CWE-79

High likelihood

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Parent: CWE-74 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

45,769 vulnerabilities with CWE-79
CVE-2026-15652 MEDIUM
Easy Accordion <= 3.1.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'align' Block Attribute
CVSS 6.4
CVE-2026-14987 MEDIUM
GiveWP <= 4.16.3 - Authenticated (Give Worker+) Stored Cross-Site Scripting via 'twitter_message' Sequoia Template Setting
CVSS 6.4
CVE-2026-13005 MEDIUM
MxChat <= 3.2.10 - Authenticated (Admin+) Stored Cross-Site Scripting via 'intro_message' Setting
CVSS 4.4
CVE-2026-54458 CRITICAL
AVideo: Unauthenticated Stored DOM Cross-Site Scripting via Per-Client Metadata Broadcast in YPTSocket Plugin
CVSS 9.6
CVE-2026-50183 MEDIUM
WWBN AVideo: Stored XSS via Hostile YouTube Video Title in AVideo YouTubeAPI Gallery Section
CVSS 4.7
CVE-2026-50182 MEDIUM
AVideo Has Unauthenticated Reflected XSS via $_GET['search'] in YouTubeAPI Gallery Pagination
CVSS 6.1
CVE-2026-49279 HIGH
WWBN AVideo <= 29.0 MessageSQLite - Stored Cross-Site Scripting
CVE-2026-26719 MEDIUM
xxl-job-admin 3.0.0 - Remote Code Execution via Crafted HTTP GET Request with Malicious Script
CVSS 6.1
CVE-2026-49867 MEDIUM
DataEase: Authenticated Stored XSS in DataEase Template Static Resources
CVE-2026-45738 HIGH
Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation
CVSS 7.3
CVE-2026-62948 CRITICAL
OpenWrt < 25.12.5 odhcpd/LuCI - Stored Cross-Site Scripting
CVSS 9.6
CVE-2026-62378 CRITICAL
RustFS Console: Critical Stored XSS in Preview Modal leading to Administrative Account Takeover
CVSS 9.0
CVE-2026-1563 MEDIUM
Pega Infinity < Infinity 25.1.2 - XSS
CVSS 4.8
CVE-2026-1562 MEDIUM
Pega Infinity < Infinity 25.1.2 - XSS
CVSS 4.8
CVE-2026-9007 MEDIUM
Reflected XSS in HCL Notes
CVE-2026-41580 MEDIUM
Stirling-PDF: Reflected XSS through crafted PDF metadata fields (Title and Author)
CVSS 6.1
CVE-2026-61453 MEDIUM
Grav before 2.0.1 XSS via Twig String Concatenation
CVSS 6.1
CVE-2026-58077 HIGH
Joomla Extension - weeblr.com - Unauthenticated stored XSS in 4Analytics < 5.0.2
CVE-2026-57833 HIGH
Joomla Extension - weeblr.com - Unauthenticated stored XSS in 4Analytics < 5.0.2
CVE-2026-47730 MEDIUM
Twig: XSS in profiler HtmlDumper via unescaped template and profile names
CVSS 5.4
CVE-2026-46637 MEDIUM
Twig: HTML-output filters in twig/* extras incorrectly declared `is_safe => ['all']`
CVSS 5.4
CVE-2026-42447 LOW
jadx: HTML Injection in Summary panel
CVSS 3.6
CVE-2026-49978 MEDIUM
DOMPurify IN_PLACE Sanitization Bypass via Attached Shadow Root Inside <template>.content
CVSS 6.1
CVE-2026-49459 MEDIUM
DOMPurify: IN_PLACE mode preserves attributes of a clobbered root element, allowing XSS via attacker-controlled root DOM
CVSS 6.1
CVE-2026-49458 MEDIUM
DOMPurify: Cross-realm IN_PLACE sanitization leaves executable markup intact via realm-bound `instanceof` checks
CVSS 6.1
Details
Vulnerabilities 45,769
Exploit Likelihood High