VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (46,607)

page 98 of 2,331
  • CVE-2026-5111HigMay 2, 2026
    risk 0.47cvss 7.2epss 0.00

    The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 2.10.0. This is due to insufficient input validation and output escaping on Hidden Product field values when used inside Repeater fields, where repeater subfields…

  • CVE-2026-5110HigMay 2, 2026
    risk 0.47cvss 7.2epss 0.00

    The Gravity Forms plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting in versions up to and including 2.10.0. This is due to insufficient input validation and output escaping in the SingleProduct field when used inside a Repeater field. When…

  • CVE-2026-5109HigMay 2, 2026
    risk 0.47cvss 7.2epss 0.00

    The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 2.10.0. This is due to insufficient validation and output escaping of Product Option field values. The vulnerability exists because the state validation function…

  • CVE-2018-25309HigApr 29, 2026
    risk 0.47cvss 7.2epss 0.00

    MyBB Recent threads 17.0 contains a persistent cross-site scripting vulnerability that allows attackers to inject malicious scripts by creating threads with crafted subject lines. Attackers can create threads with script tags in the subject parameter to execute arbitrary…

  • CVE-2026-3876HigApr 16, 2026
    risk 0.47cvss 7.2epss 0.00

    The Prismatic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'prismatic_encoded' pseudo-shortcode in all versions up to, and including, 3.7.3. This is due to insufficient input sanitization and output escaping on user-supplied attributes within the…

  • CVE-2026-5694HigApr 15, 2026
    risk 0.47cvss 7.2epss 0.00

    The Quick Interest Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'loan-amount' and 'loan-period' parameters in all versions up to, and including, 3.1.5 due to insufficient input sanitization and output escaping. This makes it possible for…

  • CVE-2026-3643HigApr 15, 2026
    risk 0.47cvss 7.2epss 0.00

    The Accessibly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the REST API in all versions up to, and including, 3.0.3. The plugin registers REST API endpoints at `/otm-ac/v1/update-widget-options` and `/otm-ac/v1/update-app-config` with the…

  • CVE-2026-2834HigApr 15, 2026
    risk 0.47cvss 7.2epss 0.00

    The Age Verification & Identity Verification by Token of Trust plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘description’ parameter in all versions up to, and including, 3.32.3 due to insufficient input sanitization and output escaping. This…

  • CVE-2026-4388HigApr 14, 2026
    risk 0.47cvss 7.2epss 0.00

    The Form Maker by 10Web plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Matrix field (Text Box input type) in form submissions in all versions up to, and including, 1.15.40. This is due to insufficient input sanitization (`sanitize_text_field` strips…

  • CVE-2026-40038HigApr 13, 2026
    risk 0.47cvss 7.2epss 0.00

    Pachno 1.0.6 contains a stored cross-site scripting vulnerability that allows attackers to execute arbitrary HTML and script code by injecting malicious payloads into POST parameters. Attackers can inject scripts through the value, comment_body, article_content, description, and…

  • CVE-2026-5217HigApr 11, 2026
    risk 0.47cvss 7.2epss 0.00

    The Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 4.2.2. This is due to insufficient input sanitization and output escaping on the…

  • CVE-2026-35035HigApr 6, 2026
    risk 0.47cvss 7.2epss 0.00

    CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to 0.31.2.0, the application fails to properly sanitize user-controlled input within System Settings – Company Information.…

  • CVE-2026-5425HigApr 4, 2026
    risk 0.47cvss 7.2epss 0.00

    The Widgets for Social Photo Feed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'feed_data' parameter keys in all versions up to, and including, 1.7.9 due to insufficient input sanitization and output escaping. This makes it possible for…

  • CVE-2026-27655HigApr 3, 2026
    risk 0.47cvss 7.3epss 0.01

    Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Permissions Based on Mailboxes report.

  • CVE-2026-4108HigApr 3, 2026
    risk 0.47cvss 7.3epss 0.01

    Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Non-Owner Mailbox Permission report.

  • CVE-2026-4107HigApr 3, 2026
    risk 0.47cvss 7.3epss 0.01

    Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Folder Message Count and Size report.

  • CVE-2026-3880HigApr 3, 2026
    risk 0.47cvss 7.3epss 0.01

    Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Public Folder Client Permissions report.

  • CVE-2026-3879HigApr 3, 2026
    risk 0.47cvss 7.3epss 0.01

    Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Equipment Mailbox Details report.

  • CVE-2026-28703HigApr 3, 2026
    risk 0.47cvss 7.3epss 0.01

    Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Mails Exchanged Between Users report.

  • CVE-2026-28756HigApr 3, 2026
    risk 0.47cvss 7.3epss 0.01

    Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Permissions based on Distribution Groups report.