CWE-79

High likelihood

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Parent: CWE-74 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

45,751 vulnerabilities with CWE-79
CVE-2026-66490 MEDIUM
Joomla Extension - balbooa.com - Stored cross-site scripting via a comment avatar in Gridbox < 2.20.2
CVSS 6.1
CVE-2026-65946 MEDIUM
Joomla Extension - rolandd.com - XSS vectors in AJAX endpoint handlers RO CSVI < 9.11.0
CVSS 6.1
CVE-2026-8791 MEDIUM
Booking System Trafft <= 1.0.17 - Authenticated (Subscriber+) Stored Cross-Site Scripting
CVSS 6.4
CVE-2026-7436 MEDIUM
WPC Badge Management for WooCommerce <= 3.1.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'text' Attribute
CVSS 6.4
CVE-2026-16655 HIGH
Fluent Forms <= 6.2.7 - Unauthenticated Stored Cross-Site Scripting via Name Field Nested `password` Member
CVSS 7.2
CVE-2026-16597 HIGH
GTM4WP <= 1.22.3 - Unauthenticated Stored Cross-Site Scripting via WooCommerce Billing Fields
CVSS 7.2
CVE-2026-13425 HIGH
Database for CF7 <= 1.2.6 - Unauthenticated Stored Cross-Site Scripting via Array Form Field Values
CVSS 7.2
CVE-2026-18197 MEDIUM
Link Library < 7.9.4 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2026-14234 HIGH
WOLF - WordPress Posts Bulk Editor and Manager < 1.1.0 - Stored XSS via CSRF
CVSS 7.1
CVE-2026-13605 MEDIUM
Photo Swipe <= 4.1.1.1 - Author+ Stored XSS via title Attribute
CVSS 6.8
CVE-2026-17162 MEDIUM
Wpxpo WowStore <= 4.4.24 - Contributor+ Stored Cross-Site Scripting via currentPostId
CVSS 6.4
CVE-2026-17161 MEDIUM
Wpxpo WowStore <= 4.4.24 - Contributor+ Stored Cross-Site Scripting via filterMobileText
CVSS 6.4
CVE-2026-15735 MEDIUM
Contact Form to Any API <= 3.0.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'cf7anyapi_form_field' Post Meta
CVSS 6.4
CVE-2026-12939 MEDIUM
Newsletters <= 4.15 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'link' Shortcode Attribute
CVSS 6.4
CVE-2026-12938 MEDIUM
Newsletters <= 4.15 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'target' Shortcode Attribute
CVSS 6.4
CVE-2026-14515 MEDIUM
IBM WebSphere Application Server is affected by cross-site scripting and deserialization vulnerabilities
CVSS 6.1
CVE-2026-48060 HIGH
Litestar: HTML Injection Through CSRF Token
CVSS 8.1
CVE-2026-18084 HIGH
Cross-Site Scripting (XSS) in time zone parameter of BlackBerry UEM
CVE-2026-7775 MEDIUM
IBM Sterling B2B Integrator/File Gateway 6.2.x - Stored Cross-Site Scripting
CVSS 5.5
CVE-2026-67174 CRITICAL
DOM-Based Cross-Site Scripting via Unsafe String and SVG Icon Rendering in Pivotick
CVE-2026-66921 MEDIUM
Pivotick - Stored DOM-Based Cross-Site Scripting via Unescaped Markdown Node References
CVE-2026-66919 MEDIUM
Stored DOM-Based Cross-Site Scripting in Node Modal Headers
CVE-2026-66918 HIGH
DOM-Based Cross-Site Scripting via Unsanitized SVG Node Icons
CVE-2026-65882 MEDIUM
Joomdle < 3.1.1 - Reflected Cross-Site Scripting via goto URL
CVSS 6.1
CVE-2026-15393 MEDIUM
Cozy Blocks <= 2.2.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'postMeta.font.size' Block Attribute
CVSS 6.4
Details
Vulnerabilities 45,751
Exploit Likelihood High