CWE-79

High likelihood

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Parent: CWE-74 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

45,771 vulnerabilities with CWE-79
CVE-2026-55481 MEDIUM
Snipe-IT: CSS Injection via `header_color` Setting
CVSS 4.8
CVE-2026-55466 HIGH
Snipe-IT: Stored XSS via inline-served attachment
CVSS 8.7
CVE-2026-54714 MEDIUM
Logto: XSS via unescaped RelayState in SAML auto-submit form
CVSS 6.1
CVE-2026-55464 MEDIUM
Snipe-IT: Stored XSS via Markdown custom field
CVSS 5.4
CVE-2026-56667 HIGH
ZITADEL: Stored XSS via Default URI Redirect in Login V2
CVSS 7.3
CVE-2026-55890 MEDIUM
Grav: Stored CSS injection via Markdown image ?style=… reaches MediaObjectTrait::style()
CVSS 4.8
CVE-2026-3251 MEDIUM
XSS in Webremium's Mezunum Satiyorum
CVSS 6.4
CVE-2026-8595 MEDIUM
Grafana OSS - Stored XSS in the Table Panel (TableNG)
CVSS 6.8
CVE-2026-61492 LOW
Jetbrains YouTrack < 2026.2.17394 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSS 3.5
CVE-2026-61456 MEDIUM
Grav before 1.0.3 Stored XSS via SVG Upload API
CVSS 4.6
CVE-2026-59795 HIGH
Jetbrains TeamCity < 2026.1.2 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSS 8.1
CVE-2026-59794 HIGH
Jetbrains TeamCity < 2026.1.2 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSS 7.3
CVE-2026-56354 MEDIUM
n8n - Cross-Site Scripting and Open Redirect in Form Node
CVSS 4.1
CVE-2026-29519 HIGH
Lucee CFML Server Reflected XSS via URL Path Parsing
CVSS 8.2
CVE-2026-41877 MEDIUM
Stored XSS in R-SOFT DMS
CVE-2026-13710 MEDIUM
Powerful Addons For Elementor, Widgets & Templates For WordPress < 3.2.6 - XSS
CVSS 6.4
CVE-2026-13247 MEDIUM
Logo Slider <= 5.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'lgx_tooltip_position' Parameter
CVSS 6.4
CVE-2026-9838 MEDIUM
ICS Calendar <= 12.0.9 - Reflected Cross-Site Scripting via 'htmltagtitle' Parameter
CVSS 6.1
CVE-2026-3907 MEDIUM
Hostel <= 1.1.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'wphostel-book' Shortcode
CVSS 6.4
CVE-2026-12924 MEDIUM
Eventin <= 4.1.15 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'etn_faq_content' Parameter
CVSS 6.4
CVE-2026-12108 MEDIUM
Highlighting Code Block <= 2.2.0 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'font_family' Setting
CVSS 4.4
CVE-2026-15301 MEDIUM
BuddyHolis TableSearch <= 1.1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
CVSS 6.4
CVE-2026-15299 MEDIUM
Animation Addons for Elementor <= 2.6.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Weather Widget
CVSS 6.4
CVE-2026-15298 HIGH
TelSender <= 1.14.14 - Unauthenticated Stored Cross-Site Scripting via Telegram Chat Title
CVSS 7.2
CVE-2026-15297 MEDIUM
Newsletter, SMTP, Email marketing and Subscribe forms by Brevo (formely Sendinblue) <= 3.1.77 - Reflected Cross-Site Scripting
CVSS 6.1
Details
Vulnerabilities 45,771
Exploit Likelihood High