CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Description
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85
CVEs mapped to this weakness (46,817)
page 2050 of 2,341| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-11597 | Med | 0.00 | 6.4 | 0.00 | Jun 27, 2026 | The Surbma | Infusionsoft Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'infusionsoft-form' shortcode in versions up to, and including, 2.0.1. This is due to insufficient input sanitization and output escaping on user-supplied 'account' and… | ||
| CVE-2026-13245 | Med | 0.00 | 6.1 | 0.00 | Jun 27, 2026 | The MaxButtons – Create buttons plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'view' parameter in all versions up to, and including, 9.8.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated… | ||
| CVE-2026-13335 | Med | 0.00 | 6.4 | 0.00 | Jun 27, 2026 | The CodePeople Post Map for Google Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'cpm_point' Post Meta in all versions up to, and including, 1.2.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated… | ||
| CVE-2026-11356 | Med | 0.00 | 4.4 | 0.00 | Jun 27, 2026 | The Ivory Search – WordPress Search Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'menu_title' and 'menu_magnifier_color' Settings in all versions up to, and including, 5.5.15 due to insufficient input sanitization and output escaping. This makes… | ||
| CVE-2026-50767 | Med | 0.00 | 5.4 | 0.00 | Jun 26, 2026 | A stored cross-site scripting (XSS) vulnerability in the item type administration page of Koha Library Management System 0 through 25.11 versions allow an authenticated remote attacker with administrator privileges to inject arbitrary web scripts via the item type check-in… | ||
| CVE-2026-50766 | Med | 0.00 | 5.4 | 0.00 | Jun 26, 2026 | A stored cross-site scripting (XSS) vulnerability in the OPAC item detail page of Koha Library Management System 0 through 25.11 versions allow an authenticated remote attacker with edit_items permission to inject arbitrary web scripts via the item public notes field… | ||
| CVE-2026-50765 | Med | 0.00 | 6.1 | 0.00 | Jun 26, 2026 | A stored cross-site scripting (XSS) vulnerability in the patron restriction type administration page of Koha Library Management System 0 through 25.11 versions allow an authenticated remote attacker with administrator privileges to inject arbitrary web scripts via the… | ||
| CVE-2026-52781 | Med | 0.00 | 6.4 | 0.00 | Jun 26, 2026 | OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, the HTML sanitizer grants elements unrestricted data-* attributes via :data wildcard. An attacker injects data-controller="poll-for-changes" into a work package description,… | ||
| CVE-2026-44696 | Med | 0.00 | 5.7 | 0.00 | Jun 26, 2026 | OpenProject is open-source, web-based project management software. Prior to 17.4.0, OpenProject's rich text (markdown) rendering pipeline uses Sanitize::Config::RELAXED[:css] for inline style sanitization. This configuration permits essentially all CSS properties in style… | ||
| CVE-2026-57656 | Med | 0.00 | 5.9 | 0.00 | Jun 26, 2026 | Author Cross Site Scripting (XSS) in Hester Core <= 1.1.8 versions. | ||
| CVE-2026-57651 | Med | 0.00 | 6.5 | 0.00 | Jun 26, 2026 | Contributor Cross Site Scripting (XSS) in Ghost Kit <= 3.6.0 versions. | ||
| CVE-2026-57650 | Med | 0.00 | 6.5 | 0.00 | Jun 26, 2026 | Contributor Cross Site Scripting (XSS) in Magazine Blocks <= 1.8.3 versions. | ||
| CVE-2026-57638 | Med | 0.00 | 6.5 | 0.00 | Jun 26, 2026 | Contributor Cross Site Scripting (XSS) in Fluent Booking <= 2.1.0 versions. | ||
| CVE-2026-57629 | Med | 0.00 | 6.5 | 0.00 | Jun 26, 2026 | Contributor Cross Site Scripting (XSS) in StatCounter <= 2.1.1 versions. | ||
| CVE-2026-57618 | Med | 0.00 | 6.5 | 0.00 | Jun 26, 2026 | Contributor Cross Site Scripting (XSS) in Neve PRO <= 3.1.2 versions. | ||
| CVE-2026-57617 | Med | 0.00 | 6.5 | 0.00 | Jun 26, 2026 | Contributor Cross Site Scripting (XSS) in SeedProd Pro < 6.19.5 versions. | ||
