CWE-79

High likelihood

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Parent: CWE-74 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

45,769 vulnerabilities with CWE-79
CVE-2026-45270 HIGH
CI4MS: Stored XSS in Pages Module Content via Broken html_purify Validation Rule
CVSS 8.7
CVE-2026-2445 MEDIUM
Reflected Cross-Site Scripting via URL Parameter in Multiple WSO2 Products Enables UI Redirection and Modification
CVSS 6.1
CVE-2026-9833 HIGH
Tag Groups < 2.2.0 - Reflected XSS via 'tag_groups_task' Parameter
CVSS 7.1
CVE-2026-12970 HIGH
LearnPress < 4.4.1 - Reflected XSS via c_search
CVSS 7.1
CVE-2026-12592 HIGH
SlimStat Analytics < 5.5.0 - Unauthenticated Stored XSS via CF-IPCountry Header
CVSS 7.5
CVE-2026-10081 HIGH
Unlimited Elements for Elementor < 2.0.11 - Unauthenticated Stored XSS via Google Reviews Widget
CVSS 8.8
CVE-2026-45138 MEDIUM
CI4MS: Stored XSS in Blog Content via Broken `html_purify` Validation Rule
CVSS 5.4
CVE-2026-16229 MEDIUM
itsourcecode Courier Management System index.php cross site scripting
CVSS 4.3
CVE-2026-16220 MEDIUM
code-projects Online Examination System account.php cross site scripting
CVSS 4.3
CVE-2026-16205 LOW
Pluck CMS Albums albums.admin.php htmlspecialchars_decode cross site scripting
CVSS 2.4
CVE-2026-16203 LOW
SourceCodester Class and Exam Timetabling System forCYS.php cross site scripting
CVSS 3.5
CVE-2026-16202 LOW
SourceCodester Class and Exam Timetabling System CYS.php cross site scripting
CVSS 3.5
CVE-2026-16156 LOW
SourceCodester Class and Exam Timetabling System forexam.php cross site scripting
CVSS 3.5
CVE-2026-57857 MEDIUM
Flow Payment Plugin for WordPress Reflected Cross-Site Scripting via error_message Parameter
CVSS 4.3
CVE-2026-16155 LOW
SourceCodester Class and Exam Timetabling System schoolyr.php cross site scripting
CVSS 3.5
CVE-2026-12228 HIGH
Stored XSS in Direct Messages via Prompt Sharing in parisneo/lollms
CVSS 8.7
CVE-2026-54498 HIGH
view_component: around_render HTML-Safety Bypass
CVSS 8.7
CVE-2026-54163 MEDIUM
secure_headers: CSP directive injection via sandbox, plugin_types, and report_to when given untrusted input
CVSS 4.7
CVE-2026-15091 CRITICAL
IBM Engineering AI Hub 1.0.0-1.2.0 - Cross-Site Scripting
CVSS 9.3
CVE-2026-16073 LOW
AstrBotDevs AstrBot T2I Feature base.py NetworkRenderStrategy.render cross site scripting
CVSS 3.5
CVE-2026-48015 MEDIUM
Shopware: Stored XSS via SVG file upload — no SVG sanitization
CVSS 4.9
CVE-2026-9588 HIGH
Authenticated Stored Cross-Site Scripting (XSS) in Switchvox SMB Web Portal
CVE-2026-9585 HIGH
Sangoma Switchvox SMB Edition < 8.4.0.2 - XSS
CVE-2026-49216 MEDIUM
Symfony UX: XSS in symfony/ux-autocomplete via unescaped AJAX response data
CVSS 5.4
CVE-2026-49210 MEDIUM
Symfony UX: XSS in symfony/ux-live-component via attacker-controlled child component tag
CVSS 6.1
Details
Vulnerabilities 45,769
Exploit Likelihood High