | Med | 0.00 | 4.3 | 0.00 | Jun 29, 2026 | A security flaw has been discovered in code-projects Online Music Site 1.0. This affects an unknown part of the file /Frontend/Feedback.php of the component POST Request Handler. The manipulation of the argument fname/femail/faddress/fmessage results in cross site scripting. The… | ||
| CVE-2026-13558 | Low | 0.00 | 3.5 | 0.00 | Jun 29, 2026 | A security flaw has been discovered in CodeAstro Complaint Management System 1.0. This issue affects some unknown processing of the file /report/addreport of the component Report Handler. Performing a manipulation of the argument Report Title results in cross site scripting.… | ||
| CVE-2026-13557 | Med | 0.00 | 4.3 | 0.00 | Jun 29, 2026 | A vulnerability was identified in itsourcecode Online Hotel Management System 1.0. This vulnerability affects unknown code of the file /admin/mod_room/controller.php?action=add of the component POST Request Handler. Such manipulation of the argument Name leads to cross site… | ||
| CVE-2026-13556 | Med | 0.00 | 4.3 | 0.00 | Jun 29, 2026 | A vulnerability was determined in itsourcecode Online Hotel Management System 1.0. This affects an unknown part of the file /admin/mod_users/controller.php?action=edit of the component POST Request Handler. This manipulation of the argument Name causes cross site scripting. The… | ||
| CVE-2026-13554 | Med | 0.00 | 4.3 | 0.00 | Jun 29, 2026 | A vulnerability has been found in itsourcecode Online Hotel Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/mod_amenities/controller.php?action=add of the component POST Request Handler. The manipulation of the argument Name… | ||
| CVE-2026-13536 | Med | 0.00 | 4.3 | 0.00 | Jun 29, 2026 | A vulnerability has been found in GotoHTTP up to 10.2. This issue affects some unknown processing of the file /reg.12x. The manipulation of the argument sn leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may… | ||
| CVE-2026-13504 | Low | 0.00 | 3.5 | 0.00 | Jun 28, 2026 | A vulnerability has been found in code-projects Project Management System 1.0. This vulnerability affects unknown code of the file /mail.php of the component Mail Compose Page. Such manipulation leads to cross site scripting. The attack may be performed from remote. The exploit… | ||
| CVE-2026-13499 | Med | 0.00 | 4.3 | 0.00 | Jun 28, 2026 | A security flaw has been discovered in yashpokharna2555 restaurent-management-system. This impacts an unknown function of the file login_register.php of the component Registration Handler. Performing a manipulation of the argument Username results in cross site scripting. The… | ||
| CVE-2026-13295 | Med | 0.00 | 6.4 | 0.00 | Jun 27, 2026 | The Page Builder by SiteOrigin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via panels_data Parameter in all versions up to, and including, 2.34.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,… | ||
| CVE-2026-12399 | Med | 0.00 | 4.4 | 0.00 | Jun 27, 2026 | The Gutenverse – WordPress Blocks, Page Builder & Site Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.8.0 due to insufficient input sanitization and output escaping. This makes it possible for… | ||
| CVE-2026-11783 | Med | 0.00 | 6.4 | 0.00 | Jun 27, 2026 | The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Product SKU in all versions up to, and including, 5.0.4 due to insufficient input sanitization and… |
- risk 0.00cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in Landing Page Builder <= 1.5.3.5 versions.
- risk 0.00cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in Jobify <= 4.3.2 versions.
- risk 0.00cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in Link Whisper Free <= 0.9.4 versions.
- risk 0.00cvss 6.5epss 0.00
Subscriber Cross Site Scripting (XSS) in MasterStudy LMS <= 3.7.27 versions.
- risk 0.00cvss 6.5epss 0.00
Subscriber Cross Site Scripting (XSS) in WooCommerce Designer Pro <= 1.9.34 versions.
- risk 0.00cvss 6.5epss 0.00
Subscriber Cross Site Scripting (XSS) in Business Directory <= 6.4.22 versions.
- risk 0.00cvss 6.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in Business Directory <= 6.4.22 versions.
- risk 0.00cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in BEAR <= 1.1.8 versions.
- risk 0.00cvss 3.5epss 0.00
A vulnerability was detected in SourceCodester Inventory Management System 1.0. Impacted is an unknown function of the file /api/users_handler.php of the component User Registration Endpoint. Performing a manipulation of the argument full_name results in cross site scripting.…
- risk 0.00cvss 4.3epss 0.00
A security flaw has been discovered in code-projects Online Music Site 1.0. This affects an unknown part of the file /Frontend/Feedback.php of the component POST Request Handler. The manipulation of the argument fname/femail/faddress/fmessage results in cross site scripting. The…
- risk 0.00cvss 3.5epss 0.00
A security flaw has been discovered in CodeAstro Complaint Management System 1.0. This issue affects some unknown processing of the file /report/addreport of the component Report Handler. Performing a manipulation of the argument Report Title results in cross site scripting.…
- risk 0.00cvss 4.3epss 0.00
A vulnerability was identified in itsourcecode Online Hotel Management System 1.0. This vulnerability affects unknown code of the file /admin/mod_room/controller.php?action=add of the component POST Request Handler. Such manipulation of the argument Name leads to cross site…
- risk 0.00cvss 4.3epss 0.00
A vulnerability was determined in itsourcecode Online Hotel Management System 1.0. This affects an unknown part of the file /admin/mod_users/controller.php?action=edit of the component POST Request Handler. This manipulation of the argument Name causes cross site scripting. The…
- risk 0.00cvss 4.3epss 0.00
A vulnerability has been found in itsourcecode Online Hotel Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/mod_amenities/controller.php?action=add of the component POST Request Handler. The manipulation of the argument Name…
- risk 0.00cvss 4.3epss 0.00
A vulnerability has been found in GotoHTTP up to 10.2. This issue affects some unknown processing of the file /reg.12x. The manipulation of the argument sn leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may…
- risk 0.00cvss 3.5epss 0.00
A vulnerability has been found in code-projects Project Management System 1.0. This vulnerability affects unknown code of the file /mail.php of the component Mail Compose Page. Such manipulation leads to cross site scripting. The attack may be performed from remote. The exploit…
- risk 0.00cvss 4.3epss 0.00
A security flaw has been discovered in yashpokharna2555 restaurent-management-system. This impacts an unknown function of the file login_register.php of the component Registration Handler. Performing a manipulation of the argument Username results in cross site scripting. The…
- risk 0.00cvss 6.4epss 0.00
The Page Builder by SiteOrigin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via panels_data Parameter in all versions up to, and including, 2.34.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,…
- risk 0.00cvss 4.4epss 0.00
The Gutenverse – WordPress Blocks, Page Builder & Site Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.8.0 due to insufficient input sanitization and output escaping. This makes it possible for…
- risk 0.00cvss 6.4epss 0.00
The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Product SKU in all versions up to, and including, 5.0.4 due to insufficient input sanitization and…