CWE-79

High likelihood

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Parent: CWE-74 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

45,759 vulnerabilities with CWE-79
CVE-2026-12968 HIGH
Product Addons – WowAddons < 1.6.15 - Unauthenticated Stored XSS via Arbitrary SVG Upload
CVSS 8.8
CVE-2026-16486 MEDIUM
SourceCodester Class and Exam Timetabling System BSIS.php cross site scripting
CVSS 4.3
CVE-2026-16485 MEDIUM
SourceCodester Class and Exam Timetabling System class.php cross site scripting
CVSS 4.3
CVE-2026-60664 HIGH
Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0 - Unauthenticated Remote Code Execution via HTTP with User Interaction
CVSS 8.8
CVE-2026-60650 HIGH
Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0 - Authenticated Remote Code Execution via Web Content Management
CVSS 8.0
CVE-2026-60646 HIGH
Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0 - Authenticated Remote Code Execution via Web Content Management
CVSS 8.0
CVE-2026-60639 HIGH
Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0 - Unauthenticated Remote Code Execution via HTTP
CVSS 8.8
CVE-2026-60638 HIGH
Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0 - Unauthenticated Remote Code Execution via HTTP with User Interaction
CVSS 8.8
CVE-2026-60637 HIGH
Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0 - Unauthenticated Remote Code Execution via Content Server
CVSS 8.8
CVE-2026-60636 HIGH
Oracle WebCenter Content 12.2.1.4.0 and 14.1.2.0.0 - Unauthenticated Remote Code Execution via Content Server
CVSS 8.8
CVE-2026-60635 HIGH
Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0 - Unauthenticated Remote Code Execution via HTTP with User Interaction
CVSS 8.8
CVE-2026-60634 HIGH
Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0 - Unauthenticated Remote Code Execution via HTTP with User Interaction
CVSS 8.8
CVE-2026-60633 HIGH
Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0 - Unauthenticated Remote Code Execution via HTTP
CVSS 8.8
CVE-2026-52475 MEDIUM
AiFlowy <= 2.1.2 - Stored Cross-Site Scripting via File Upload in UploadController
CVSS 6.1
CVE-2026-47689 MEDIUM
FOGProject has stored XSS via unescaped inventory data in buildRow() rendered on Group Inventory tab
CVSS 4.6
CVE-2026-47687 HIGH
FOGProject has stored XSS via unescaped option label in selectForm() accessible from unauthenticated inventory endpoint
CVSS 7.3
CVE-2026-47685 HIGH
FOGProject has stored XSS via unauthenticated inventory service renders unescaped in Host Management page
CVSS 7.3
CVE-2026-50758 HIGH
next-ai-draw-io 0.4.13 - Stored Cross-Site Scripting via mcp Parameter
CVSS 8.1
CVE-2026-55081 HIGH
DHIS2 Reflected XSS in OpenAPI HTML scope parameter
CVE-2026-64823 MEDIUM
Home Assistant Core < 2026.5.4 XSS via Shelly media_player.py thumb URI
CVSS 4.7
CVE-2026-28315 MEDIUM
SolarWinds Serv-U Authenticated Stored Cross-site Scripting (XSS) Vulnerability
CVSS 6.2
CVE-2026-65048 CRITICAL
Ninja Forms Unauthenticated Stored Cross-Site Scripting via Repeatable Fieldset Submission Index
CVSS 9.3
CVE-2026-64628 MEDIUM
Grav Stored Cross-Site Scripting via Shortcode Attribute Handlers
CVSS 5.4
CVE-2026-15145 MEDIUM
Essential Addons for Elementor <= 6.6.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via Fancy Text Widget
CVSS 6.4
CVE-2026-11767 HIGH
CRT Addons for Elementor < 1.6.7 - Unauthenticated Stored XSS via Contact Form
CVSS 8.8
Details
Vulnerabilities 45,759
Exploit Likelihood High