CWE-79

High likelihood

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Parent: CWE-74 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

45,786 vulnerabilities with CWE-79
CVE-2026-59795 HIGH
Jetbrains TeamCity < 2026.1.2 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSS 8.1
CVE-2026-59794 HIGH
Jetbrains TeamCity < 2026.1.2 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSS 7.3
CVE-2026-56354 MEDIUM
n8n - Cross-Site Scripting and Open Redirect in Form Node
CVSS 4.1
CVE-2026-29519 HIGH
Lucee CFML Server Reflected XSS via URL Path Parsing
CVSS 8.2
CVE-2026-41877 MEDIUM
Stored XSS in R-SOFT DMS
CVE-2026-13710 MEDIUM
Powerful Addons For Elementor, Widgets & Templates For WordPress < 3.2.6 - XSS
CVSS 6.4
CVE-2026-13247 MEDIUM
Logo Slider <= 5.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'lgx_tooltip_position' Parameter
CVSS 6.4
CVE-2026-9838 MEDIUM
ICS Calendar <= 12.0.9 - Reflected Cross-Site Scripting via 'htmltagtitle' Parameter
CVSS 6.1
CVE-2026-3907 MEDIUM
Hostel <= 1.1.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'wphostel-book' Shortcode
CVSS 6.4
CVE-2026-12924 MEDIUM
Eventin <= 4.1.15 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'etn_faq_content' Parameter
CVSS 6.4
CVE-2026-12108 MEDIUM
Highlighting Code Block <= 2.2.0 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'font_family' Setting
CVSS 4.4
CVE-2026-15301 MEDIUM
BuddyHolis TableSearch <= 1.1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
CVSS 6.4
CVE-2026-15299 MEDIUM
Animation Addons for Elementor <= 2.6.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Weather Widget
CVSS 6.4
CVE-2026-15298 HIGH
TelSender <= 1.14.14 - Unauthenticated Stored Cross-Site Scripting via Telegram Chat Title
CVSS 7.2
CVE-2026-15297 MEDIUM
Newsletter, SMTP, Email marketing and Subscribe forms by Brevo (formely Sendinblue) <= 3.1.77 - Reflected Cross-Site Scripting
CVSS 6.1
CVE-2026-15296 MEDIUM
affiliate-toolkit – WP Affiliate Plugin with Amazon <= 3.7.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
CVSS 6.4
CVE-2026-15292 MEDIUM
Sudoku Shortcode <= 1.0.0 - Authenticated (Contributor+) Cross-Site Scripting via 'background' Shortcode Attribute
CVSS 6.4
CVE-2026-15285 MEDIUM
The Plus Addons for Elementor <= 6.4.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via Button Widget Custom Attributes
CVSS 6.4
CVE-2026-15284 MEDIUM
King Addons for Elementor <= 51.1.62 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'form_page_id' Parameter
CVSS 6.4
CVE-2026-15283 MEDIUM
WPvivid Backup for MainWP <= 0.9.33 - Authenticated (Admin+) Stored Cross-Site Scripting
CVSS 4.4
CVE-2026-15321 LOW
MyEMS Admin Backend svg.py on_post cross site scripting
CVSS 2.4
CVE-2026-11392 MEDIUM
WP Hotel Booking <= 2.3.1 - Reflected Cross-Site Scripting via 'check_in_date' and 'check_out_date' Parameters
CVSS 6.1
CVE-2026-15311 LOW
NousResearch hermes-agent Matrix Adapter matrix.py MatrixAdapter._markdown_to_html cross site scripting
CVSS 3.5
CVE-2026-59833 HIGH
SiYuan: Stored XSS to RCE in SiYuan via a per-attribute URL-scheme sanitizer gap in Lute (form action / SVG xlink:href)
CVE-2026-58144 MEDIUM
Cotonti Siena 0.9.26 Stored XSS via PFS Module ntitle Parameter
CVSS 5.4
Details
Vulnerabilities 45,786
Exploit Likelihood High