CWE-79

High likelihood

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Parent: CWE-74 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

45,751 vulnerabilities with CWE-79
CVE-2026-59727 LOW
Astro: Cross-site scripting via unescaped transition:* directive values on hydrated islands
CVE-2026-66031 MEDIUM
Ekushey Project Manager CRM 5.0 Stored XSS via Reply Ticket Field
CVSS 5.4
CVE-2026-66030 MEDIUM
Ekushey Project Manager CRM 5.0 Stored XSS via Ticket Title Field
CVSS 5.4
CVE-2026-66029 MEDIUM
Ekushey Project Manager CRM 5.0 Stored XSS via Client Name Field
CVSS 5.4
CVE-2026-59239 HIGH
Stored XSS in Prospero Flow CRM email body allows administrator account takeover
CVE-2026-66390 MEDIUM
Apache Wicket: crafted Link URL strings can break out of the JavaScript sequence
CVSS 6.1
CVE-2026-66396 HIGH
SiYuan before v3.7.2 Stored XSS to RCE via title-img IAL
CVSS 8.4
CVE-2026-66395 CRITICAL
SiYuan Desktop before v3.7.2 Reflected XSS to RCE via siyuan Protocol
CVSS 9.6
CVE-2026-66394 HIGH
SiYuan before v3.7.3 Stored and Reflected XSS via SVG Sanitizer Bypass
CVSS 8.7
CVE-2026-66475 MEDIUM
WordPress Checkout Field Editor for WooCommerce &#8211; Checkout Manager plugin <= 3.0.5 - Cross Site Scripting (XSS) vulnerability
CVSS 5.9
CVE-2026-66448 MEDIUM
WordPress Gallery PhotoBlocks plugin <= 1.3.3 - Cross Site Scripting (XSS) vulnerability
CVSS 6.5
CVE-2026-66445 MEDIUM
WordPress Open User Map plugin <= 1.4.46 - Cross Site Scripting (XSS) vulnerability
CVSS 6.5
CVE-2026-66434 MEDIUM
WordPress Photonic Gallery & Lightbox for Flickr, SmugMug & Others plugin <= 3.33 - Cross Site Scripting (XSS) vulnerability
CVSS 6.5
CVE-2026-66433 MEDIUM
WordPress Location Weather plugin <= 3.0.6 - Cross Site Scripting (XSS) vulnerability
CVSS 6.5
CVE-2026-65563 MEDIUM
WordPress Orbit Fox by ThemeIsle plugin <= 3.0.7 - Cross Site Scripting (XSS) vulnerability
CVSS 5.9
CVE-2026-65562 MEDIUM
WordPress BetterDocs plugin <= 4.6.2 - Cross Site Scripting (XSS) vulnerability
CVSS 6.5
CVE-2026-65561 MEDIUM
WordPress WordPress Social Login and Register plugin <= 7.8.0 - Cross Site Scripting (XSS) vulnerability
CVSS 6.5
CVE-2026-65557 MEDIUM
WordPress Abandoned Cart Lite for WooCommerce plugin <= 6.8.0 - Cross Site Scripting (XSS) vulnerability
CVSS 5.9
CVE-2026-59559 MEDIUM
WordPress RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg plugin <= 1.5.1 - Cross Site Scripting (XSS) vulnerability
CVSS 6.5
CVE-2026-59558 HIGH
WordPress Booking Calendar plugin <= 11.4.2 - Cross Site Scripting (XSS) vulnerability
CVSS 7.1
CVE-2026-59556 HIGH
WordPress Dynamic Pricing With Discount Rules for WooCommerce plugin <= 4.5.11 - Cross Site Scripting (XSS) vulnerability
CVSS 7.1
CVE-2026-59553 HIGH
WordPress Product Feed Manager plugin <= 7.6.1 - Cross Site Scripting (XSS) vulnerability
CVSS 7.1
CVE-2026-14856 MEDIUM
Stored Cross-Site Scripting (XSS) in TastyIgniter Media Manager
CVE-2026-65764 MEDIUM
Phoca Commander for Joomla 5.0.0-6.1.1 - Reflected Cross-Site Scripting
CVE-2026-14827 MEDIUM
Calendar < 1.3.18 - Contributor+ Stored XSS via event_link Parameter
CVSS 6.8
Details
Vulnerabilities 45,751
Exploit Likelihood High