CWE-79

High likelihood

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Parent: CWE-74 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

45,751 vulnerabilities with CWE-79
CVE-2026-14203 MEDIUM
Smart Manager < 8.92.0 - Contributor+ Stored XSS via Post Title
CVSS 4.8
CVE-2026-14190 MEDIUM
Sina Extension for Elementor < 3.10.2 - Reflected XSS
CVSS 6.1
CVE-2026-13726 HIGH
Multiple Page Generator Plugin – MPG < 4.1.8 - Reflected XSS via mpg_shortcode
CVSS 7.1
CVE-2026-13400 MEDIUM
Simply Schedule Appointments < 1.6.12.4 - Unauthenticated Stored XSS via Booking Customer Information
CVSS 6.1
CVE-2026-12982 MEDIUM
Document Gallery < 5.1.1 - Reflected XSS via dg_generate_gallery
CVSS 6.1
CVE-2026-10082 MEDIUM
Advanced Ads – Ad Manager & AdSense < 2.0.23 - Contributor+ Stored XSS via the_ad Shortcode 'ad_args' Parameter
CVSS 6.1
CVE-2026-15928 HIGH
Xmlrpc-c - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2026-17496 HIGH
NoteGen chat preview XSS via unsanitized AI/skill HTML rendering
CVSS 8.1
CVE-2026-15425 MEDIUM
Yoast SEO <= 28.0 - Authenticated (Author+) Stored Cross-Site Scripting via Post Slug (post_name)
CVSS 6.4
CVE-2026-57531 MEDIUM
Milkdown < 7.21.3 DOM XSS via innerHTML Assignment
CVSS 5.4
CVE-2026-57530 MEDIUM
Milkdown < 7.21.3 Stored XSS via javascript: URL in link href
CVSS 5.4
CVE-2026-8308 MEDIUM
Reflected XSS Polen Media's Website Template
CVSS 6.1
CVE-2026-55730 HIGH
Loytec LWEB802: Reflected Cross-Site Scripting in LWEB802
CVE-2026-12496 HIGH
Loytec LINX firmware: Unauthenticated stored XSS in OPC XML-DA server
CVE-2026-66010 MEDIUM
DOMPurify before 3.4.12 Hook Bypass via CUSTOM_ELEMENT_HANDLING
CVSS 6.1
CVE-2026-15810 HIGH
Cross-Site Scripting (XSS) in Looker allows Admin Account Takeover
CVE-2026-15401 HIGH
VikBooking Hotel Booking Engine & PMS <= 1.8.13 - Unauthenticated Stored Cross-Site Scripting via Custom Field 'vbfX' Parameter
CVSS 7.2
CVE-2026-15821 MEDIUM
SureDash <= 1.10.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes
CVSS 6.4
CVE-2026-15739 MEDIUM
Rich Showcase for Google Reviews <= 6.9.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'pagination' Shortcode Attribute
CVSS 6.4
CVE-2026-15346 MEDIUM
VikBooking Hotel Booking Engine & PMS <= 1.8.13 - Reflected Cross-Site Scripting via 'category_id' Parameter
CVSS 6.1
CVE-2026-15755 MEDIUM
Open User Map <= 1.4.45 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes
CVSS 6.4
CVE-2026-15665 MEDIUM
Fluent Support <= 2.3.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'redirect-to' Shortcode Attribute
CVSS 6.4
CVE-2026-15653 MEDIUM
Visualizer <= 4.0.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'backend-title' Parameter
CVSS 6.4
CVE-2026-15648 MEDIUM
Brands for WooCommerce <= 3.8.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'width' Shortcode Attribute
CVSS 6.4
CVE-2026-15464 MEDIUM
WP Hotel Booking <= 2.3.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'widget_search' Shortcode Attribute
CVSS 6.4
Details
Vulnerabilities 45,751
Exploit Likelihood High