CWE-79

High likelihood

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Parent: CWE-74 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

45,769 vulnerabilities with CWE-79
CVE-2026-58148 HIGH
Joomla Extension - chronoengine.com - Stored XSS in ChronoForms extension for Joomla < 8.0.53
CVE-2026-51081 MEDIUM
Proxmox Virtual Environment 8.x <= 4.3.16 and 9.x <= 5.1.8 - Cross-Site Scripting via Crafted Payload Injection
CVSS 6.1
CVE-2026-10525 MEDIUM
NEX-Forms < 9.2.3 - Unauthenticated Stored XSS via Form Submission
CVSS 6.1
CVE-2026-15094 MEDIUM
WP Hotel Booking <= 2.3.2 - Reflected Cross-Site Scripting via 'check_in_date' Parameter
CVSS 6.1
CVE-2026-15759 MEDIUM
Themeatelier ChatHelp <= 3.5.1 - Authenticated Stored Cross-Site Scripting
CVSS 6.4
CVE-2026-15161 MEDIUM
Ninja Forms - Excel Export <= 3.3.6 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'filter' Parameter
CVSS 6.4
CVE-2026-15395 HIGH
Kali Forms <= 2.4.18 - Unauthenticated Stored Cross-Site Scripting via 'digitalSignature' Field Value
CVSS 7.2
CVE-2026-11324 MEDIUM
WooCommerce Placetopay Gateway <= 3.2.2 - Reflected Cross-Site Scripting via 'redirect-url'
CVSS 6.1
CVE-2026-2594 MEDIUM
Smart Custom Fields <= 5.0.7 - Authenticated (Author+) Stored Cross-Site Scripting via Attachment Title
CVSS 6.4
CVE-2026-62826 MEDIUM
Microsoft SharePoint Server Spoofing Vulnerability
CVSS 4.6
CVE-2026-58643 MEDIUM
Windows Admin Center Spoofing Vulnerability
CVSS 6.1
CVE-2026-45368 HIGH
Kirby: Cross-site scripting (XSS) from links in KirbyTags and image blocks in the site frontend
CVE-2026-44175 HIGH
Kirby: Cross-site scripting (XSS) from list field content in the site frontend
CVE-2026-46686 HIGH
Emlog Reflected Cross-Site Scripting
CVE-2026-63081 MEDIUM
Perfect Support Ticketing System 1.7 Stored XSS via Ticket Notes Field
CVSS 5.4
CVE-2026-7543 HIGH
Breakdance <= 2.7.1 - Unauthenticated Stored Cross-Site Scripting via Webhook Action Details
CVSS 7.2
CVE-2026-15324 MEDIUM
SysBasics Customize My Account for WooCommerce <= 4.4.14 - Authenticated (Shop Manager+) Stored Cross-Site Scripting via 'row_type' Parameter
CVSS 4.4
CVE-2026-15099 MEDIUM
WP Delicious <= 1.10.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'steps' Block Attribute
CVSS 6.4
CVE-2026-15021 MEDIUM
wpForo Forum <= 3.1.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'location' Profile Field
CVSS 6.4
CVE-2026-13755 MEDIUM
Tickera <= 3.6.0.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'price_wrapper' Shortcode Attribute
CVSS 6.4
CVE-2026-12978 HIGH
FunnelKit < 3.15.0.6 - Reflected XSS via Divi Optin Form
CVSS 7.1
CVE-2026-12869 MEDIUM
Header Footer Builder for Elementor < 1.2.1 - Contributor+ Stored XSS via Template Import
CVSS 6.1
CVE-2026-11371 MEDIUM
BetterDocs < 4.5.5 - Unauthenticated Stored XSS via AI Doc Summarizer Prompt Injection
CVSS 6.1
CVE-2026-15306 MEDIUM
Product Feed Manager For WooCommerce <= 7.6.1 - Reflected Cross-Site Scripting via 's' Search Parameter
CVSS 6.1
CVE-2026-13042 HIGH
RPB Chessboard <= 8.1.2 - Unauthenticated Stored Cross-Site Scripting via Comment Content
CVSS 7.2
Details
Vulnerabilities 45,769
Exploit Likelihood High