| CVE-2026-57431 | Med | 0.00 | 6.5 | 0.00 | Jun 26, 2026 | Author Cross Site Scripting (XSS) in Featured Image <= 2.1 versions. | ||
| CVE-2026-57325 | Hig | 0.00 | 7.1 | 0.00 | Jun 26, 2026 | Unauthenticated Cross Site Scripting (XSS) in NanoMag <= 1.8 versions. | ||
| CVE-2026-57322 | Hig | 0.00 | 7.1 | 0.00 | Jun 26, 2026 | Unauthenticated Cross Site Scripting (XSS) in weMail <= 2.1.2 versions. | ||
| CVE-2026-57319 | Hig | 0.00 | 7.1 | 0.00 | Jun 26, 2026 | Unauthenticated Cross Site Scripting (XSS) in FOX <= 1.4.8 versions. |
- risk 0.00cvss 6.4epss 0.00
The Surbma | Infusionsoft Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'infusionsoft-form' shortcode in versions up to, and including, 2.0.1. This is due to insufficient input sanitization and output escaping on user-supplied 'account' and…
- risk 0.00cvss 6.1epss 0.00
The MaxButtons – Create buttons plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'view' parameter in all versions up to, and including, 9.8.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated…
- risk 0.00cvss 6.4epss 0.00
The CodePeople Post Map for Google Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'cpm_point' Post Meta in all versions up to, and including, 1.2.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…
- risk 0.00cvss 4.4epss 0.00
The Ivory Search – WordPress Search Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'menu_title' and 'menu_magnifier_color' Settings in all versions up to, and including, 5.5.15 due to insufficient input sanitization and output escaping. This makes…
- risk 0.00cvss 5.4epss 0.00
A stored cross-site scripting (XSS) vulnerability in the item type administration page of Koha Library Management System 0 through 25.11 versions allow an authenticated remote attacker with administrator privileges to inject arbitrary web scripts via the item type check-in…
- risk 0.00cvss 5.4epss 0.00
A stored cross-site scripting (XSS) vulnerability in the OPAC item detail page of Koha Library Management System 0 through 25.11 versions allow an authenticated remote attacker with edit_items permission to inject arbitrary web scripts via the item public notes field…
- risk 0.00cvss 6.1epss 0.00
A stored cross-site scripting (XSS) vulnerability in the patron restriction type administration page of Koha Library Management System 0 through 25.11 versions allow an authenticated remote attacker with administrator privileges to inject arbitrary web scripts via the…
- risk 0.00cvss 6.4epss 0.00
OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, the HTML sanitizer grants elements unrestricted data-* attributes via :data wildcard. An attacker injects data-controller="poll-for-changes" into a work package description,…
- risk 0.00cvss 5.7epss 0.00
OpenProject is open-source, web-based project management software. Prior to 17.4.0, OpenProject's rich text (markdown) rendering pipeline uses Sanitize::Config::RELAXED[:css] for inline style sanitization. This configuration permits essentially all CSS properties in style…
- risk 0.00cvss 5.9epss 0.00
Author Cross Site Scripting (XSS) in Hester Core <= 1.1.8 versions.
- risk 0.00cvss 6.5epss 0.00
Contributor Cross Site Scripting (XSS) in Ghost Kit <= 3.6.0 versions.
- risk 0.00cvss 6.5epss 0.00
Contributor Cross Site Scripting (XSS) in Magazine Blocks <= 1.8.3 versions.
- risk 0.00cvss 6.5epss 0.00
Contributor Cross Site Scripting (XSS) in Fluent Booking <= 2.1.0 versions.
- risk 0.00cvss 6.5epss 0.00
Contributor Cross Site Scripting (XSS) in StatCounter <= 2.1.1 versions.
- risk 0.00cvss 6.5epss 0.00
Contributor Cross Site Scripting (XSS) in Neve PRO <= 3.1.2 versions.
- risk 0.00cvss 6.5epss 0.00
Contributor Cross Site Scripting (XSS) in SeedProd Pro < 6.19.5 versions.
- risk 0.00cvss 6.5epss 0.00
Author Cross Site Scripting (XSS) in Featured Image <= 2.1 versions.
- risk 0.00cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in NanoMag <= 1.8 versions.
- risk 0.00cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in weMail <= 2.1.2 versions.
- risk 0.00cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in FOX <= 1.4.8 versions.