CWE-79
High likelihoodImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
45,786 vulnerabilities with CWE-79
CVE-2026-59795
HIGH
Jetbrains TeamCity < 2026.1.2 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSS 8.1
CVE-2026-59794
HIGH
Jetbrains TeamCity < 2026.1.2 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSS 7.3
CVE-2026-56354
MEDIUM
n8n - Cross-Site Scripting and Open Redirect in Form Node
CVSS 4.1
CVE-2026-29519
HIGH
Lucee CFML Server Reflected XSS via URL Path Parsing
CVSS 8.2
CVE-2026-41877
MEDIUM
Stored XSS in R-SOFT DMS
CVE-2026-13710
MEDIUM
Powerful Addons For Elementor, Widgets & Templates For WordPress < 3.2.6 - XSS
CVSS 6.4
CVE-2026-13247
MEDIUM
Logo Slider <= 5.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'lgx_tooltip_position' Parameter
CVSS 6.4
CVE-2026-9838
MEDIUM
ICS Calendar <= 12.0.9 - Reflected Cross-Site Scripting via 'htmltagtitle' Parameter
CVSS 6.1
CVE-2026-3907
MEDIUM
Hostel <= 1.1.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'wphostel-book' Shortcode
CVSS 6.4
CVE-2026-12924
MEDIUM
Eventin <= 4.1.15 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'etn_faq_content' Parameter
CVSS 6.4
CVE-2026-12108
MEDIUM
Highlighting Code Block <= 2.2.0 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'font_family' Setting
CVSS 4.4
CVE-2026-15301
MEDIUM
BuddyHolis TableSearch <= 1.1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
CVSS 6.4
CVE-2026-15299
MEDIUM
Animation Addons for Elementor <= 2.6.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Weather Widget
CVSS 6.4
CVE-2026-15298
HIGH
TelSender <= 1.14.14 - Unauthenticated Stored Cross-Site Scripting via Telegram Chat Title
CVSS 7.2
CVE-2026-15297
MEDIUM
Newsletter, SMTP, Email marketing and Subscribe forms by Brevo (formely Sendinblue) <= 3.1.77 - Reflected Cross-Site Scripting
CVSS 6.1
CVE-2026-15296
MEDIUM
affiliate-toolkit – WP Affiliate Plugin with Amazon <= 3.7.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
CVSS 6.4
CVE-2026-15292
MEDIUM
Sudoku Shortcode <= 1.0.0 - Authenticated (Contributor+) Cross-Site Scripting via 'background' Shortcode Attribute
CVSS 6.4
CVE-2026-15285
MEDIUM
The Plus Addons for Elementor <= 6.4.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via Button Widget Custom Attributes
CVSS 6.4
CVE-2026-15284
MEDIUM
King Addons for Elementor <= 51.1.62 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'form_page_id' Parameter
CVSS 6.4
CVE-2026-15283
MEDIUM
WPvivid Backup for MainWP <= 0.9.33 - Authenticated (Admin+) Stored Cross-Site Scripting
CVSS 4.4
CVE-2026-15321
LOW
MyEMS Admin Backend svg.py on_post cross site scripting
CVSS 2.4
CVE-2026-11392
MEDIUM
WP Hotel Booking <= 2.3.1 - Reflected Cross-Site Scripting via 'check_in_date' and 'check_out_date' Parameters
CVSS 6.1
CVE-2026-15311
LOW
NousResearch hermes-agent Matrix Adapter matrix.py MatrixAdapter._markdown_to_html cross site scripting
CVSS 3.5
CVE-2026-59833
HIGH
SiYuan: Stored XSS to RCE in SiYuan via a per-attribute URL-scheme sanitizer gap in Lute (form action / SVG xlink:href)
CVE-2026-58144
MEDIUM
Cotonti Siena 0.9.26 Stored XSS via PFS Module ntitle Parameter
CVSS 5.4
Details
Vulnerabilities
45,786
Exploit Likelihood
High