CWE-79

High likelihood

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Parent: CWE-74 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

45,786 vulnerabilities with CWE-79
CVE-2026-55424 MEDIUM
Discourse: Topic featured link susceptible to stored XSS
CVSS 5.4
CVE-2026-53963 HIGH
Discourse: Stored-XSS in 2FA delete confirmation modal
CVSS 7.3
CVE-2026-53962 MEDIUM
Discourse: Insufficient SVG sanitization logic
CVSS 5.4
CVE-2026-60120 MEDIUM
Bagisto < 2.4.4 Stored XSS via CSTI in create.blade.php
CVSS 5.4
CVE-2026-54002 HIGH
Kirby: Cross-site scripting (XSS) from incomplete HTML/XML sanitization in `Dom::sanitize()`
CVE-2026-0279 MEDIUM
Palo Alto Networks Cloud Ngfw - XSS
CVSS 6.1
CVE-2026-15202 MEDIUM
YzmCMS Header yzmphp.php get_url cross site scripting
CVSS 4.3
CVE-2026-59214 HIGH
Open WebUI: Stored web worker XSS via Pyodide
CVSS 7.3
CVE-2026-53987 MEDIUM
GLPI 11 < 2.14.4 Tag Plugin Stored Cross-Site Scripting in Kanban Badge Rendering
CVSS 6.4
CVE-2026-5005 MEDIUM
Stored XSS in Twiser's OKRs & Goals
CVSS 5.4
CVE-2026-9253 HIGH
WP Cost Estimation & Payment Forms Builder (E&P Forms) <= 10.5.97 - Unauthenticated Stored Cross-Site Scripting via 'customerInfos' Parameter
CVSS 7.2
CVE-2026-13441 HIGH
EventPrime <= 4.3.4.2 - Stored Cross-Site Scripting
CVSS 7.2
CVE-2026-5793 MEDIUM
XSS in Inrove Software's BiEticaret
CVSS 6.1
CVE-2026-2342 CRITICAL
XSS in Oceanicsoft's ValeApp
CVSS 9.3
CVE-2026-6910 MEDIUM
Bookero.pl <= 2.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes
CVSS 6.4
CVE-2026-4653 MEDIUM
Block, Suspend, Report for BuddyPress <= 3.6.4 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'link' Parameter
CVSS 6.4
CVE-2026-31981 MEDIUM
HTML injection in Diagram tab and Graph view in Guardian/CMC before 26.2.0
CVSS 5.9
CVE-2026-15000 HIGH
Connect Contact Form 7 and Mailchimp <= 0.9.78.06 - Unauthenticated Stored Cross-Site Scripting via Mailchimp Merge Field Values
CVSS 7.2
CVE-2026-14343 MEDIUM
Download Manager <= 3.3.61 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'note_before' and 'note_after' Shortcode Attributes
CVSS 6.4
CVE-2026-13771 MEDIUM
Customer Reviews for WooCommerce <= 5.113.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'color' Shortcode Attribute
CVSS 6.4
CVE-2026-13334 MEDIUM
Mang Board WP <= 2.3.4 - Reflected Cross-Site Scripting via 'stag' Parameter
CVSS 6.1
CVE-2026-13253 MEDIUM
Post Grid Gutenberg Blocks – PostX < 5.0.31 - XSS
CVSS 6.4
CVE-2026-12170 MEDIUM
AcyMailing <= 10.10.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'alignment' Attribute
CVSS 6.4
CVE-2026-47646 CRITICAL
Dynamics 365 Customer Voice Spoofing Vulnerability
CVSS 9.3
CVE-2026-15128 MEDIUM
Google Chrome - XSS
CVSS 6.1
Details
Vulnerabilities 45,786
Exploit Likelihood High