CWE-79
High likelihoodImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
45,751 vulnerabilities with CWE-79
CVE-2026-46594
MEDIUM
Reflected XSS in PHP Poll Script
CVE-2026-56672
HIGH
ComfyUI: Stored XSS via /userdata/{file} due to Missing Content-Type Sanitization
CVSS 8.2
CVE-2026-56670
HIGH
ComfyUI: Stored XSS via SVG file upload on the /view endpoint
CVSS 8.2
CVE-2026-66421
CRITICAL
OpenClaw Dashboard Stored XSS via lastMessage Session Field
CVSS 9.3
CVE-2026-66418
CRITICAL
OpenClaw Dashboard v3.0.0 Stored XSS via Failed Login Username Field
CVSS 9.3
CVE-2026-61526
MEDIUM
AdonisJS HTTP Server is vulnerable to reflected XSS through its exception handler
CVSS 6.1
CVE-2026-11707
CRITICAL
Cross-site Scripting in IBM WebSphere Application Server shipped with Tivoli System Automation Application Manager
CVSS 9.3
CVE-2026-11383
MEDIUM
Cross-site Scripting in IBM WebSphere Application Server shipped with Tivoli System Automation Application Manager
CVSS 5.4
CVE-2026-18361
HIGH
DFIR-IRIS Stored XSS in Datastore Upload
CVSS 7.6
CVE-2026-18360
HIGH
DFIR-IRIS Stored XSS in Custom Attributes
CVSS 7.6
CVE-2026-16969
HIGH
DFIR-IRIS Stored XSS in Assets
CVSS 7.6
CVE-2026-59328
MEDIUM
Cross-Site Scripting in Eclipse Spring Boot Starter Wizard Dependency Tooltips
CVSS 4.2
CVE-2026-14592
MEDIUM
WP Real IP-based Access Control <= 1.3.1 - Unauthenticated Stored XSS via acl_ctrl_addr
CVSS 6.1
CVE-2026-14318
MEDIUM
GiveWP < 4.16.3 - GiveWP Worker+ Stored XSS via Donation Form Template Settings
CVSS 6.8
CVE-2026-14207
MEDIUM
LifterLMS < 10.0.10 - Instructor+ Stored XSS via Featured Pricing Information
CVSS 6.1
CVE-2026-13344
MEDIUM
Essential Addons for Elementor - Lite < 6.6.10 - Contributor+ Stored XSS via Pricing Table Title Tag
CVSS 4.8
CVE-2026-13330
MEDIUM
Animation Addons for Elementor < 2.7.0 - Author+ Stored XSS via SVG Upload
CVSS 6.1
CVE-2026-11881
MEDIUM
Fluent Forms < 6.2.6 - Contributor+ Stored XSS via Date/Time Field
CVSS 6.1
CVE-2026-17962
MEDIUM
Google Chrome - XSS
CVSS 6.1
CVE-2026-17903
MEDIUM
Google Chrome < 151.0.7922.72 - Cross-Site Scripting in Chromecast via Local Network Traffic
CVSS 5.4
CVE-2026-17878
MEDIUM
Google Chrome - XSS
CVSS 6.1
CVE-2026-17739
MEDIUM
Google Chrome - XSS
CVSS 4.2
CVE-2026-17734
MEDIUM
Google Chrome - XSS
CVSS 5.4
CVE-2026-17728
MEDIUM
Google Chrome - XSS
CVSS 5.4
CVE-2026-3093
MEDIUM
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
CVSS 4.7
Details
Vulnerabilities
45,751
Exploit Likelihood
High