CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Description
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85
CVEs mapped to this weakness (46,817)
page 287 of 2,341| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-66471 | Med | 0.42 | 6.5 | 0.00 | Aug 13, 2026 | Subscriber Cross Site Scripting (XSS) in Accordion <= 3.0.6 versions. | ||
| CVE-2026-66467 | Med | 0.42 | 6.5 | 0.00 | Aug 13, 2026 | Subscriber Cross Site Scripting (XSS) in FluentCommunity <= 2.7.5 versions. | ||
| CVE-2026-66460 | Med | 0.42 | 6.5 | 0.00 | Aug 13, 2026 | Subscriber Cross Site Scripting (XSS) in AfterShip Tracking <= 1.18.1 versions. | ||
| CVE-2026-66456 | Med | 0.42 | 6.5 | 0.00 | Aug 13, 2026 | Subscriber Cross Site Scripting (XSS) in Profile Extra Fields by BestWebSoft <= 1.3.4 versions. | ||
| CVE-2026-28182 | Med | 0.42 | 6.5 | 0.00 | Aug 13, 2026 | Subscriber Cross Site Scripting (XSS) in AcyMailing SMTP Newsletter <= 10.11.1 versions. | ||
| CVE-2026-27537 | Med | 0.42 | 6.5 | 0.00 | Aug 13, 2026 | Unauthenticated Cross Site Scripting (XSS) in Popup by Supsystic <= 1.11.2 versions. | ||
| CVE-2026-3639 | Med | 0.42 | 6.4 | 0.00 | Aug 13, 2026 | The PPWP – Password Protect Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `ppwp` shortcode attributes in all versions up to, and including, 1.9.21 due to insufficient input sanitization and output escaping on user supplied attributes.… | ||
| CVE-2026-73415 | Hig | 0.42 | — | 0.01 | Aug 12, 2026 | jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. Prior to 4.5.10 and 4.6.2, in packages/imageviewer/src/widget.ts, JupyterLab's ImageViewer uses URL.createObjectURL for a specially crafted SVG image… | ||
| CVE-2026-72787 | Med | 0.42 | 6.4 | 0.00 | Aug 12, 2026 | Craft CMS versions before 5.10.8 contain a stored cross-site scripting vulnerability in the control panel where draft names are rendered without HTML encoding in element chips and cards. A low-privilege user who can create element drafts can inject malicious JavaScript that… | ||
| CVE-2026-49466 | Med | 0.42 | 6.5 | 0.00 | Aug 12, 2026 | Draft List is a WordPress plugin to manage and promote unpublished content. Versions 2.6.3 and below are vulnerable to stored Cross-Site Scripting (XSS) in the `[drafts]` shortcode and Draft List widget when the documented custom `template` option places the `{{draft}}`… | ||
| CVE-2026-16694 | Med | 0.42 | 6.4 | 0.00 | Aug 12, 2026 | IBM i 7.6, 7.5, 7.4, and 7.3 is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted… | ||
| CVE-2026-66703 | Med | 0.42 | 6.5 | 0.00 | Aug 6, 2026 | Contributor Cross Site Scripting (XSS) in MailOptin <= 1.2.78.0 versions. | ||
| CVE-2026-66688 | Med | 0.42 | 6.5 | 0.00 | Aug 6, 2026 | Contributor Cross Site Scripting (XSS) in Ultimate Addons for Elementor <= 1.45.2 versions. | ||
| CVE-2026-61959 | Med | 0.42 | 6.5 | 0.00 | Aug 6, 2026 | Subscriber Cross Site Scripting (XSS) in Business Directory <= 6.4.24 versions. | ||
| CVE-2026-28178 | Med | 0.42 | 6.5 | 0.00 | Aug 6, 2026 | Contributor Cross Site Scripting (XSS) in Powerkit <= 3.1.0 versions. | ||
| CVE-2026-18501 | Med | 0.42 | 6.4 | 0.00 | Aug 6, 2026 | The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Badge Widget Variable Substitution in all versions up to, and including, 1.2.69 due to insufficient input… | ||
| CVE-2026-5391 | Med | 0.42 | 6.4 | 0.00 | Aug 6, 2026 | The LatePoint plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'btn_wrapper_classes' attribute of the 'latepoint_resources' shortcode in all versions up to, and including, 5.3.2. This is due to insufficient input sanitization and output escaping in the… | ||
| CVE-2026-5158 | Med | 0.42 | 6.4 | 0.00 | Aug 6, 2026 | The Post Grid Gutenberg Blocks for News, Magazines, Blog Websites – PostX plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'inputPlaceHolder' parameter in all versions up to, and including, 5.0.13 due to insufficient input sanitization and output… | ||
| CVE-2026-18400 | Med | 0.42 | 6.4 | 0.00 | Aug 6, 2026 | The Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'delay' Post Meta Setting in all versions up to, and including, 3.111.0 due to insufficient input sanitization and output… | ||
| CVE-2026-7441 | Med | 0.42 | 6.4 | 0.00 | Aug 5, 2026 | The Simple Yearly Archive plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `posttype` attribute of the `SimpleYearlyArchive` shortcode in all versions up to, and including, 2.2.4 due to insufficient input sanitization and output escaping on user supplied… |
- risk 0.42cvss 6.5epss 0.00
Subscriber Cross Site Scripting (XSS) in Accordion <= 3.0.6 versions.
