CWE-79

High likelihood

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Parent: CWE-74 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

45,769 vulnerabilities with CWE-79
CVE-2026-55020 MEDIUM
Microsoft SharePoint Server Spoofing Vulnerability
CVSS 4.6
CVE-2026-55019 MEDIUM
Microsoft SharePoint Server Spoofing Vulnerability
CVSS 4.6
CVE-2026-55016 MEDIUM
Microsoft SharePoint Server Spoofing Vulnerability
CVSS 4.6
CVE-2026-50684 MEDIUM
Microsoft Windows 10 Version 1607 - Active Directory Federation Server Spoofing Vulnerability
CVSS 4.8
CVE-2026-15715 MEDIUM
SourceCodester Class and Exam Timetabling System exam.php cross site scripting
CVSS 4.3
CVE-2026-58647 HIGH
Microsoft PowerBI Report Server Spoofing Vulnerability
CVSS 8.0
CVE-2026-55008 CRITICAL
Microsoft Exchange Server Spoofing Vulnerability
CVSS 9.6
CVE-2026-54433 HIGH
Roundcube Webmail - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSS 7.2
CVE-2026-54432 MEDIUM
Roundcube Webmail - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSS 4.7
CVE-2026-36214 MEDIUM
osTicket 1.10-1.17.7 and 1.18.0-1.18.3 - Stored Cross-Site Scripting via Bootstrap Tooltip Component
CVSS 5.4
CVE-2026-9292 HIGH
Rockwell Automation FactoryTalk® DataMosaix™ Private Cloud - Stored Cross-Site Scripting
CVE-2026-52838 LOW
Easy!Appointments < 1.6.0 - Stored Cross-Site Scripting
CVSS 2.6
CVE-2026-23573 MEDIUM
Fortinet FortiOS - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSS 6.1
CVE-2026-58475 MEDIUM
Sustainable Irrigation Platform 5.2.16 Stored XSS via Program Name
CVSS 6.1
CVE-2026-15678 LOW
code-projects Online Job Portal DetailJob.php cross site scripting
CVSS 3.5
CVE-2026-7640 MEDIUM
WP Customer Area <= 8.3.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'type' Shortcode Attribute
CVSS 6.4
CVE-2026-11390 MEDIUM
News Kit Addons For Elementor <= 1.4.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Site Logo Title and Single Author Box Widgets
CVSS 6.4
CVE-2026-44767 MEDIUM
Allowlist Bypass in setThemeRoot() Enables Cross-Origin CSS Injection
CVSS 6.1
CVE-2026-44760 MEDIUM
SAP NetWeaver AS ABAP BSP - Cross-Site Scripting
CVSS 4.7
CVE-2026-44759 MEDIUM
SAP NetWeaver Enterprise Portal - Unauthenticated Reflected Cross-Site Scripting
CVSS 6.1
CVE-2026-44752 HIGH
SAP NetWeaver AS Java Configuration Wizard - Unauthenticated Cross-Site Scripting
CVSS 8.2
CVE-2026-58500 HIGH
MCP Appium: Unescaped Locator Data XSS in MCP-UI Resource (createLocatorGeneratorUI)
CVSS 8.2
CVE-2026-58487 MEDIUM
HedgeDoc: Stored HTML injection via email local-part
CVE-2026-58411 HIGH
ChurchCRM has Reflected Cross-Site Scripting (XSS) via unsanitized request parameter names and values
CVE-2026-15596 MEDIUM
SourceCodester Class and Exam Timetabling System subject.php cross site scripting
CVSS 4.3
Details
Vulnerabilities 45,769
Exploit Likelihood High