CWE-79

High likelihood

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Parent: CWE-74 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

45,750 vulnerabilities with CWE-79
CVE-2026-56672 HIGH
ComfyUI: Stored XSS via /userdata/{file} due to Missing Content-Type Sanitization
CVSS 8.2
CVE-2026-56670 HIGH
ComfyUI: Stored XSS via SVG file upload on the /view endpoint
CVSS 8.2
CVE-2026-66421 CRITICAL
OpenClaw Dashboard Stored XSS via lastMessage Session Field
CVSS 9.3
CVE-2026-66418 CRITICAL
OpenClaw Dashboard v3.0.0 Stored XSS via Failed Login Username Field
CVSS 9.3
CVE-2026-61526 MEDIUM
AdonisJS HTTP Server is vulnerable to reflected XSS through its exception handler
CVSS 6.1
CVE-2026-11707 CRITICAL
Cross-site Scripting in IBM WebSphere Application Server shipped with Tivoli System Automation Application Manager
CVSS 9.3
CVE-2026-11383 MEDIUM
Cross-site Scripting in IBM WebSphere Application Server shipped with Tivoli System Automation Application Manager
CVSS 5.4
CVE-2026-18361 HIGH
DFIR-IRIS Stored XSS in Datastore Upload
CVSS 7.6
CVE-2026-18360 HIGH
DFIR-IRIS Stored XSS in Custom Attributes
CVSS 7.6
CVE-2026-16969 HIGH
DFIR-IRIS Stored XSS in Assets
CVSS 7.6
CVE-2026-59328 MEDIUM
Cross-Site Scripting in Eclipse Spring Boot Starter Wizard Dependency Tooltips
CVSS 4.2
CVE-2026-14592 MEDIUM
WP Real IP-based Access Control <= 1.3.1 - Unauthenticated Stored XSS via acl_ctrl_addr
CVSS 6.1
CVE-2026-14318 MEDIUM
GiveWP < 4.16.3 - GiveWP Worker+ Stored XSS via Donation Form Template Settings
CVSS 6.8
CVE-2026-14207 MEDIUM
LifterLMS < 10.0.10 - Instructor+ Stored XSS via Featured Pricing Information
CVSS 6.1
CVE-2026-13344 MEDIUM
Essential Addons for Elementor - Lite < 6.6.10 - Contributor+ Stored XSS via Pricing Table Title Tag
CVSS 4.8
CVE-2026-13330 MEDIUM
Animation Addons for Elementor < 2.7.0 - Author+ Stored XSS via SVG Upload
CVSS 6.1
CVE-2026-11881 MEDIUM
Fluent Forms < 6.2.6 - Contributor+ Stored XSS via Date/Time Field
CVSS 6.1
CVE-2026-17962 MEDIUM
Google Chrome - XSS
CVSS 6.1
CVE-2026-17903 MEDIUM
Google Chrome < 151.0.7922.72 - Cross-Site Scripting in Chromecast via Local Network Traffic
CVSS 5.4
CVE-2026-17878 MEDIUM
Google Chrome - XSS
CVSS 6.1
CVE-2026-17739 MEDIUM
Google Chrome - XSS
CVSS 4.2
CVE-2026-17734 MEDIUM
Google Chrome - XSS
CVSS 5.4
CVE-2026-17728 MEDIUM
Google Chrome - XSS
CVSS 5.4
CVE-2026-3093 MEDIUM
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
CVSS 4.7
CVE-2026-66490 MEDIUM
Joomla Extension - balbooa.com - Stored cross-site scripting via a comment avatar in Gridbox < 2.20.2
CVSS 6.1
Details
Vulnerabilities 45,750
Exploit Likelihood High