CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Description
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85
CVEs mapped to this weakness (46,817)
page 2052 of 2,341| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-50740 | Med | 0.00 | 5.4 | 0.00 | Jun 26, 2026 | A missing sanitisation vulnerability of user input in the zone-include.php script exists in Revive Adserver 6.0.7 and earlier. A low‑privileged user could exploit the refresh parameter of the iFrame invocation tag to perform reflected XSS attacks. | ||
| CVE-2026-54025 | Med | 0.00 | 5.4 | 0.00 | Jun 25, 2026 | LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. Prior to 0.8.4-rc1, there is a vulnerability in LibreChat's markdown artifact preview pipeline. The marked library v15.0.12 does not HTML-escape double-quote characters in image alt text when a custom… | ||
| CVE-2026-48942 | Med | 0.00 | 6.1 | 0.00 | Jun 25, 2026 | K2 ≤ 2.26 renders the `#__k2_users.image` column directly into HTML `src` attributes via two distinct templates, in both cases without HTML escaping. | ||
| CVE-2026-48940 | Low | 0.00 | 3.4 | 0.00 | Jun 25, 2026 | A Joomla user with K2 "create item" rights (Author tier by default) can submit an article whose `embedVideo` POST field contains a raw `` tag; K2 stores it verbatim and renders it unescaped to any visitor of the article page. | ||
| CVE-2026-56071 | Hig | 0.00 | 7.1 | 0.00 | Jun 25, 2026 | Unauthenticated Cross Site Scripting (XSS) in Forminator <= 1.53.1 versions. | ||
| CVE-2026-56051 | Hig | 0.00 | 7.1 | 0.00 | Jun 25, 2026 | Unauthenticated Cross Site Scripting (XSS) in TablePress <= 3.3.1 versions. | ||
| CVE-2026-56042 | Hig | 0.00 | 7.1 | 0.00 | Jun 25, 2026 | Customer Cross Site Scripting (XSS) in Advanced Order Export For WooCommerce <= 4.0.9 versions. | ||
| CVE-2026-56014 | Hig | 0.00 | 7.1 | 0.00 | Jun 25, 2026 | Unauthenticated Cross Site Scripting (XSS) in Master Slider <= 3.11.2 versions. | ||
| CVE-2026-56006 | Hig | 0.00 | 7.1 | 0.00 | Jun 25, 2026 | Unauthenticated Cross Site Scripting (XSS) in H5P <= 1.17.6 versions. | ||
| CVE-2026-56005 | Hig | 0.00 | 7.1 | 0.00 | Jun 25, 2026 | Subscriber Cross Site Scripting (XSS) in WP Activity Log <= 5.6.3.1 versions. | ||
| CVE-2026-10712 | Hig | 0.00 | 8.0 | 0.00 | Jun 25, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.10 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed an unauthenticated user to execute arbitrary JavaScript in a user's browser session due to… | ||
| CVE-2026-10086 | Hig | 0.00 | 8.7 | 0.00 | Jun 25, 2026 | GitLab has remediated an issue in GitLab EE affecting all versions from 16.4 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed an authenticated user with developer-role permissions to execute arbitrary client-side code in… | ||
| CVE-2026-10833 | Med | 0.00 | 6.4 | 0.00 | Jun 25, 2026 | The Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'configurablePrefix' Block Attribute in all versions up to, and including, 6.1.4 due to insufficient input sanitization and… | ||
| CVE-2026-44960 | — | Non | 0.00 | 0.0 | 0.00 | Jun 23, 2026 | A stored XSS can be exploited by leveraging the usernames as an attack vector. When an admin user viewed the audit log details for affected entries, any malicious JavaScript payload embedded in the username would be executed due to missing output sanitisation. Proper escaping… | |
| CVE-2026-44956 | — | Non | 0.00 | 0.0 | 0.00 | Jun 23, 2026 | Low‑privileged users could use their Full Name as a vector for a stored XSS attack. The name is included in system‑generated emails, whose content is stored in the details field of the userlog table. An admin user viewing the email content through userlog-details.php would… | |
| CVE-2026-34915 | Med | 0.00 | 6.1 | 0.00 | Jun 23, 2026 | A missing sanitisation of user input in the zone-include.php script of Revive Adserver 6.0.6 and earlier could allow a low‑privileged user to exploit the clientid parameter to perform blind SQL injection attacks. Input sanitisation has been improved to ensure that all… | ||
| CVE-2026-11772 | Med | 0.00 | — | 0.01 | Jun 23, 2026 | DRIMO CMS is vulnerable to Reflected XSS via q parameter in searching functionality. An attacker can prepare an URL that, when opened, results in arbitrary JavaScript execution in the victim's browser. Product is in End Of Life phase and will not receive any updates. However,… | ||
| CVE-2026-10857 | Med | 0.00 | 6.1 | 0.00 | Jun 23, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in AKIN Software Computer Import Export Industry and Trade Ltd. E-Commerce allows Reflected XSS. This issue affects e-Commerce: before 1.25.01.06. | ||
| CVE-2026-11994 | Med | 0.00 | — | 0.00 | Jun 22, 2026 | Akaunting 3.1.21 contains an authenticated stored Cross-Site Scripting vulnerability in the report management workflow. A user with permission to create or update reports can store arbitrary HTML/JavaScript in the description field of a report. | ||
| CVE-2026-11943 | Med | 0.00 | — | 0.00 | Jun 22, 2026 | Akaunting 3.1.21 contains an authenticated stored cross-site scripting vulnerability in the document timeline shown on invoice and bill detail pages. An authenticated user can store HTML/JavaScript in their own profile name. |
- risk 0.00cvss 5.4epss 0.00
A missing sanitisation vulnerability of user input in the zone-include.php script exists in Revive Adserver 6.0.7 and earlier. A low‑privileged user could exploit the refresh parameter of the iFrame invocation tag to perform reflected XSS attacks.
