VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (46,817)

page 2052 of 2,341
  • CVE-2026-50740MedJun 26, 2026
    risk 0.00cvss 5.4epss 0.00

    A missing sanitisation vulnerability of user input in the zone-include.php script exists in Revive Adserver 6.0.7 and earlier. A low‑privileged user could exploit the refresh parameter of the iFrame invocation tag to perform reflected XSS attacks.

  • CVE-2026-54025MedJun 25, 2026
    risk 0.00cvss 5.4epss 0.00

    LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. Prior to 0.8.4-rc1, there is a vulnerability in LibreChat's markdown artifact preview pipeline. The marked library v15.0.12 does not HTML-escape double-quote characters in image alt text when a custom…

  • CVE-2026-48942MedJun 25, 2026
    risk 0.00cvss 6.1epss 0.00

    K2 ≤ 2.26 renders the `#__k2_users.image` column directly into HTML `src` attributes via two distinct templates, in both cases without HTML escaping.

  • CVE-2026-48940LowJun 25, 2026
    risk 0.00cvss 3.4epss 0.00

    A Joomla user with K2 "create item" rights (Author tier by default) can submit an article whose `embedVideo` POST field contains a raw `` tag; K2 stores it verbatim and renders it unescaped to any visitor of the article page.

  • CVE-2026-56071HigJun 25, 2026
    risk 0.00cvss 7.1epss 0.00

    Unauthenticated Cross Site Scripting (XSS) in Forminator <= 1.53.1 versions.

  • CVE-2026-56051HigJun 25, 2026
    risk 0.00cvss 7.1epss 0.00

    Unauthenticated Cross Site Scripting (XSS) in TablePress <= 3.3.1 versions.

  • CVE-2026-56042HigJun 25, 2026
    risk 0.00cvss 7.1epss 0.00

    Customer Cross Site Scripting (XSS) in Advanced Order Export For WooCommerce <= 4.0.9 versions.

  • CVE-2026-56014HigJun 25, 2026
    risk 0.00cvss 7.1epss 0.00

    Unauthenticated Cross Site Scripting (XSS) in Master Slider <= 3.11.2 versions.

  • CVE-2026-56006HigJun 25, 2026
    risk 0.00cvss 7.1epss 0.00

    Unauthenticated Cross Site Scripting (XSS) in H5P <= 1.17.6 versions.

  • CVE-2026-56005HigJun 25, 2026
    risk 0.00cvss 7.1epss 0.00

    Subscriber Cross Site Scripting (XSS) in WP Activity Log <= 5.6.3.1 versions.

  • CVE-2026-10712HigJun 25, 2026
    risk 0.00cvss 8.0epss 0.00

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.10 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed an unauthenticated user to execute arbitrary JavaScript in a user's browser session due to…

  • CVE-2026-10086HigJun 25, 2026
    risk 0.00cvss 8.7epss 0.00

    GitLab has remediated an issue in GitLab EE affecting all versions from 16.4 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed an authenticated user with developer-role permissions to execute arbitrary client-side code in…

  • CVE-2026-10833MedJun 25, 2026
    risk 0.00cvss 6.4epss 0.00

    The Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'configurablePrefix' Block Attribute in all versions up to, and including, 6.1.4 due to insufficient input sanitization and…

  • CVE-2026-44960NonJun 23, 2026
    risk 0.00cvss 0.0epss 0.00

    A stored XSS can be exploited by leveraging the usernames as an attack vector. When an admin user viewed the audit log details for affected entries, any malicious JavaScript payload embedded in the username would be executed due to missing output sanitisation. Proper escaping…

  • CVE-2026-44956NonJun 23, 2026
    risk 0.00cvss 0.0epss 0.00

    Low‑privileged users could use their Full Name as a vector for a stored XSS attack. The name is included in system‑generated emails, whose content is stored in the details field of the userlog table. An admin user viewing the email content through userlog-details.php would…

  • CVE-2026-34915MedJun 23, 2026
    risk 0.00cvss 6.1epss 0.00

    A missing sanitisation of user input in the zone-include.php script of Revive Adserver 6.0.6 and earlier could allow a low‑privileged user to exploit the clientid parameter to perform blind SQL injection attacks. Input sanitisation has been improved to ensure that all…

  • CVE-2026-11772MedJun 23, 2026
    risk 0.00cvss epss 0.01

    DRIMO CMS is vulnerable to Reflected XSS via q parameter in searching functionality. An attacker can prepare an URL that, when opened, results in arbitrary JavaScript execution in the victim's browser. Product is in End Of Life phase and will not receive any updates. However,…

  • CVE-2026-10857MedJun 23, 2026
    risk 0.00cvss 6.1epss 0.00

    Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in AKIN Software Computer Import Export Industry and Trade Ltd. E-Commerce allows Reflected XSS. This issue affects e-Commerce: before 1.25.01.06.

  • CVE-2026-11994MedJun 22, 2026
    risk 0.00cvss epss 0.00

    Akaunting 3.1.21 contains an authenticated stored Cross-Site Scripting vulnerability in the report management workflow. A user with permission to create or update reports can store arbitrary HTML/JavaScript in the description field of a report.

  • CVE-2026-11943MedJun 22, 2026
    risk 0.00cvss epss 0.00

    Akaunting 3.1.21 contains an authenticated stored cross-site scripting vulnerability in the document timeline shown on invoice and bill detail pages. An authenticated user can store HTML/JavaScript in their own profile name.