CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Description
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85
CVEs mapped to this weakness (46,817)
page 286 of 2,341| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-66641 | Med | 0.42 | 6.5 | 0.00 | Aug 18, 2026 | Contributor Cross Site Scripting (XSS) in Video Conferencing with Zoom <= 4.6.8 versions. | ||
| CVE-2026-66640 | Med | 0.42 | 6.5 | 0.00 | Aug 18, 2026 | Contributor Cross Site Scripting (XSS) in Login With Ajax <= 4.5.1 versions. | ||
| CVE-2026-66639 | Med | 0.42 | 6.5 | 0.00 | Aug 18, 2026 | Contributor Cross Site Scripting (XSS) in WPZOOM Forms – Contact Form Plugin for Gutenberg <= 2.0.4 versions. | ||
| CVE-2026-66638 | Med | 0.42 | 6.5 | 0.00 | Aug 18, 2026 | Contributor Cross Site Scripting (XSS) in Frontend Admin by DynamiApps <= 3.29.10 versions. | ||
| CVE-2026-66637 | Med | 0.42 | 6.5 | 0.00 | Aug 18, 2026 | Contributor Cross Site Scripting (XSS) in Featured Video Plus <= 2.3.3 versions. | ||
| CVE-2026-66636 | Med | 0.42 | 6.5 | 0.00 | Aug 18, 2026 | Contributor Cross Site Scripting (XSS) in Wise Chat <= 3.4 versions. | ||
| CVE-2026-75831 | Hig | 0.42 | 7.6 | 0.00 | Aug 18, 2026 | Grav before 2.0.15 contains a stored cross-site scripting vulnerability in the audio and video media rendering through the sourceParsedownElement method. The media URL fragment is concatenated unescaped into rawHtml source elements, allowing attackers to inject arbitrary HTML… | ||
| CVE-2026-2357 | Med | 0.42 | 6.4 | 0.00 | Aug 16, 2026 | The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bt_bb_shortcode' shortcode in all versions up to, and including, 5.6.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it… | ||
| CVE-2026-18402 | Med | 0.42 | 6.4 | 0.00 | Aug 16, 2026 | The SureDash – Community, Courses & Member Dashboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'draweropenverposition' Block/Shortcode Attribute in all versions up to, and including, 1.10.3 due to insufficient input sanitization and output escaping.… | ||
| CVE-2026-16758 | Med | 0.42 | 6.4 | 0.00 | Aug 16, 2026 | The Snippet Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in all versions up to, and including, 5.2.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | ||
| CVE-2026-15790 | Med | 0.42 | 6.4 | 0.00 | Aug 16, 2026 | The Youtube Showcase plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.0.4 via the 'emd_mb_meta' shortcode. This is due to insufficient input sanitization and output escaping on attachment titles referenced by the shortcode's… | ||
| CVE-2026-15604 | Med | 0.42 | 6.4 | 0.00 | Aug 16, 2026 | The Toocheke Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.10 via the 'series_bg_color' post meta field. This is due to insufficient input sanitization in the toocheke_series_bg_color_save() function (which stores… | ||
| CVE-2026-15726 | Med | 0.42 | 6.4 | 0.00 | Aug 16, 2026 | The Serious Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'theme' Shortcode Attribute in all versions up to, and including, 1.4.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | ||
| CVE-2026-15066 | Med | 0.42 | 6.4 | 0.00 | Aug 16, 2026 | The Loco Translate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via PO File Extracted Comments in all versions up to, and including, 2.8.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | ||
| CVE-2026-11780 | Med | 0.42 | 6.4 | 0.00 | Aug 16, 2026 | The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'question_title' parameter in all versions up to, and including, 11.2.1 due to insufficient input sanitization and output escaping. This… | ||
| CVE-2026-17090 | Med | 0.42 | 6.4 | 0.00 | Aug 15, 2026 | The Beaver Builder Page Builder – Drag and Drop Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Button Module 'button' (Button Code) Setting in all versions up to, and including, 2.10.2.2 due to insufficient input sanitization and output… | ||
| CVE-2026-15948 | Med | 0.42 | 6.4 | 0.00 | Aug 15, 2026 | The Hydra Booking — Appointment Scheduling & Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'first_name' parameter in all versions up to, and including, 1.2.2 due to insufficient input sanitization and output escaping. This makes it… | ||
| CVE-2026-73357 | Med | 0.42 | 6.5 | 0.00 | Aug 13, 2026 | Donor Cross Site Scripting (XSS) in GiveWP < 4.16.6 versions. | ||
| CVE-2026-73340 | Med | 0.42 | 6.5 | 0.00 | Aug 13, 2026 | Contributor Cross Site Scripting (XSS) in Featured Image from URL <= 5.3.3 versions. | ||
| CVE-2026-66687 | Med | 0.42 | 6.5 | 0.00 | Aug 13, 2026 | Customer Cross Site Scripting (XSS) in WpBookingly <= 1.3.2 versions. |
- risk 0.42cvss 6.5epss 0.00
Contributor Cross Site Scripting (XSS) in Video Conferencing with Zoom <= 4.6.8 versions.
