VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (46,817)

page 296 of 2,341
  • CVE-2022-50961MedMay 10, 2026
    risk 0.42cvss 6.4epss 0.00

    WordPress Plugin IP2Location Country Blocker 2.26.7 contains a stored cross-site scripting vulnerability that allows authenticated users to inject arbitrary JavaScript code through the Frontend Settings interface. Attackers can inject malicious scripts in the URL field of the…

  • CVE-2022-50949MedMay 10, 2026
    risk 0.42cvss 6.4epss 0.00

    WordPress Plugin Videos sync PDF 1.7.4 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by exploiting unsanitized mov, pdf, mp4, webm, and ogg parameters. Attackers can inject payloads like autofocus onfocus…

  • CVE-2022-50948MedMay 10, 2026
    risk 0.42cvss 6.4epss 0.00

    Motopress Hotel Booking Lite 4.2.4 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by submitting payloads in accommodation type fields. Attackers can inject script tags through the title and excerpt parameters…

  • CVE-2022-50947MedMay 10, 2026
    risk 0.42cvss 6.4epss 0.00

    WordPress Plugin Testimonial Slider and Showcase 2.2.6 contains a stored cross-site scripting vulnerability that allows authenticated editors to inject malicious scripts by failing to sanitize the post_title parameter. Attackers with editor privileges can inject JavaScript…

  • CVE-2022-50946MedMay 10, 2026
    risk 0.42cvss 6.4epss 0.00

    WordPress Plugin Netroics Blog Posts Grid 1.0 contains a stored cross-site scripting vulnerability that allows authenticated editors to inject malicious scripts by failing to sanitize the post_title parameter. Attackers with editor privileges can inject script payloads through…

  • CVE-2022-50945MedMay 10, 2026
    risk 0.42cvss 6.4epss 0.00

    WordPress 3dady Real-Time Web Stats plugin 1.0 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious JavaScript by exploiting unsanitized input fields. Attackers can insert JavaScript payloads in the dady_input_text or…

  • CVE-2021-47951MedMay 10, 2026
    risk 0.42cvss 6.4epss 0.00

    WordPress Picture Gallery 1.4.2 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts through the Edit Content URL field in the Access Control settings. Attackers can enter JavaScript payloads in the plugin options…

  • CVE-2021-47950MedMay 10, 2026
    risk 0.42cvss 6.4epss 0.00

    Advanced Guestbook 2.4.4 contains a persistent cross-site scripting vulnerability in the smilies administration interface that allows authenticated attackers to inject malicious scripts by manipulating the s_emotion parameter. Attackers can submit POST requests to admin.php with…

  • CVE-2021-47947MedMay 10, 2026
    risk 0.42cvss 6.4epss 0.00

    Projectsend r1295 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by submitting crafted input in the 'name' parameter of files-edit.php. Attackers can inject JavaScript payloads through the file name field that…

  • CVE-2021-47931MedMay 10, 2026
    risk 0.42cvss 6.4epss 0.00

    Exponent CMS 2.6 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts through the Title and Text Block parameters in the text editing endpoint. Attackers can inject iframe payloads with embedded SVG onload events to…

  • CVE-2021-47929MedMay 10, 2026
    risk 0.42cvss 6.4epss 0.00

    Filterable Portfolio Gallery 1.0 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious JavaScript by entering payloads in the title field. Attackers can store JavaScript code like image tags with onerror handlers that…

  • CVE-2021-47927MedMay 10, 2026
    risk 0.42cvss 6.4epss 0.00

    WordPress Plugin WP Symposium Pro 2021.10 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by exploiting insufficient sanitization of the forum name parameter. Attackers can submit POST requests to the admin…

  • CVE-2021-47926MedMay 10, 2026
    risk 0.42cvss 6.4epss 0.00

    Contact Form to Email 1.3.24 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by creating forms with script tags in the form name field. Attackers can craft form names containing JavaScript code that executes…

  • CVE-2021-47925MedMay 10, 2026
    risk 0.42cvss 6.4epss 0.00

    CMDBuild 3.3.2 contains multiple stored cross-site scripting vulnerabilities that allow authenticated attackers to inject arbitrary web script or HTML via crafted input in card creation and file upload endpoints. Attackers can inject XSS payloads through Employee card parameters…

  • CVE-2021-47924MedMay 10, 2026
    risk 0.42cvss 6.4epss 0.00

    Ultimate Product Catalogue 5.8.2 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts through the price parameter. Attackers can submit POST requests to post.php with HTML/JavaScript payloads in the price field to…

  • CVE-2021-47922MedMay 10, 2026
    risk 0.42cvss 6.4epss 0.00

    Slider by Soliloquy 2.6.2 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts through the title parameter. Attackers can add JavaScript payloads in the title field when creating or editing sliders, which executes…

  • CVE-2021-47910MedMay 10, 2026
    risk 0.42cvss 6.4epss 0.00

    AccessPress Social Icons 1.8.2 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by entering JavaScript payloads into the 'icon title' field. Attackers can store XSS payloads like image tags with onerror event…

  • CVE-2021-47907MedMay 10, 2026
    risk 0.42cvss 6.4epss 0.00

    Rocket LMS 1.1 contains a persistent cross-site scripting vulnerability in the support ticket module that allows authenticated users to inject malicious script code through the title parameter. Attackers can submit support tickets with embedded HTML/JavaScript payloads that…

  • CVE-2026-42224HigMay 8, 2026
    risk 0.42cvss 7.6epss 0.00

    ipl/web is a set of common web components for php projects. Prior to versions 0.13.1 and 0.10.3, the vulnerability allows an attacker to inject malicious Javascript into a victim's browser to run it in the context of Icinga Web. The victim needs to visit a specifically prepared…

  • CVE-2026-41886HigMay 8, 2026
    risk 0.42cvss 7.5epss 0.00

    locize is a localization platform that connects code and i18n setup. Prior to version 4.0.21, the locize client SDK registers a window.addEventListener("message", …) handler that dispatches to registered internal handlers (editKey, commitKey, commitKeys, isLocizeEnabled,…