CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Description
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85
CVEs mapped to this weakness (46,817)
page 285 of 2,341| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-18100 | Med | 0.42 | 6.4 | 0.00 | Aug 25, 2026 | The MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'mf_form_id' Widget Setting in all versions up to, and including, 4.1.8 due to insufficient input sanitization and output… | ||
| CVE-2026-12561 | Med | 0.42 | 6.4 | 0.00 | Aug 25, 2026 | The tagDiv Composer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the vc_raw_html shortcode in all versions up to and including 5.4.5. This is due to insufficient input sanitization and output escaping in the vc_raw_html::render() method, which… | ||
| CVE-2026-76063 | Med | 0.42 | 6.4 | 0.00 | Aug 25, 2026 | The FundEngine – Donation and Crowdfunding Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wfp_featured_video_url' parameter in all versions up to, and including, 1.8.1 due to insufficient input sanitization and output escaping. This makes… | ||
| CVE-2026-19943 | Med | 0.42 | 6.4 | 0.00 | Aug 25, 2026 | The Gutenverse – WordPress Blocks, Page Builder & Site Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'titleTag' Block Attribute in all versions up to, and including, 4.0.2 due to insufficient input sanitization and output escaping. This makes it… | ||
| CVE-2026-75019 | Med | 0.42 | 6.4 | 0.00 | Aug 25, 2026 | The Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 700+ Patterns, 58 Blocks & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via cozyHoverEffect Block Attribute in all versions up to, and including, 2.2.16 due to insufficient input… | ||
| CVE-2025-9878 | Med | 0.42 | 6.4 | 0.00 | Aug 25, 2026 | The PPWP – Password Protect WordPress | #1 Most-Reviewed Password Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ppwp' shortcode in all versions up to, and including, 1.9.21 due to insufficient input sanitization and output escaping… | ||
| CVE-2026-78290 | Med | 0.42 | 6.5 | 0.00 | Aug 24, 2026 | Contributor Cross Site Scripting (XSS) in Magazine Blocks <= 1.8.6 versions. | ||
| CVE-2026-65644 | Hig | 0.42 | 7.5 | 0.00 | Aug 21, 2026 | Rocket.Chat in versions before 8.8.0, 8.7.1, 8.6.2, 8.5.3, 8.4.6, 8.3.8, 8.2.8, 8.1.8, and 7.10.15 has a REST API endpoint POST /api/v1/livechat/visitor that accepts an unauthenticated, unsanitized name field for Livechat visitors. This name is stored raw and later rendered via… | ||
| CVE-2026-73402 | Med | 0.42 | 6.5 | 0.00 | Aug 20, 2026 | Subscriber Cross Site Scripting (XSS) in WP BASE Booking <= 6.3.2 versions. | ||
| CVE-2026-66601 | Med | 0.42 | 6.5 | 0.00 | Aug 20, 2026 | Subscriber Cross Site Scripting (XSS) in Media LIbrary Assistant <= 3.39 versions. | ||
| CVE-2026-68900 | Hig | 0.42 | 7.6 | 0.00 | Aug 19, 2026 | Wekan is open source kanban built with Meteor. From 8.72 until 10.23, addBoardHTMLToZip() in client/lib/exportHTML.js read a card title and body through textContent, which decoded entity-encoded markup, and then interpolated titleText and allText into content.innerHTML in the… | ||
| CVE-2026-15421 | Med | 0.42 | 6.4 | 0.00 | Aug 19, 2026 | The Speed Optimizer – The All-In-One Performance-Boosting Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Image Tag Attributes in all versions up to, and including, 7.8.0 due to insufficient input sanitization and output escaping. This makes it… | ||
| CVE-2026-66591 | Med | 0.42 | 6.5 | 0.00 | Aug 18, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in David Lingren Media LIbrary Assistant allows Stored XSS. This issue affects Media LIbrary Assistant: from n/a through 3.39. | ||
| CVE-2026-73336 | Med | 0.42 | 6.4 | 0.00 | Aug 18, 2026 | Joomla! Core - [20260806] - XSS through schema.org outputs in Joomla 5.1.0-5.4.7, 6.0.0-6.1.2 - Improper escaping flags lead to an XSS vector in schema.org markup outputs. | ||
| CVE-2026-73359 | Med | 0.42 | 6.5 | 0.00 | Aug 18, 2026 | Subscriber Cross Site Scripting (XSS) in WP Cookie Notice for GDPR, CCPA & ePrivacy Consent <= 4.3.9 versions. | ||
| CVE-2026-68565 | Med | 0.42 | 6.5 | 0.00 | Aug 18, 2026 | Contributor Cross Site Scripting (XSS) in GeoDirectory <= 2.8.172 versions. | ||
| CVE-2026-66646 | Med | 0.42 | 6.5 | 0.00 | Aug 18, 2026 | Contributor Cross Site Scripting (XSS) in WP Tab Widget <= 1.2.11 versions. | ||
