CWE-79

High likelihood

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Parent: CWE-74 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

45,503 vulnerabilities with CWE-79
CVE-2024-34343 MEDIUM
nuxt < 3.12.4 - Cross-Site Scripting via navigateTo URL Parsing Bypass
CVSS 6.3
CVE-2024-41960 LOW
mailcow < 2024-07 - Authenticated Stored Cross-Site Scripting via Relay Hosts Configuration
CVSS 3.8
CVE-2024-41959 HIGH
mailcow < 2024-07 - Unauthenticated Stored Cross-Site Scripting via API Log Injection
CVSS 7.6
CVE-2024-41816 MEDIUM
Cooked < 1.8.1 - Authenticated Stored Cross-Site Scripting via [cooked-timer] Shortcode
CVSS 5.4
CVE-2024-6361 MEDIUM
OpenText ALM Octane < 23.4 - Stored Cross-Site Scripting
CVSS 5.4
CVE-2024-42009 CRITICAL KEV
Roundcube Webmail <= 1.5.7 and 1.6.x <= 1.6.7 - Cross-Site Scripting via Desanitization in message_body()
CVSS 9.3
CVE-2024-42008 CRITICAL
Roundcube Webmail < 1.5.8 - Cross-Site Scripting via Malicious Email Attachment Content-Type Header
CVSS 9.3
CVE-2024-41381 MEDIUM
microweber 2.0.16 - Cross-Site Scripting via admin.php
CVSS 6.1
CVE-2024-41380 MEDIUM
microweber 2.0.16 - Cross-Site Scripting via add_tagging_tagged.php
CVSS 6.1
CVE-2024-6710 MEDIUM
Ditty < 3.1.46 - Authenticated Stored Cross-Site Scripting
CVSS 5.4
CVE-2024-6498 MEDIUM
Collect.chat WordPress <2.4.4 - XSS
CVSS 4.8
CVE-2024-6270 MEDIUM
Community Events WordPress <1.5.1 - XSS
CVSS 4.8
CVE-2024-3636 MEDIUM
Pinpoint Booking System < 2.9.9.4.8 - Authenticated Stored Cross-Site Scripting via Settings
CVSS 5.4
CVE-2024-7466 LOW
PMWeb 7.2.00 - Cross-Site Scripting
CVSS 2.4
CVE-2024-7453 LOW
FastAdmin 1.5.0.20240328 - Cross-Site Scripting in Attachment Management Section
CVSS 2.4
CVE-2024-7356 MEDIUM
Zephyr Project Manager <= 3.3.100 - Authenticated Stored Cross-Site Scripting via Filename Parameter
CVSS 6.4
CVE-2024-6390 MEDIUM
Quiz and Survey Master <9.1.0 - XSS
CVSS 5.9
CVE-2024-33893 MEDIUM
ewon Cosy+ Firmware 21.x < 21.2s10 and 22.x < 22.1s3 - Cross-Site Scripting in Log Display
CVSS 6.1
CVE-2024-41519 MEDIUM
Feripro <= 2.2.3 - Cross-Site Scripting via School Input Field
CVSS 5.4
CVE-2024-7204 MEDIUM
Ai3 QbiBot < 8.0.9.02 - Unauthenticated Stored Cross-Site Scripting in Chat Box
CVSS 6.1
CVE-2024-6704 MEDIUM
Comments - wpDiscuz <= 7.6.21 - Unauthenticated HTML Injection in Comments
CVSS 5.3
CVE-2024-4643 MEDIUM
Element Pack Elementor Addons <= 5.7.1 - Authenticated Stored Cross-Site Scripting via end_redirect_link Parameter
CVSS 6.4
CVE-2024-5595 MEDIUM
Essential Blocks < 4.7.0 - Stored Cross-Site Scripting via Block Options
CVSS 5.4
CVE-2024-3827 MEDIUM
Spectra Pro <= 1.1.4 - Authenticated Stored Cross-Site Scripting via Block IDs
CVSS 6.4
CVE-2024-39647 HIGH
Message Filter for Contact Form 7 <= 1.6.1.1 - Cross-Site Scripting
CVSS 7.1
Details
Vulnerabilities 45,503
Exploit Likelihood High