VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (46,817)

page 2050 of 2,341
  • CVE-2026-11597MedJun 27, 2026
    risk 0.00cvss 6.4epss 0.00

    The Surbma | Infusionsoft Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'infusionsoft-form' shortcode in versions up to, and including, 2.0.1. This is due to insufficient input sanitization and output escaping on user-supplied 'account' and…

  • CVE-2026-13245MedJun 27, 2026
    risk 0.00cvss 6.1epss 0.00

    The MaxButtons – Create buttons plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'view' parameter in all versions up to, and including, 9.8.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated…

  • CVE-2026-13335MedJun 27, 2026
    risk 0.00cvss 6.4epss 0.00

    The CodePeople Post Map for Google Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'cpm_point' Post Meta in all versions up to, and including, 1.2.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…

  • CVE-2026-11356MedJun 27, 2026
    risk 0.00cvss 4.4epss 0.00

    The Ivory Search – WordPress Search Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'menu_title' and 'menu_magnifier_color' Settings in all versions up to, and including, 5.5.15 due to insufficient input sanitization and output escaping. This makes…

  • CVE-2026-50767MedJun 26, 2026
    risk 0.00cvss 5.4epss 0.00

    A stored cross-site scripting (XSS) vulnerability in the item type administration page of Koha Library Management System 0 through 25.11 versions allow an authenticated remote attacker with administrator privileges to inject arbitrary web scripts via the item type check-in…

  • CVE-2026-50766MedJun 26, 2026
    risk 0.00cvss 5.4epss 0.00

    A stored cross-site scripting (XSS) vulnerability in the OPAC item detail page of Koha Library Management System 0 through 25.11 versions allow an authenticated remote attacker with edit_items permission to inject arbitrary web scripts via the item public notes field…

  • CVE-2026-50765MedJun 26, 2026
    risk 0.00cvss 6.1epss 0.00

    A stored cross-site scripting (XSS) vulnerability in the patron restriction type administration page of Koha Library Management System 0 through 25.11 versions allow an authenticated remote attacker with administrator privileges to inject arbitrary web scripts via the…

  • CVE-2026-52781MedJun 26, 2026
    risk 0.00cvss 6.4epss 0.00

    OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, the HTML sanitizer grants elements unrestricted data-* attributes via :data wildcard. An attacker injects data-controller="poll-for-changes" into a work package description,…

  • CVE-2026-44696MedJun 26, 2026
    risk 0.00cvss 5.7epss 0.00

    OpenProject is open-source, web-based project management software. Prior to 17.4.0, OpenProject's rich text (markdown) rendering pipeline uses Sanitize::Config::RELAXED[:css] for inline style sanitization. This configuration permits essentially all CSS properties in style…

  • CVE-2026-57656MedJun 26, 2026
    risk 0.00cvss 5.9epss 0.00

    Author Cross Site Scripting (XSS) in Hester Core <= 1.1.8 versions.

  • CVE-2026-57651MedJun 26, 2026
    risk 0.00cvss 6.5epss 0.00

    Contributor Cross Site Scripting (XSS) in Ghost Kit <= 3.6.0 versions.

  • CVE-2026-57650MedJun 26, 2026
    risk 0.00cvss 6.5epss 0.00

    Contributor Cross Site Scripting (XSS) in Magazine Blocks <= 1.8.3 versions.

  • CVE-2026-57638MedJun 26, 2026
    risk 0.00cvss 6.5epss 0.00

    Contributor Cross Site Scripting (XSS) in Fluent Booking <= 2.1.0 versions.

  • CVE-2026-57629MedJun 26, 2026
    risk 0.00cvss 6.5epss 0.00

    Contributor Cross Site Scripting (XSS) in StatCounter <= 2.1.1 versions.

  • CVE-2026-57618MedJun 26, 2026
    risk 0.00cvss 6.5epss 0.00

    Contributor Cross Site Scripting (XSS) in Neve PRO <= 3.1.2 versions.

  • CVE-2026-57617MedJun 26, 2026
    risk 0.00cvss 6.5epss 0.00

    Contributor Cross Site Scripting (XSS) in SeedProd Pro < 6.19.5 versions.

  • CVE-2026-57431MedJun 26, 2026
    risk 0.00cvss 6.5epss 0.00

    Author Cross Site Scripting (XSS) in Featured Image <= 2.1 versions.

  • CVE-2026-57325HigJun 26, 2026
    risk 0.00cvss 7.1epss 0.00

    Unauthenticated Cross Site Scripting (XSS) in NanoMag <= 1.8 versions.

  • CVE-2026-57322HigJun 26, 2026
    risk 0.00cvss 7.1epss 0.00

    Unauthenticated Cross Site Scripting (XSS) in weMail <= 2.1.2 versions.

  • CVE-2026-57319HigJun 26, 2026
    risk 0.00cvss 7.1epss 0.00

    Unauthenticated Cross Site Scripting (XSS) in FOX <= 1.4.8 versions.