CWE-79

High likelihood

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Parent: CWE-74 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

45,769 vulnerabilities with CWE-79
CVE-2026-48320 HIGH
Adobe ColdFusion 2025 < 10 - XSS
CVSS 8.5
CVE-2026-48761 MEDIUM
Symfony: HtmlSanitizer UrlAttributeSanitizer Misses URL Attributes on <object>, <applet>, <iframe>, <img> and the URL Inside <meta http-equiv="refresh"> content
CVSS 6.1
CVE-2026-48371 MEDIUM
Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)
CVSS 5.4
CVE-2026-48355 MEDIUM
Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)
CVSS 5.4
CVE-2026-48263 MEDIUM
Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)
CVSS 5.4
CVE-2026-48262 MEDIUM
Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)
CVSS 5.4
CVE-2026-48261 MEDIUM
Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)
CVSS 5.4
CVE-2026-48260 MEDIUM
Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)
CVSS 5.4
CVE-2026-48257 MEDIUM
Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)
CVSS 5.4
CVE-2026-48255 MEDIUM
Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)
CVSS 5.4
CVE-2026-48254 MEDIUM
Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)
CVSS 5.4
CVE-2026-48253 MEDIUM
Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)
CVSS 5.4
CVE-2026-47999 MEDIUM
Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)
CVSS 4.8
CVE-2026-47995 HIGH
Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)
CVSS 8.1
CVE-2026-47994 HIGH
Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)
CVSS 8.7
CVE-2026-47428 CRITICAL
Vitest browser mode serves unsanitized otelCarrier query parameter as inline script
CVSS 9.6
CVE-2026-47423 HIGH
DOMPurify XSS via `selectedcontent` re-clone
CVSS 8.2
CVE-2026-45753 MEDIUM
Symfony HtmlSanitizer - Cross-Site Scripting via Unsanitized URL Attributes
CVSS 6.1
CVE-2026-45072 MEDIUM
Symfony: Stored XSS in WebProfiler CodeExtension::fileExcerpt() — Unescaped Non-PHP File Rendering
CVSS 5.4
CVE-2026-57101 HIGH
Visual Studio Code Security Feature Bypass Vulnerability
CVSS 7.1
CVE-2026-55135 MEDIUM
Microsoft SharePoint Server Spoofing Vulnerability
CVSS 4.6
CVE-2026-55126 HIGH
Microsoft SharePoint Server Spoofing Vulnerability
CVSS 7.3
CVE-2026-55034 HIGH
Microsoft SharePoint Server Spoofing Vulnerability
CVSS 7.3
CVE-2026-55030 MEDIUM
Microsoft SharePoint Server Spoofing Vulnerability
CVSS 4.6
CVE-2026-55021 HIGH
Microsoft SharePoint Server Spoofing Vulnerability
CVSS 7.3
Details
Vulnerabilities 45,769
Exploit Likelihood High