CWE-79
High likelihoodImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
45,759 vulnerabilities with CWE-79
CVE-2026-57370
HIGH
WordPress Visitor Traffic Real Time Statistics Pro plugin <= 11.9.1 - Reflected Cross Site Scripting (XSS) vulnerability
CVSS 7.1
CVE-2026-27403
MEDIUM
WordPress Hubbub Lite plugin <= 1.36.3 - Cross Site Scripting (XSS) vulnerability
CVSS 6.5
CVE-2026-24628
MEDIUM
WordPress Photo Gallery by Supsystic plugin <= 1.16.3 - Cross Site Scripting (XSS) vulnerability
CVSS 5.9
CVE-2026-65756
MEDIUM
Joomla Extension - regularlabs.com - XSS vector in Keyboard Shortcuts extension
CVSS 6.1
CVE-2026-15794
MEDIUM
Grid/List View for WooCommerce <= 3.0.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'position' Shortcode Attribute
CVSS 6.4
CVE-2026-15647
MEDIUM
Brands for WooCommerce <= 3.8.8 - Authenticated (Shop Manager+) Stored Cross-Site Scripting via 'br_brand_tooltip' Term Meta Field
CVSS 4.4
CVE-2026-15646
MEDIUM
Brands for WooCommerce <= 3.8.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'style' Shortcode Attribute
CVSS 6.4
CVE-2026-15404
MEDIUM
Bulk Page Generator <= 2.5.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Post Title
CVSS 6.4
CVE-2026-15394
MEDIUM
Header Footer Script Adder <= 2.1 - Authenticated (Author+) Stored Cross-Site Scripting via 'asm_code' Snippet Meta
CVSS 6.4
CVE-2026-14481
MEDIUM
Equalize Digital Accessibility Checker <= 1.46.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'html' Parameter
CVSS 6.4
CVE-2026-9729
MEDIUM
Web Push Notifications <= 4.39.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'webpushr_notification_title' Post Meta Parameter
CVSS 6.4
CVE-2026-9635
MEDIUM
WP Shortcode by MyThemeShop <= 1.4.17 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'title' Shortcode Attribute
CVSS 6.4
CVE-2026-12421
HIGH
ARforms <= 7.2.1 - Unauthenticated Stored Cross-Site Scripting via 'password' Field Values
CVSS 7.2
CVE-2026-9577
MEDIUM
Post Status Notifier Lite < 1.13.0 - Reflected XSS via mod Parameter
CVSS 4.8
CVE-2026-9066
MEDIUM
WP Compress < 7.10.04 - Reflected XSS via test_zone
CVSS 6.1
CVE-2026-7534
HIGH
SUMO Reward Points for WooCommerce <= 32.7.0 - Unauthenticated Stored Cross-Site Scripting via 'reason' Parameter
CVSS 7.2
CVE-2026-7232
HIGH
FormCraft <= 3.9.14 - Unauthenticated Stored Cross-Site Scripting via Matrix Field Sub-Parameters
CVSS 7.2
CVE-2026-64795
MEDIUM
Joomla Extension - regularlabs.com - XSS vectors in tag-provided inputs in various Regular Labs extensions
CVSS 5.4
CVE-2026-63281
MEDIUM
Regular Labs Joomla Extensions - Stored Cross-Site Scripting in Conditions
CVSS 4.8
CVE-2026-64828
MEDIUM
Froiden TableTrack 1.3.10 Stored XSS via Order Notes Field
CVSS 6.1
CVE-2026-8152
CRITICAL
Unblu Spark Open Redirect leading to DOM-Based XSS
CVE-2026-65597
MEDIUM
n8n before 1.123.64 DOM-Based XSS via Unsandboxed iframe
CVSS 5.4
CVE-2026-65592
MEDIUM
n8n before 1.123.64 Stored DOM XSS via cachedResultUrl
CVSS 5.4
CVE-2026-63264
MEDIUM
Joomla Extension - joomshopping.com - Reflective XSS in JoomShopping < 5.9.3
CVE-2026-15787
MEDIUM
Ultimate Addons For Elementor < 2.9.1 - XSS
CVSS 6.4
Details
Vulnerabilities
45,759
Exploit Likelihood
High