- risk 0.00cvss 5.4epss 0.00
LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. Prior to 0.8.4-rc1, there is a vulnerability in LibreChat's markdown artifact preview pipeline. The marked library v15.0.12 does not HTML-escape double-quote characters in image alt text when a custom…
- risk 0.00cvss 6.1epss 0.00
K2 ≤ 2.26 renders the `#__k2_users.image` column directly into HTML `src` attributes via two distinct templates, in both cases without HTML escaping.
- risk 0.00cvss 3.4epss 0.00
A Joomla user with K2 "create item" rights (Author tier by default) can submit an article whose `embedVideo` POST field contains a raw `` tag; K2 stores it verbatim and renders it unescaped to any visitor of the article page.
- risk 0.00cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in Forminator <= 1.53.1 versions.
- risk 0.00cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in TablePress <= 3.3.1 versions.
- risk 0.00cvss 7.1epss 0.00
Customer Cross Site Scripting (XSS) in Advanced Order Export For WooCommerce <= 4.0.9 versions.
- risk 0.00cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in Master Slider <= 3.11.2 versions.
- risk 0.00cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in H5P <= 1.17.6 versions.
- risk 0.00cvss 7.1epss 0.00
Subscriber Cross Site Scripting (XSS) in WP Activity Log <= 5.6.3.1 versions.
- risk 0.00cvss 8.0epss 0.00
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.10 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed an unauthenticated user to execute arbitrary JavaScript in a user's browser session due to…
- risk 0.00cvss 8.7epss 0.00
GitLab has remediated an issue in GitLab EE affecting all versions from 16.4 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed an authenticated user with developer-role permissions to execute arbitrary client-side code in…
- risk 0.00cvss 6.4epss 0.00
The Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'configurablePrefix' Block Attribute in all versions up to, and including, 6.1.4 due to insufficient input sanitization and…
- risk 0.00cvss 0.0epss 0.00
A stored XSS can be exploited by leveraging the usernames as an attack vector. When an admin user viewed the audit log details for affected entries, any malicious JavaScript payload embedded in the username would be executed due to missing output sanitisation. Proper escaping…
- risk 0.00cvss 0.0epss 0.00
Low‑privileged users could use their Full Name as a vector for a stored XSS attack. The name is included in system‑generated emails, whose content is stored in the details field of the userlog table. An admin user viewing the email content through userlog-details.php would…
- risk 0.00cvss 6.1epss 0.00
A missing sanitisation of user input in the zone-include.php script of Revive Adserver 6.0.6 and earlier could allow a low‑privileged user to exploit the clientid parameter to perform blind SQL injection attacks. Input sanitisation has been improved to ensure that all…
- risk 0.00cvss —epss 0.01
DRIMO CMS is vulnerable to Reflected XSS via q parameter in searching functionality. An attacker can prepare an URL that, when opened, results in arbitrary JavaScript execution in the victim's browser. Product is in End Of Life phase and will not receive any updates. However,…
- risk 0.00cvss 6.1epss 0.00
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in AKIN Software Computer Import Export Industry and Trade Ltd. E-Commerce allows Reflected XSS. This issue affects e-Commerce: before 1.25.01.06.
- risk 0.00cvss —epss 0.00
Akaunting 3.1.21 contains an authenticated stored Cross-Site Scripting vulnerability in the report management workflow. A user with permission to create or update reports can store arbitrary HTML/JavaScript in the description field of a report.
- risk 0.00cvss —epss 0.00
Akaunting 3.1.21 contains an authenticated stored cross-site scripting vulnerability in the document timeline shown on invoice and bill detail pages. An authenticated user can store HTML/JavaScript in their own profile name.