CWE-79

High likelihood

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Parent: CWE-74 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

45,759 vulnerabilities with CWE-79
CVE-2026-57370 HIGH
WordPress Visitor Traffic Real Time Statistics Pro plugin <= 11.9.1 - Reflected Cross Site Scripting (XSS) vulnerability
CVSS 7.1
CVE-2026-27403 MEDIUM
WordPress Hubbub Lite plugin <= 1.36.3 - Cross Site Scripting (XSS) vulnerability
CVSS 6.5
CVE-2026-24628 MEDIUM
WordPress Photo Gallery by Supsystic plugin <= 1.16.3 - Cross Site Scripting (XSS) vulnerability
CVSS 5.9
CVE-2026-65756 MEDIUM
Joomla Extension - regularlabs.com - XSS vector in Keyboard Shortcuts extension
CVSS 6.1
CVE-2026-15794 MEDIUM
Grid/List View for WooCommerce <= 3.0.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'position' Shortcode Attribute
CVSS 6.4
CVE-2026-15647 MEDIUM
Brands for WooCommerce <= 3.8.8 - Authenticated (Shop Manager+) Stored Cross-Site Scripting via 'br_brand_tooltip' Term Meta Field
CVSS 4.4
CVE-2026-15646 MEDIUM
Brands for WooCommerce <= 3.8.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'style' Shortcode Attribute
CVSS 6.4
CVE-2026-15404 MEDIUM
Bulk Page Generator <= 2.5.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Post Title
CVSS 6.4
CVE-2026-15394 MEDIUM
Header Footer Script Adder <= 2.1 - Authenticated (Author+) Stored Cross-Site Scripting via 'asm_code' Snippet Meta
CVSS 6.4
CVE-2026-14481 MEDIUM
Equalize Digital Accessibility Checker <= 1.46.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'html' Parameter
CVSS 6.4
CVE-2026-9729 MEDIUM
Web Push Notifications <= 4.39.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'webpushr_notification_title' Post Meta Parameter
CVSS 6.4
CVE-2026-9635 MEDIUM
WP Shortcode by MyThemeShop <= 1.4.17 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'title' Shortcode Attribute
CVSS 6.4
CVE-2026-12421 HIGH
ARforms <= 7.2.1 - Unauthenticated Stored Cross-Site Scripting via 'password' Field Values
CVSS 7.2
CVE-2026-9577 MEDIUM
Post Status Notifier Lite < 1.13.0 - Reflected XSS via mod Parameter
CVSS 4.8
CVE-2026-9066 MEDIUM
WP Compress < 7.10.04 - Reflected XSS via test_zone
CVSS 6.1
CVE-2026-7534 HIGH
SUMO Reward Points for WooCommerce <= 32.7.0 - Unauthenticated Stored Cross-Site Scripting via 'reason' Parameter
CVSS 7.2
CVE-2026-7232 HIGH
FormCraft <= 3.9.14 - Unauthenticated Stored Cross-Site Scripting via Matrix Field Sub-Parameters
CVSS 7.2
CVE-2026-64795 MEDIUM
Joomla Extension - regularlabs.com - XSS vectors in tag-provided inputs in various Regular Labs extensions
CVSS 5.4
CVE-2026-63281 MEDIUM
Regular Labs Joomla Extensions - Stored Cross-Site Scripting in Conditions
CVSS 4.8
CVE-2026-64828 MEDIUM
Froiden TableTrack 1.3.10 Stored XSS via Order Notes Field
CVSS 6.1
CVE-2026-8152 CRITICAL
Unblu Spark Open Redirect leading to DOM-Based XSS
CVE-2026-65597 MEDIUM
n8n before 1.123.64 DOM-Based XSS via Unsandboxed iframe
CVSS 5.4
CVE-2026-65592 MEDIUM
n8n before 1.123.64 Stored DOM XSS via cachedResultUrl
CVSS 5.4
CVE-2026-63264 MEDIUM
Joomla Extension - joomshopping.com - Reflective XSS in JoomShopping < 5.9.3
CVE-2026-15787 MEDIUM
Ultimate Addons For Elementor < 2.9.1 - XSS
CVSS 6.4
Details
Vulnerabilities 45,759
Exploit Likelihood High