VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (46,607)

page 25 of 2,331
  • CVE-2026-16617HigAug 19, 2026
    risk 0.57cvss 8.8epss 0.00

    The Simple File List WordPress plugin through 6.3.11 does not properly sanitise and escape a file's description before outputting it on the public file list, allowing unauthenticated users (when front-end file management is enabled) to perform Stored Cross-Site Scripting attacks…

  • CVE-2026-14334HigAug 19, 2026
    risk 0.57cvss 8.8epss 0.00

    The Booking calendar, Appointment Booking System WordPress plugin through 3.2.36 does not properly sanitize uploaded SVG files, allowing unauthenticated attackers to upload a file that bypasses the Booking calendar, Appointment Booking System WordPress plugin through 3.2.36's…

  • CVE-2026-73329HigAug 12, 2026
    risk 0.57cvss 8.7epss 0.00

    CamaleonCMS contains a stored cross-site scripting vulnerability that allows authenticated low-privileged users to execute arbitrary JavaScript in an administrator's browser by injecting unsanitized HTML payloads into the post title parameter during draft creation. Attackers can…

  • CVE-2026-15217HigAug 12, 2026
    risk 0.57cvss 8.7epss 0.00

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed cross-site scripting due to improper neutralization of user-controlled values rendered in…

  • CVE-2026-15216HigAug 12, 2026
    risk 0.57cvss 8.7epss 0.00

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed cross-site scripting due to improper neutralization of user-controlled data rendered in…

  • CVE-2026-48413HigAug 11, 2026
    risk 0.57cvss 8.7epss 0.01

    Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page…

  • CVE-2026-65767HigAug 11, 2026
    risk 0.57cvss 8.8epss 0.00

    Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Teams for Android allows an authorized attacker to perform spoofing over a network.

  • CVE-2026-57104HigAug 11, 2026
    risk 0.57cvss 8.8epss 0.01

    Improper neutralization of input during web page generation ('cross-site scripting') in Azure Storage Explorer allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2026-14293HigAug 10, 2026
    risk 0.57cvss 8.8epss 0.00

    The Autopay WordPress plugin before 5.0.1 does not perform any capability or nonce check before saving a styling option from a public request, and does not escape that value when it is later output on the checkout page, allowing unauthenticated attackers to store JavaScript that…

  • CVE-2026-66494HigAug 7, 2026
    risk 0.57cvss epss 0.00

    Joomla Extension - joomshaper.com - Unauthenticated stored XSS in Shapes API endpoint SP Page Builder < 6.7.0 - An unauthenticated attacker can store malicious JavaScript in a Joomla site's database via a single HTTP request. When an administrator opens the SP Page Builder…

  • CVE-2024-39024HigAug 6, 2026
    risk 0.57cvss 8.8epss 0.01

    In Packetfence 13.2.0, the WebGui interface setting allows authenticated remote code execution.

  • CVE-2026-71236HigAug 5, 2026
    risk 0.57cvss 8.7epss 0.00

    Grocy's API request-body parser (controllers/Api/BaseApiController.php, GetParsedAndFilteredRequestBody) purifies incoming field values with HTMLPurifier, then manually reverses HTML-entity encoding of the resulting output by replacing &lt;, &gt;, and &amp; back to…

  • CVE-2026-71233HigAug 5, 2026
    risk 0.57cvss 8.7epss 0.00

    InvoiceNinja v5-stable renders an invoice or quote's "terms" field in the client portal using Laravel Blade's raw output directive {!! ->terms !!} (resources/views/portal/ninja2020/invoices/includes/terms.blade.php) with no HTML sanitization.

  • CVE-2026-13609HigJul 31, 2026
    risk 0.57cvss 8.8epss 0.00

    The Frontend Admin by DynamiApps WordPress plugin before 3.29.9 decodes HTML entities in a submitted form field value after sanitizing it, which restores HTML tags that the sanitizer had neutralized. A double-encoded payload submitted by an unauthenticated visitor is therefore…

  • CVE-2026-45270HigJul 20, 2026
    risk 0.57cvss 8.7epss 0.00

    CI4MS is a CodeIgniter 4-based content management system skeleton. Prior to version 0.31.9.0, the `Pages` backend module registers the `html_purify` validation rule on language-keyed page content but persists the raw, un-purified POST value into the database. The public renderer…

  • CVE-2026-47994HigJul 14, 2026
    risk 0.57cvss 8.7epss 0.01

    Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page…

  • CVE-2026-28737HigJul 3, 2026
    risk 0.57cvss 8.7epss 0.00

    Gitea versions from 1.25.0 before 1.26.0 allow stored cross-site scripting through the extensionsRequired field in glTF files rendered by the 3D file viewer.

  • CVE-2026-48307HigJun 30, 2026
    risk 0.57cvss 8.8epss 0.01

    ColdFusion versions 2025.9, 2023.20 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this vulnerability to inject malicious scripts into a web page, potentially resulting in arbitrary code execution in the context of the…

  • CVE-2026-9780HigJun 25, 2026
    risk 0.57cvss 8.8epss 0.01

    Quest NetVault Backup addclient3 Cross-Site Scripting Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of Quest NetVault Backup. User interaction is required to exploit this vulnerability in that…

  • CVE-2026-7569HigJun 25, 2026
    risk 0.57cvss 8.8epss 0.01

    Quest NetVault Backup viewclient Cross-Site Scripting Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of Quest NetVault Backup. User interaction is required to exploit this vulnerability in that…