| CVE-2026-66645 | Med | 0.42 | 6.5 | 0.00 | Aug 18, 2026 | Contributor Cross Site Scripting (XSS) in Table Of Contents Block <= 1.5.0 versions. | ||
| CVE-2026-66644 | Med | 0.42 | 6.5 | 0.00 | Aug 18, 2026 | Contributor Cross Site Scripting (XSS) in Typing Effect <= 1.3.7 versions. | ||
| CVE-2026-66643 | Med | 0.42 | 6.5 | 0.00 | Aug 18, 2026 | Contributor Cross Site Scripting (XSS) in Wufoo Shortcode <= 1.55 versions. |
- risk 0.42cvss 6.4epss 0.00
The MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'mf_form_id' Widget Setting in all versions up to, and including, 4.1.8 due to insufficient input sanitization and output…
- risk 0.42cvss 6.4epss 0.00
The tagDiv Composer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the vc_raw_html shortcode in all versions up to and including 5.4.5. This is due to insufficient input sanitization and output escaping in the vc_raw_html::render() method, which…
- risk 0.42cvss 6.4epss 0.00
The FundEngine – Donation and Crowdfunding Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wfp_featured_video_url' parameter in all versions up to, and including, 1.8.1 due to insufficient input sanitization and output escaping. This makes…
- risk 0.42cvss 6.4epss 0.00
The Gutenverse – WordPress Blocks, Page Builder & Site Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'titleTag' Block Attribute in all versions up to, and including, 4.0.2 due to insufficient input sanitization and output escaping. This makes it…
- risk 0.42cvss 6.4epss 0.00
The Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 700+ Patterns, 58 Blocks & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via cozyHoverEffect Block Attribute in all versions up to, and including, 2.2.16 due to insufficient input…
- risk 0.42cvss 6.4epss 0.00
The PPWP – Password Protect WordPress | #1 Most-Reviewed Password Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ppwp' shortcode in all versions up to, and including, 1.9.21 due to insufficient input sanitization and output escaping…
- risk 0.42cvss 6.5epss 0.00
Contributor Cross Site Scripting (XSS) in Magazine Blocks <= 1.8.6 versions.
- risk 0.42cvss 7.5epss 0.00
Rocket.Chat in versions before 8.8.0, 8.7.1, 8.6.2, 8.5.3, 8.4.6, 8.3.8, 8.2.8, 8.1.8, and 7.10.15 has a REST API endpoint POST /api/v1/livechat/visitor that accepts an unauthenticated, unsanitized name field for Livechat visitors. This name is stored raw and later rendered via…
- risk 0.42cvss 6.5epss 0.00
Subscriber Cross Site Scripting (XSS) in WP BASE Booking <= 6.3.2 versions.
- risk 0.42cvss 6.5epss 0.00
Subscriber Cross Site Scripting (XSS) in Media LIbrary Assistant <= 3.39 versions.
- risk 0.42cvss 7.6epss 0.00
Wekan is open source kanban built with Meteor. From 8.72 until 10.23, addBoardHTMLToZip() in client/lib/exportHTML.js read a card title and body through textContent, which decoded entity-encoded markup, and then interpolated titleText and allText into content.innerHTML in the…
- risk 0.42cvss 6.4epss 0.00
The Speed Optimizer – The All-In-One Performance-Boosting Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Image Tag Attributes in all versions up to, and including, 7.8.0 due to insufficient input sanitization and output escaping. This makes it…
- risk 0.42cvss 6.5epss 0.00
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in David Lingren Media LIbrary Assistant allows Stored XSS. This issue affects Media LIbrary Assistant: from n/a through 3.39.
- risk 0.42cvss 6.4epss 0.00
Joomla! Core - [20260806] - XSS through schema.org outputs in Joomla 5.1.0-5.4.7, 6.0.0-6.1.2 - Improper escaping flags lead to an XSS vector in schema.org markup outputs.
- risk 0.42cvss 6.5epss 0.00
Subscriber Cross Site Scripting (XSS) in WP Cookie Notice for GDPR, CCPA & ePrivacy Consent <= 4.3.9 versions.
- risk 0.42cvss 6.5epss 0.00
Contributor Cross Site Scripting (XSS) in GeoDirectory <= 2.8.172 versions.
- risk 0.42cvss 6.5epss 0.00
Contributor Cross Site Scripting (XSS) in WP Tab Widget <= 1.2.11 versions.
- risk 0.42cvss 6.5epss 0.00
Contributor Cross Site Scripting (XSS) in Table Of Contents Block <= 1.5.0 versions.
- risk 0.42cvss 6.5epss 0.00
Contributor Cross Site Scripting (XSS) in Typing Effect <= 1.3.7 versions.
- risk 0.42cvss 6.5epss 0.00
Contributor Cross Site Scripting (XSS) in Wufoo Shortcode <= 1.55 versions.