- risk 0.42cvss 6.5epss 0.00
Contributor Cross Site Scripting (XSS) in Login With Ajax <= 4.5.1 versions.
- risk 0.42cvss 6.5epss 0.00
Contributor Cross Site Scripting (XSS) in WPZOOM Forms – Contact Form Plugin for Gutenberg <= 2.0.4 versions.
- risk 0.42cvss 6.5epss 0.00
Contributor Cross Site Scripting (XSS) in Frontend Admin by DynamiApps <= 3.29.10 versions.
- risk 0.42cvss 6.5epss 0.00
Contributor Cross Site Scripting (XSS) in Featured Video Plus <= 2.3.3 versions.
- risk 0.42cvss 6.5epss 0.00
Contributor Cross Site Scripting (XSS) in Wise Chat <= 3.4 versions.
- risk 0.42cvss 7.6epss 0.00
Grav before 2.0.15 contains a stored cross-site scripting vulnerability in the audio and video media rendering through the sourceParsedownElement method. The media URL fragment is concatenated unescaped into rawHtml source elements, allowing attackers to inject arbitrary HTML…
- risk 0.42cvss 6.4epss 0.00
The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bt_bb_shortcode' shortcode in all versions up to, and including, 5.6.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it…
- risk 0.42cvss 6.4epss 0.00
The SureDash – Community, Courses & Member Dashboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'draweropenverposition' Block/Shortcode Attribute in all versions up to, and including, 1.10.3 due to insufficient input sanitization and output escaping.…
- risk 0.42cvss 6.4epss 0.00
The Snippet Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in all versions up to, and including, 5.2.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…
- risk 0.42cvss 6.4epss 0.00
The Youtube Showcase plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.0.4 via the 'emd_mb_meta' shortcode. This is due to insufficient input sanitization and output escaping on attachment titles referenced by the shortcode's…
- risk 0.42cvss 6.4epss 0.00
The Toocheke Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.10 via the 'series_bg_color' post meta field. This is due to insufficient input sanitization in the toocheke_series_bg_color_save() function (which stores…
- risk 0.42cvss 6.4epss 0.00
The Serious Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'theme' Shortcode Attribute in all versions up to, and including, 1.4.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…
- risk 0.42cvss 6.4epss 0.00
The Loco Translate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via PO File Extracted Comments in all versions up to, and including, 2.8.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…
- risk 0.42cvss 6.4epss 0.00
The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'question_title' parameter in all versions up to, and including, 11.2.1 due to insufficient input sanitization and output escaping. This…
- risk 0.42cvss 6.4epss 0.00
The Beaver Builder Page Builder – Drag and Drop Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Button Module 'button' (Button Code) Setting in all versions up to, and including, 2.10.2.2 due to insufficient input sanitization and output…
- risk 0.42cvss 6.4epss 0.00
The Hydra Booking — Appointment Scheduling & Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'first_name' parameter in all versions up to, and including, 1.2.2 due to insufficient input sanitization and output escaping. This makes it…
- risk 0.42cvss 6.5epss 0.00
Donor Cross Site Scripting (XSS) in GiveWP < 4.16.6 versions.
- risk 0.42cvss 6.5epss 0.00
Contributor Cross Site Scripting (XSS) in Featured Image from URL <= 5.3.3 versions.
- risk 0.42cvss 6.5epss 0.00
Customer Cross Site Scripting (XSS) in WpBookingly <= 1.3.2 versions.