CWE-79
High likelihoodImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
45,759 vulnerabilities with CWE-79
CVE-2026-15782
MEDIUM
WPForms <= 2.0.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via OptinMonster Integration data-sitekey Attribute in Post Content
CVSS 4.9
CVE-2026-15156
MEDIUM
Essential Addons for Elementor <= 6.6.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via Reading Progress Global Color Settings
CVSS 6.4
CVE-2026-51025
MEDIUM
fuint Member Marketing System <= 1.0 - Remote Code Execution via ClientMessageController.java
CVSS 6.1
CVE-2026-12900
MEDIUM
Spectra Gutenberg Blocks <= 2.19.28 - Authenticated (Contributor+) Stored Cross-Site Scripting via uagb/image Block
CVSS 6.4
CVE-2026-44230
MEDIUM
RT: Reflected Cross-Site Scripting in search results chart
CVSS 6.1
CVE-2026-44229
MEDIUM
RT: Cross-Site Scripting via inline-served uploaded content
CVSS 5.4
CVE-2026-60034
CRITICAL
Joomla Extension - themexpert.com - Authenticated stored XSS in JMedia Extension < 1.6.0
CVE-2026-60029
MEDIUM
Joomla Extension - themexpert.com - Authenticated stored XSS in Quix Page Builder < 6.2.1
CVE-2026-60028
HIGH
Joomla Extension - themexpert.com - Authenticated stored XSS in Quix Page Builder < 6.2.1
CVE-2026-44228
MEDIUM
RT: Stored Cross-Site Scripting via insufficient template escaping
CVSS 5.4
CVE-2026-44227
MEDIUM
Bestpractical RT < 6.0.0, < 6.0.3 - XSS
CVSS 6.1
CVE-2026-39878
CRITICAL
Chamilo stored XSS via user registration leads to admin account takeover
CVSS 9.3
CVE-2026-26483
MEDIUM
SendPortal <= 3.0.1 - Stored Cross-Site Scripting via Template Content Parameter
CVSS 6.1
CVE-2026-6793
MEDIUM
Stored XSS in Bifra Engineering's Q-smart NexT Poll
CVSS 5.4
CVE-2026-45797
MEDIUM
HeyForm Vulnerable to Stored XSS via Unauthenticated SVG File Upload
CVE-2026-35198
CRITICAL
HeyForm vulnerable to stored XSS via form field titles
CVSS 9.0
CVE-2026-59238
MEDIUM
Stored XSS in Pentestify via unsanitized finding images and report client logo
CVE-2026-46516
MEDIUM
Frogman vulnerable to stored XSS in chat console formatter (escalation vector in multi-admin deployments)
CVE-2026-45270
HIGH
CI4MS: Stored XSS in Pages Module Content via Broken html_purify Validation Rule
CVSS 8.7
CVE-2026-2445
MEDIUM
Reflected Cross-Site Scripting via URL Parameter in Multiple WSO2 Products Enables UI Redirection and Modification
CVSS 6.1
CVE-2026-9833
HIGH
Tag Groups < 2.2.0 - Reflected XSS via 'tag_groups_task' Parameter
CVSS 7.1
CVE-2026-12970
HIGH
LearnPress < 4.4.1 - Reflected XSS via c_search
CVSS 7.1
CVE-2026-12592
HIGH
SlimStat Analytics < 5.5.0 - Unauthenticated Stored XSS via CF-IPCountry Header
CVSS 7.5
CVE-2026-10081
HIGH
Unlimited Elements for Elementor < 2.0.11 - Unauthenticated Stored XSS via Google Reviews Widget
CVSS 8.8
CVE-2026-45138
MEDIUM
CI4MS: Stored XSS in Blog Content via Broken `html_purify` Validation Rule
CVSS 5.4
Details
Vulnerabilities
45,759
Exploit Likelihood
High