VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (46,817)

page 283 of 2,341
  • CVE-2016-7851MedNov 8, 2016
    risk 0.43cvss 6.1epss 0.07

    Adobe Connect version 9.5.6 and earlier does not adequately validate input in the events registration module. This vulnerability could be exploited in cross-site scripting attacks.

  • CVE-2015-8398MedApr 11, 2016
    risk 0.43cvss 6.1epss 0.02

    Cross-site scripting (XSS) vulnerability in Atlassian Confluence before 5.8.17 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to rest/prototype/1/session/check.

  • CVE-2016-2279MedMar 2, 2016
    risk 0.43cvss 6.1epss 0.08

    Cross-site scripting (XSS) vulnerability in the web server in Rockwell Automation Allen-Bradley CompactLogix 1769-L* before 28.011+ allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2015-7252MedDec 30, 2015
    risk 0.43cvss 6.1epss 0.03

    Cross-site scripting (XSS) vulnerability in cgi-bin/webproc on ZTE ZXHN H108N R1A devices before ZTE.bhs.ZXHNH108NR1A.k_PE allows remote attackers to inject arbitrary web script or HTML via the errorpage parameter.

  • CVE-2009-2216MedJun 25, 2009
    risk 0.43cvss 6.1epss 0.02

    Cross-site scripting (XSS) vulnerability in CMD_REDIRECT in DirectAdmin 1.33.6 and earlier allows remote attackers to inject arbitrary web script or HTML via the URI in a view=advanced request.

  • CVE-2008-3937MedSep 5, 2008
    risk 0.43cvss 6.1epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in Open Media Collectors Database (OpenDb) 1.0.6 allow remote attackers to inject arbitrary web script or HTML via the (1) user_id parameter in an edit action to user_admin.php, the (2) title parameter to listings.php, and the…

  • CVE-2007-5954MedNov 14, 2007
    risk 0.43cvss 6.1epss 0.01

    Cross-site scripting (XSS) vulnerability in buscador.php in JLMForo System allows remote attackers to inject arbitrary web script or HTML via the clave parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

  • CVE-2007-5817MedNov 5, 2007
    risk 0.43cvss 6.1epss 0.01

    dialog.php in CONTENTCustomizer 3.1mp and earlier allows remote attackers to perform certain privileged actions via a (1) del, (2) delbackup, (3) res, or (4) ren action. NOTE: this issue can be leveraged to conduct cross-site scripting (XSS) and possibly other attacks.

  • CVE-2006-5847MedNov 10, 2006
    risk 0.43cvss 6.1epss 0.02

    Cross-site scripting (XSS) vulnerability in index.php in FreeWebshop 2.2.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the cat parameter.

  • CVE-2026-76573MedSep 5, 2026
    risk 0.42cvss 6.4epss 0.00

    The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'not_found' Shortcode Attribute in all versions up to, and including, 3.3.9.1 due to insufficient input sanitization and output escaping. This makes it possible for…

  • CVE-2026-18404MedSep 5, 2026
    risk 0.42cvss 6.4epss 0.00

    The Social Chat – Click To Chat App Button plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'consent_message' JSON Attribute in .qlwapp data-box in all versions up to, and including, 8.6.2 due to insufficient input sanitization and output escaping. This…

  • CVE-2026-27086MedSep 4, 2026
    risk 0.42cvss 6.5epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Xtemos WoodMart allows DOM-Based XSS. This issue affects WoodMart: from n/a before 8.3.8.

  • CVE-2026-85303MedSep 3, 2026
    risk 0.42cvss 6.5epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Magepeople inc. Booking and Rental Manager allows Stored XSS. This issue affects Booking and Rental Manager: from n/a through 2.7.7.

  • CVE-2026-85302MedSep 3, 2026
    risk 0.42cvss 6.5epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPKoi WordPress Themes WPKoi Templates for Elementor allows DOM-Based XSS. This issue affects WPKoi Templates for Elementor: from n/a through 3.7.2.

  • CVE-2026-81282MedSep 3, 2026
    risk 0.42cvss 6.5epss 0.00

    Subscriber Cross Site Scripting (XSS) in Product Variations Swatches for WooCommerce <= 1.1.18 versions.

  • CVE-2026-81281MedSep 3, 2026
    risk 0.42cvss 6.5epss 0.00

    Subscriber Cross Site Scripting (XSS) in Graphene <= 2.9.4 versions.

  • CVE-2026-3852MedSep 3, 2026
    risk 0.42cvss 6.4epss 0.00

    The Divi theme for WordPress is vulnerable to Stored Cross-Site Scripting via the `skype_url` shortcode attribute of the Social Media Follow module in all versions up to, and including, 4.27.6. This is due to a three-part sanitization failure: (1) the `skype_url` field is not…

  • CVE-2026-75134MedSep 2, 2026
    risk 0.42cvss 6.4epss 0.00

    SEOWriting plugin for WordPress through 1.12.5 contains a stored cross-site scripting vulnerability that allows authenticated contributors to inject malicious JavaScript by exploiting an overly permissive KSES allowlist that explicitly permits the onload event handler on iframe…

  • CVE-2026-84781MedSep 2, 2026
    risk 0.42cvss 6.5epss 0.00

    Contributor Cross Site Scripting (XSS) in Gallery PhotoBlocks <= 1.3.4 versions.

  • CVE-2026-83562MedSep 2, 2026
    risk 0.42cvss 6.5epss 0.00

    Contributor Cross Site Scripting (XSS) in WCFM Marketplace <= 3.8.2 versions.