VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (46,817)

page 2051 of 2,341
  • CVE-2026-57317HigJun 26, 2026
    risk 0.00cvss 7.1epss 0.00

    Unauthenticated Cross Site Scripting (XSS) in Simply Schedule Appointments <= 1.6.12.2 versions.

  • CVE-2026-57314HigJun 26, 2026
    risk 0.00cvss 7.1epss 0.00

    Unauthenticated Cross Site Scripting (XSS) in SureCart <= 4.3.2 versions.

  • CVE-2026-57313MedJun 26, 2026
    risk 0.00cvss 6.5epss 0.00

    Subscriber Cross Site Scripting (XSS) in SureCart <= 4.2.2 versions.

  • CVE-2026-57312HigJun 26, 2026
    risk 0.00cvss 7.1epss 0.00

    Unauthenticated Cross Site Scripting (XSS) in Everest Forms <= 3.4.8 versions.

  • CVE-2026-56072HigJun 26, 2026
    risk 0.00cvss 7.1epss 0.00

    Unauthenticated Cross Site Scripting (XSS) in WoodMart <= 8.5.3 versions.

  • CVE-2026-56047HigJun 26, 2026
    risk 0.00cvss 7.1epss 0.00

    Unauthenticated Cross Site Scripting (XSS) in perfmatters <= 2.6.3 versions.

  • CVE-2026-56046MedJun 26, 2026
    risk 0.00cvss 6.5epss 0.00

    Subscriber Cross Site Scripting (XSS) in ListingPro <= 2.9.11 versions.

  • CVE-2026-56045HigJun 26, 2026
    risk 0.00cvss 7.1epss 0.00

    Unauthenticated Cross Site Scripting (XSS) in Automatic < 3.135.1 versions.

  • CVE-2026-56044HigJun 26, 2026
    risk 0.00cvss 7.1epss 0.00

    Unauthenticated Cross Site Scripting (XSS) in Blog2Social <= 8.9.2 versions.

  • CVE-2026-56043HigJun 26, 2026
    risk 0.00cvss 7.1epss 0.00

    Unauthenticated Cross Site Scripting (XSS) in Customer Reviews for WooCommerce <= 5.110.1 versions.

  • CVE-2026-56041HigJun 26, 2026
    risk 0.00cvss 7.1epss 0.00

    Unauthenticated Cross Site Scripting (XSS) in Responsive Lightbox <= 2.7.6 versions.

  • CVE-2026-56040HigJun 26, 2026
    risk 0.00cvss 7.1epss 0.00

    Unauthenticated Cross Site Scripting (XSS) in Gutenverse Form <= 2.4.7 versions.

  • CVE-2026-56039HigJun 26, 2026
    risk 0.00cvss 7.1epss 0.00

    Unauthenticated Cross Site Scripting (XSS) in Quick Interest Slider <= 3.1.6 versions.

  • CVE-2026-56011HigJun 26, 2026
    risk 0.00cvss 7.1epss 0.00

    Unauthenticated Cross Site Scripting (XSS) in MapPress Maps for WordPress <= 2.97.3 versions.

  • CVE-2025-68075MedJun 26, 2026
    risk 0.00cvss 6.5epss 0.00

    Contributor Cross Site Scripting (XSS) in BNE Testimonials <= 2.0.8 versions.

  • CVE-2025-68074MedJun 26, 2026
    risk 0.00cvss 6.5epss 0.00

    Contributor Cross Site Scripting (XSS) in Image Carousel <= 1.0.0.41 versions.

  • CVE-2026-57620MedJun 26, 2026
    risk 0.00cvss 6.5epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tim Strifler Exclusive Addons Elementor allows Stored XSS. This issue affects Exclusive Addons Elementor: from n/a through 2.7.9.8.

  • CVE-2026-8661MedJun 26, 2026
    risk 0.00cvss 4.8epss 0.00

    Server-Side Request Forgery in the markdown_to_pdf action of Rapid7 InsightConnect Markdown Plugin on Linux in versions prior to 4.0.2 allows remote attackers to make arbitrary outbound HTTP requests via unsanitized resource-loading HTML elements (img/src, CSS url(), @import)…

  • CVE-2026-50745MedJun 26, 2026
    risk 0.00cvss 6.1epss 0.00

    A missing sanitisation vulnerability exists with user input in the stats-video.php script. The way URLs to this script were constructed did not follow best practices, and the output of the Smarty custom helper function url was neither properly encoded nor sanitised, allowing…

  • CVE-2026-50742MedJun 26, 2026
    risk 0.00cvss 5.4epss 0.00

    A stored XSS vulnerabilities exists in the `maintenance-acl-check.php` and `maintenance-banners-check.php` tools of Revive Adserver 6.0.7. The issue was caused by entity names being displayed without proper escaping when inconsistencies were detected. Whether the XSS payload is…