- risk 0.42cvss 6.5epss 0.00
Subscriber Cross Site Scripting (XSS) in FluentCommunity <= 2.7.5 versions.
- risk 0.42cvss 6.5epss 0.00
Subscriber Cross Site Scripting (XSS) in AfterShip Tracking <= 1.18.1 versions.
- risk 0.42cvss 6.5epss 0.00
Subscriber Cross Site Scripting (XSS) in Profile Extra Fields by BestWebSoft <= 1.3.4 versions.
- risk 0.42cvss 6.5epss 0.00
Subscriber Cross Site Scripting (XSS) in AcyMailing SMTP Newsletter <= 10.11.1 versions.
- risk 0.42cvss 6.5epss 0.00
Unauthenticated Cross Site Scripting (XSS) in Popup by Supsystic <= 1.11.2 versions.
- risk 0.42cvss 6.4epss 0.00
The PPWP – Password Protect Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `ppwp` shortcode attributes in all versions up to, and including, 1.9.21 due to insufficient input sanitization and output escaping on user supplied attributes.…
- risk 0.42cvss —epss 0.01
jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. Prior to 4.5.10 and 4.6.2, in packages/imageviewer/src/widget.ts, JupyterLab's ImageViewer uses URL.createObjectURL for a specially crafted SVG image…
- risk 0.42cvss 6.4epss 0.00
Craft CMS versions before 5.10.8 contain a stored cross-site scripting vulnerability in the control panel where draft names are rendered without HTML encoding in element chips and cards. A low-privilege user who can create element drafts can inject malicious JavaScript that…
- risk 0.42cvss 6.5epss 0.00
Draft List is a WordPress plugin to manage and promote unpublished content. Versions 2.6.3 and below are vulnerable to stored Cross-Site Scripting (XSS) in the `[drafts]` shortcode and Draft List widget when the documented custom `template` option places the `{{draft}}`…
- risk 0.42cvss 6.4epss 0.00
IBM i 7.6, 7.5, 7.4, and 7.3 is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted…
- risk 0.42cvss 6.5epss 0.00
Contributor Cross Site Scripting (XSS) in MailOptin <= 1.2.78.0 versions.
- risk 0.42cvss 6.5epss 0.00
Contributor Cross Site Scripting (XSS) in Ultimate Addons for Elementor <= 1.45.2 versions.
- risk 0.42cvss 6.5epss 0.00
Subscriber Cross Site Scripting (XSS) in Business Directory <= 6.4.24 versions.
- risk 0.42cvss 6.5epss 0.00
Contributor Cross Site Scripting (XSS) in Powerkit <= 3.1.0 versions.
- risk 0.42cvss 6.4epss 0.00
The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Badge Widget Variable Substitution in all versions up to, and including, 1.2.69 due to insufficient input…
- risk 0.42cvss 6.4epss 0.00
The LatePoint plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'btn_wrapper_classes' attribute of the 'latepoint_resources' shortcode in all versions up to, and including, 5.3.2. This is due to insufficient input sanitization and output escaping in the…
- risk 0.42cvss 6.4epss 0.00
The Post Grid Gutenberg Blocks for News, Magazines, Blog Websites – PostX plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'inputPlaceHolder' parameter in all versions up to, and including, 5.0.13 due to insufficient input sanitization and output…
- risk 0.42cvss 6.4epss 0.00
The Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'delay' Post Meta Setting in all versions up to, and including, 3.111.0 due to insufficient input sanitization and output…
- risk 0.42cvss 6.4epss 0.00
The Simple Yearly Archive plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `posttype` attribute of the `SimpleYearlyArchive` shortcode in all versions up to, and including, 2.2.4 due to insufficient input sanitization and output escaping on user supplied…