CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Description
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85
CVEs mapped to this weakness (46,817)
page 2051 of 2,341| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-57317 | Hig | 0.00 | 7.1 | 0.00 | Jun 26, 2026 | Unauthenticated Cross Site Scripting (XSS) in Simply Schedule Appointments <= 1.6.12.2 versions. | ||
| CVE-2026-57314 | Hig | 0.00 | 7.1 | 0.00 | Jun 26, 2026 | Unauthenticated Cross Site Scripting (XSS) in SureCart <= 4.3.2 versions. | ||
| CVE-2026-57313 | Med | 0.00 | 6.5 | 0.00 | Jun 26, 2026 | Subscriber Cross Site Scripting (XSS) in SureCart <= 4.2.2 versions. | ||
| CVE-2026-57312 | Hig | 0.00 | 7.1 | 0.00 | Jun 26, 2026 | Unauthenticated Cross Site Scripting (XSS) in Everest Forms <= 3.4.8 versions. | ||
| CVE-2026-56072 | Hig | 0.00 | 7.1 | 0.00 | Jun 26, 2026 | Unauthenticated Cross Site Scripting (XSS) in WoodMart <= 8.5.3 versions. | ||
| CVE-2026-56047 | Hig | 0.00 | 7.1 | 0.00 | Jun 26, 2026 | Unauthenticated Cross Site Scripting (XSS) in perfmatters <= 2.6.3 versions. | ||
| CVE-2026-56046 | Med | 0.00 | 6.5 | 0.00 | Jun 26, 2026 | Subscriber Cross Site Scripting (XSS) in ListingPro <= 2.9.11 versions. | ||
| CVE-2026-56045 | Hig | 0.00 | 7.1 | 0.00 | Jun 26, 2026 | Unauthenticated Cross Site Scripting (XSS) in Automatic < 3.135.1 versions. | ||
| CVE-2026-56044 | Hig | 0.00 | 7.1 | 0.00 | Jun 26, 2026 | Unauthenticated Cross Site Scripting (XSS) in Blog2Social <= 8.9.2 versions. | ||
| CVE-2026-56043 | Hig | 0.00 | 7.1 | 0.00 | Jun 26, 2026 | Unauthenticated Cross Site Scripting (XSS) in Customer Reviews for WooCommerce <= 5.110.1 versions. | ||
| CVE-2026-56041 | Hig | 0.00 | 7.1 | 0.00 | Jun 26, 2026 | Unauthenticated Cross Site Scripting (XSS) in Responsive Lightbox <= 2.7.6 versions. | ||
| CVE-2026-56040 | Hig | 0.00 | 7.1 | 0.00 | Jun 26, 2026 | Unauthenticated Cross Site Scripting (XSS) in Gutenverse Form <= 2.4.7 versions. | ||
| CVE-2026-56039 | Hig | 0.00 | 7.1 | 0.00 | Jun 26, 2026 | Unauthenticated Cross Site Scripting (XSS) in Quick Interest Slider <= 3.1.6 versions. | ||
| CVE-2026-56011 | Hig | 0.00 | 7.1 | 0.00 | Jun 26, 2026 | Unauthenticated Cross Site Scripting (XSS) in MapPress Maps for WordPress <= 2.97.3 versions. | ||
| CVE-2025-68075 | Med | 0.00 | 6.5 | 0.00 | Jun 26, 2026 | Contributor Cross Site Scripting (XSS) in BNE Testimonials <= 2.0.8 versions. | ||
| CVE-2025-68074 | Med | 0.00 | 6.5 | 0.00 | Jun 26, 2026 | Contributor Cross Site Scripting (XSS) in Image Carousel <= 1.0.0.41 versions. | ||
| CVE-2026-57620 | Med | 0.00 | 6.5 | 0.00 | Jun 26, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tim Strifler Exclusive Addons Elementor allows Stored XSS. This issue affects Exclusive Addons Elementor: from n/a through 2.7.9.8. | ||
| CVE-2026-8661 | Med | 0.00 | 4.8 | 0.00 | Jun 26, 2026 | Server-Side Request Forgery in the markdown_to_pdf action of Rapid7 InsightConnect Markdown Plugin on Linux in versions prior to 4.0.2 allows remote attackers to make arbitrary outbound HTTP requests via unsanitized resource-loading HTML elements (img/src, CSS url(), @import)… | ||
| CVE-2026-50745 | Med | 0.00 | 6.1 | 0.00 | Jun 26, 2026 | A missing sanitisation vulnerability exists with user input in the stats-video.php script. The way URLs to this script were constructed did not follow best practices, and the output of the Smarty custom helper function url was neither properly encoded nor sanitised, allowing… | ||
| CVE-2026-50742 | Med | 0.00 | 5.4 | 0.00 | Jun 26, 2026 | A stored XSS vulnerabilities exists in the `maintenance-acl-check.php` and `maintenance-banners-check.php` tools of Revive Adserver 6.0.7. The issue was caused by entity names being displayed without proper escaping when inconsistencies were detected. Whether the XSS payload is… |
- risk 0.00cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in Simply Schedule Appointments <= 1.6.12.2 versions.
- risk 0.00cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in SureCart <= 4.3.2 versions.
- risk 0.00cvss 6.5epss 0.00
Subscriber Cross Site Scripting (XSS) in SureCart <= 4.2.2 versions.
- risk 0.00cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in Everest Forms <= 3.4.8 versions.
- risk 0.00cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in WoodMart <= 8.5.3 versions.
- risk 0.00cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in perfmatters <= 2.6.3 versions.
- risk 0.00cvss 6.5epss 0.00
Subscriber Cross Site Scripting (XSS) in ListingPro <= 2.9.11 versions.
- risk 0.00cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in Automatic < 3.135.1 versions.
- risk 0.00cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in Blog2Social <= 8.9.2 versions.
- risk 0.00cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in Customer Reviews for WooCommerce <= 5.110.1 versions.
- risk 0.00cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in Responsive Lightbox <= 2.7.6 versions.
- risk 0.00cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in Gutenverse Form <= 2.4.7 versions.
- risk 0.00cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in Quick Interest Slider <= 3.1.6 versions.
- risk 0.00cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in MapPress Maps for WordPress <= 2.97.3 versions.
- risk 0.00cvss 6.5epss 0.00
Contributor Cross Site Scripting (XSS) in BNE Testimonials <= 2.0.8 versions.
- risk 0.00cvss 6.5epss 0.00
Contributor Cross Site Scripting (XSS) in Image Carousel <= 1.0.0.41 versions.
- risk 0.00cvss 6.5epss 0.00
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tim Strifler Exclusive Addons Elementor allows Stored XSS. This issue affects Exclusive Addons Elementor: from n/a through 2.7.9.8.
- risk 0.00cvss 4.8epss 0.00
Server-Side Request Forgery in the markdown_to_pdf action of Rapid7 InsightConnect Markdown Plugin on Linux in versions prior to 4.0.2 allows remote attackers to make arbitrary outbound HTTP requests via unsanitized resource-loading HTML elements (img/src, CSS url(), @import)…
- risk 0.00cvss 6.1epss 0.00
A missing sanitisation vulnerability exists with user input in the stats-video.php script. The way URLs to this script were constructed did not follow best practices, and the output of the Smarty custom helper function url was neither properly encoded nor sanitised, allowing…
- risk 0.00cvss 5.4epss 0.00
A stored XSS vulnerabilities exists in the `maintenance-acl-check.php` and `maintenance-banners-check.php` tools of Revive Adserver 6.0.7. The issue was caused by entity names being displayed without proper escaping when inconsistencies were detected. Whether the XSS payload is…