CWE-79
High likelihoodImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
45,751 vulnerabilities with CWE-79
CVE-2026-59727
LOW
Astro: Cross-site scripting via unescaped transition:* directive values on hydrated islands
CVE-2026-66031
MEDIUM
Ekushey Project Manager CRM 5.0 Stored XSS via Reply Ticket Field
CVSS 5.4
CVE-2026-66030
MEDIUM
Ekushey Project Manager CRM 5.0 Stored XSS via Ticket Title Field
CVSS 5.4
CVE-2026-66029
MEDIUM
Ekushey Project Manager CRM 5.0 Stored XSS via Client Name Field
CVSS 5.4
CVE-2026-59239
HIGH
Stored XSS in Prospero Flow CRM email body allows administrator account takeover
CVE-2026-66390
MEDIUM
Apache Wicket: crafted Link URL strings can break out of the JavaScript sequence
CVSS 6.1
CVE-2026-66396
HIGH
SiYuan before v3.7.2 Stored XSS to RCE via title-img IAL
CVSS 8.4
CVE-2026-66395
CRITICAL
SiYuan Desktop before v3.7.2 Reflected XSS to RCE via siyuan Protocol
CVSS 9.6
CVE-2026-66394
HIGH
SiYuan before v3.7.3 Stored and Reflected XSS via SVG Sanitizer Bypass
CVSS 8.7
CVE-2026-66475
MEDIUM
WordPress Checkout Field Editor for WooCommerce – Checkout Manager plugin <= 3.0.5 - Cross Site Scripting (XSS) vulnerability
CVSS 5.9
CVE-2026-66448
MEDIUM
WordPress Gallery PhotoBlocks plugin <= 1.3.3 - Cross Site Scripting (XSS) vulnerability
CVSS 6.5
CVE-2026-66445
MEDIUM
WordPress Open User Map plugin <= 1.4.46 - Cross Site Scripting (XSS) vulnerability
CVSS 6.5
CVE-2026-66434
MEDIUM
WordPress Photonic Gallery & Lightbox for Flickr, SmugMug & Others plugin <= 3.33 - Cross Site Scripting (XSS) vulnerability
CVSS 6.5
CVE-2026-66433
MEDIUM
WordPress Location Weather plugin <= 3.0.6 - Cross Site Scripting (XSS) vulnerability
CVSS 6.5
CVE-2026-65563
MEDIUM
WordPress Orbit Fox by ThemeIsle plugin <= 3.0.7 - Cross Site Scripting (XSS) vulnerability
CVSS 5.9
CVE-2026-65562
MEDIUM
WordPress BetterDocs plugin <= 4.6.2 - Cross Site Scripting (XSS) vulnerability
CVSS 6.5
CVE-2026-65561
MEDIUM
WordPress WordPress Social Login and Register plugin <= 7.8.0 - Cross Site Scripting (XSS) vulnerability
CVSS 6.5
CVE-2026-65557
MEDIUM
WordPress Abandoned Cart Lite for WooCommerce plugin <= 6.8.0 - Cross Site Scripting (XSS) vulnerability
CVSS 5.9
CVE-2026-59559
MEDIUM
WordPress RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg plugin <= 1.5.1 - Cross Site Scripting (XSS) vulnerability
CVSS 6.5
CVE-2026-59558
HIGH
WordPress Booking Calendar plugin <= 11.4.2 - Cross Site Scripting (XSS) vulnerability
CVSS 7.1
CVE-2026-59556
HIGH
WordPress Dynamic Pricing With Discount Rules for WooCommerce plugin <= 4.5.11 - Cross Site Scripting (XSS) vulnerability
CVSS 7.1
CVE-2026-59553
HIGH
WordPress Product Feed Manager plugin <= 7.6.1 - Cross Site Scripting (XSS) vulnerability
CVSS 7.1
CVE-2026-14856
MEDIUM
Stored Cross-Site Scripting (XSS) in TastyIgniter Media Manager
CVE-2026-65764
MEDIUM
Phoca Commander for Joomla 5.0.0-6.1.1 - Reflected Cross-Site Scripting
CVE-2026-14827
MEDIUM
Calendar < 1.3.18 - Contributor+ Stored XSS via event_link Parameter
CVSS 6.8
Details
Vulnerabilities
45,751
Exploit Likelihood
High