VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (46,817)

page 285 of 2,341
  • CVE-2026-18100MedAug 25, 2026
    risk 0.42cvss 6.4epss 0.00

    The MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'mf_form_id' Widget Setting in all versions up to, and including, 4.1.8 due to insufficient input sanitization and output…

  • CVE-2026-12561MedAug 25, 2026
    risk 0.42cvss 6.4epss 0.00

    The tagDiv Composer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the vc_raw_html shortcode in all versions up to and including 5.4.5. This is due to insufficient input sanitization and output escaping in the vc_raw_html::render() method, which…

  • CVE-2026-76063MedAug 25, 2026
    risk 0.42cvss 6.4epss 0.00

    The FundEngine – Donation and Crowdfunding Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wfp_featured_video_url' parameter in all versions up to, and including, 1.8.1 due to insufficient input sanitization and output escaping. This makes…

  • CVE-2026-19943MedAug 25, 2026
    risk 0.42cvss 6.4epss 0.00

    The Gutenverse – WordPress Blocks, Page Builder & Site Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'titleTag' Block Attribute in all versions up to, and including, 4.0.2 due to insufficient input sanitization and output escaping. This makes it…

  • CVE-2026-75019MedAug 25, 2026
    risk 0.42cvss 6.4epss 0.00

    The Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 700+ Patterns, 58 Blocks & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via cozyHoverEffect Block Attribute in all versions up to, and including, 2.2.16 due to insufficient input…

  • CVE-2025-9878MedAug 25, 2026
    risk 0.42cvss 6.4epss 0.00

    The PPWP – Password Protect WordPress | #1 Most-Reviewed Password Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ppwp' shortcode in all versions up to, and including, 1.9.21 due to insufficient input sanitization and output escaping…

  • CVE-2026-78290MedAug 24, 2026
    risk 0.42cvss 6.5epss 0.00

    Contributor Cross Site Scripting (XSS) in Magazine Blocks <= 1.8.6 versions.

  • CVE-2026-65644HigAug 21, 2026
    risk 0.42cvss 7.5epss 0.00

    Rocket.Chat in versions before 8.8.0, 8.7.1, 8.6.2, 8.5.3, 8.4.6, 8.3.8, 8.2.8, 8.1.8, and 7.10.15 has a REST API endpoint POST /api/v1/livechat/visitor that accepts an unauthenticated, unsanitized name field for Livechat visitors. This name is stored raw and later rendered via…

  • CVE-2026-73402MedAug 20, 2026
    risk 0.42cvss 6.5epss 0.00

    Subscriber Cross Site Scripting (XSS) in WP BASE Booking <= 6.3.2 versions.

  • CVE-2026-66601MedAug 20, 2026
    risk 0.42cvss 6.5epss 0.00

    Subscriber Cross Site Scripting (XSS) in Media LIbrary Assistant <= 3.39 versions.

  • CVE-2026-68900HigAug 19, 2026
    risk 0.42cvss 7.6epss 0.00

    Wekan is open source kanban built with Meteor. From 8.72 until 10.23, addBoardHTMLToZip() in client/lib/exportHTML.js read a card title and body through textContent, which decoded entity-encoded markup, and then interpolated titleText and allText into content.innerHTML in the…

  • CVE-2026-15421MedAug 19, 2026
    risk 0.42cvss 6.4epss 0.00

    The Speed Optimizer – The All-In-One Performance-Boosting Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Image Tag Attributes in all versions up to, and including, 7.8.0 due to insufficient input sanitization and output escaping. This makes it…

  • CVE-2026-66591MedAug 18, 2026
    risk 0.42cvss 6.5epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in David Lingren Media LIbrary Assistant allows Stored XSS. This issue affects Media LIbrary Assistant: from n/a through 3.39.

  • CVE-2026-73336MedAug 18, 2026
    risk 0.42cvss 6.4epss 0.00

    Joomla! Core - [20260806] - XSS through schema.org outputs in Joomla 5.1.0-5.4.7, 6.0.0-6.1.2 - Improper escaping flags lead to an XSS vector in schema.org markup outputs.

  • CVE-2026-73359MedAug 18, 2026
    risk 0.42cvss 6.5epss 0.00

    Subscriber Cross Site Scripting (XSS) in WP Cookie Notice for GDPR, CCPA & ePrivacy Consent <= 4.3.9 versions.

  • CVE-2026-68565MedAug 18, 2026
    risk 0.42cvss 6.5epss 0.00

    Contributor Cross Site Scripting (XSS) in GeoDirectory <= 2.8.172 versions.

  • CVE-2026-66646MedAug 18, 2026
    risk 0.42cvss 6.5epss 0.00

    Contributor Cross Site Scripting (XSS) in WP Tab Widget <= 1.2.11 versions.

  • CVE-2026-66645MedAug 18, 2026
    risk 0.42cvss 6.5epss 0.00

    Contributor Cross Site Scripting (XSS) in Table Of Contents Block <= 1.5.0 versions.

  • CVE-2026-66644MedAug 18, 2026
    risk 0.42cvss 6.5epss 0.00

    Contributor Cross Site Scripting (XSS) in Typing Effect <= 1.3.7 versions.

  • CVE-2026-66643MedAug 18, 2026
    risk 0.42cvss 6.5epss 0.00

    Contributor Cross Site Scripting (XSS) in Wufoo Shortcode <= 1.55 versions.