CWE-79
High likelihoodImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
45,751 vulnerabilities with CWE-79
CVE-2026-14203
MEDIUM
Smart Manager < 8.92.0 - Contributor+ Stored XSS via Post Title
CVSS 4.8
CVE-2026-14190
MEDIUM
Sina Extension for Elementor < 3.10.2 - Reflected XSS
CVSS 6.1
CVE-2026-13726
HIGH
Multiple Page Generator Plugin – MPG < 4.1.8 - Reflected XSS via mpg_shortcode
CVSS 7.1
CVE-2026-13400
MEDIUM
Simply Schedule Appointments < 1.6.12.4 - Unauthenticated Stored XSS via Booking Customer Information
CVSS 6.1
CVE-2026-12982
MEDIUM
Document Gallery < 5.1.1 - Reflected XSS via dg_generate_gallery
CVSS 6.1
CVE-2026-10082
MEDIUM
Advanced Ads – Ad Manager & AdSense < 2.0.23 - Contributor+ Stored XSS via the_ad Shortcode 'ad_args' Parameter
CVSS 6.1
CVE-2026-15928
HIGH
Xmlrpc-c - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2026-17496
HIGH
NoteGen chat preview XSS via unsanitized AI/skill HTML rendering
CVSS 8.1
CVE-2026-15425
MEDIUM
Yoast SEO <= 28.0 - Authenticated (Author+) Stored Cross-Site Scripting via Post Slug (post_name)
CVSS 6.4
CVE-2026-57531
MEDIUM
Milkdown < 7.21.3 DOM XSS via innerHTML Assignment
CVSS 5.4
CVE-2026-57530
MEDIUM
Milkdown < 7.21.3 Stored XSS via javascript: URL in link href
CVSS 5.4
CVE-2026-8308
MEDIUM
Reflected XSS Polen Media's Website Template
CVSS 6.1
CVE-2026-55730
HIGH
Loytec LWEB802: Reflected Cross-Site Scripting in LWEB802
CVE-2026-12496
HIGH
Loytec LINX firmware: Unauthenticated stored XSS in OPC XML-DA server
CVE-2026-66010
MEDIUM
DOMPurify before 3.4.12 Hook Bypass via CUSTOM_ELEMENT_HANDLING
CVSS 6.1
CVE-2026-15810
HIGH
Cross-Site Scripting (XSS) in Looker allows Admin Account Takeover
CVE-2026-15401
HIGH
VikBooking Hotel Booking Engine & PMS <= 1.8.13 - Unauthenticated Stored Cross-Site Scripting via Custom Field 'vbfX' Parameter
CVSS 7.2
CVE-2026-15821
MEDIUM
SureDash <= 1.10.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes
CVSS 6.4
CVE-2026-15739
MEDIUM
Rich Showcase for Google Reviews <= 6.9.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'pagination' Shortcode Attribute
CVSS 6.4
CVE-2026-15346
MEDIUM
VikBooking Hotel Booking Engine & PMS <= 1.8.13 - Reflected Cross-Site Scripting via 'category_id' Parameter
CVSS 6.1
CVE-2026-15755
MEDIUM
Open User Map <= 1.4.45 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes
CVSS 6.4
CVE-2026-15665
MEDIUM
Fluent Support <= 2.3.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'redirect-to' Shortcode Attribute
CVSS 6.4
CVE-2026-15653
MEDIUM
Visualizer <= 4.0.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'backend-title' Parameter
CVSS 6.4
CVE-2026-15648
MEDIUM
Brands for WooCommerce <= 3.8.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'width' Shortcode Attribute
CVSS 6.4
CVE-2026-15464
MEDIUM
WP Hotel Booking <= 2.3.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'widget_search' Shortcode Attribute
CVSS 6.4
Details
Vulnerabilities
45,751
Exploit Likelihood
High