VYPR

CWE-707

Improper Neutralization

PillarIncomplete

Description

The product does not ensure or incorrectly ensures that structured messages or data are well-formed and that certain security properties are met before being read from an upstream component or sent to a downstream component.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-250 · CAPEC-276 · CAPEC-277 · CAPEC-278 · CAPEC-279 · CAPEC-3 · CAPEC-43 · CAPEC-468 · CAPEC-52 · CAPEC-53 · CAPEC-64 · CAPEC-7 · CAPEC-78 · CAPEC-79 · CAPEC-83 · CAPEC-84

CVEs mapped to this weakness (253)

page 9 of 13
  • CVE-2022-3503LowOct 14, 2022
    risk 0.23cvss 3.5epss 0.00

    A vulnerability was found in SourceCodester Purchase Order Management System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the component Supplier Handler. The manipulation of the argument Supplier Name/Address/Contact person/Contact leads…

  • CVE-2022-3502LowOct 14, 2022
    risk 0.23cvss 3.5epss 0.00

    A vulnerability was found in Human Resource Management System 1.0. It has been classified as problematic. This affects an unknown part of the component Leave Handler. The manipulation of the argument Reason leads to cross site scripting. It is possible to initiate the attack…

  • CVE-2022-3497LowOct 14, 2022
    risk 0.23cvss 3.5epss 0.00

    A vulnerability was found in SourceCodester Human Resource Management System 1.0. It has been classified as problematic. Affected is an unknown function of the component Master List. The manipulation of the argument city/state/country/position leads to cross site scripting. It…

  • CVE-2022-3493LowOct 13, 2022
    risk 0.23cvss 3.5epss 0.00

    A vulnerability, which was classified as problematic, has been found in SourceCodester Human Resource Management System 1.0. This issue affects some unknown processing of the component Add Employee Handler. The manipulation of the argument First Name/Middle Name/Last Name leads…

  • CVE-2022-3453LowOct 11, 2022
    risk 0.23cvss 3.5epss 0.00

    A vulnerability was found in SourceCodester Book Store Management System 1.0. It has been rated as problematic. This issue affects some unknown processing of the file /transcation.php. The manipulation of the argument buyer_name leads to cross site scripting. The attack may be…

  • CVE-2022-3452LowOct 11, 2022
    risk 0.23cvss 3.5epss 0.00

    A vulnerability was found in SourceCodester Book Store Management System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /category.php. The manipulation of the argument category_name leads to cross site scripting. The attack can be…

  • CVE-2022-3442LowOct 10, 2022
    risk 0.23cvss 3.5epss 0.00

    A vulnerability was found in Crealogix EBICS 7.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /ebics-server/ebics.aspx. The manipulation leads to cross site scripting. The attack may be launched remotely. The exploit has…

  • CVE-2022-3434LowOct 8, 2022
    risk 0.23cvss 3.5epss 0.01

    A vulnerability was found in SourceCodester Web-Based Student Clearance System. It has been rated as problematic. Affected by this issue is the function prepare of the file /Admin/add-student.php. The manipulation leads to cross site scripting. The attack may be launched…

  • CVE-2022-3333LowSep 28, 2022
    risk 0.23cvss 3.5epss 0.00

    A vulnerability, which was classified as problematic, was found in Zephyr Project Manager up to 3.2.4. Affected is an unknown function of the file /v1/tasks/create/ of the component REST Call Handler. The manipulation of the argument onanimationstart leads to cross site…

  • CVE-2026-10661MedJun 2, 2026
    risk 0.21cvss 4.3epss 0.00

    A vulnerability has been found in ahujasid blender-mcp up to 7636d13bded82eca58eb93c3f4cd8708dfdfbe8b. Impacted is the function Open of the file src/blender_mcp/server.py. The manipulation of the argument input_image_url leads to injection. Remote exploitation of the attack is…

  • CVE-2022-4064LowNov 19, 2022
    risk 0.17cvss 3.7epss 0.01

    A vulnerability was found in Dalli up to 3.2.2. It has been classified as problematic. Affected is the function self.meta_set of the file lib/dalli/protocol/meta/request_formatter.rb of the component Meta Protocol Handler. The manipulation of the argument cas/ttl leads to…

  • CVE-2025-9797LowSep 1, 2025
    risk 0.16cvss 2.4epss 0.00

    A vulnerability was determined in mrvautin expressCart up to b31302f4e99c3293bd742c6d076a721e168118b0. This impacts an unknown function of the file /admin/product/edit/ of the component Edit Product Page. This manipulation causes injection. The attack can be initiated remotely.…

  • CVE-2024-10842LowNov 5, 2024
    risk 0.16cvss 2.4epss 0.00

    A vulnerability, which was classified as problematic, has been found in romadebrian WEB-Sekolah 1.0. Affected by this issue is some unknown functionality of the file /Admin/Proses_Edit_Akun.php of the component Backend. The manipulation of the argument Username_Baru/Password…

  • CVE-2024-10840LowNov 5, 2024
    risk 0.16cvss 2.4epss 0.00

    A vulnerability classified as problematic has been found in romadebrian WEB-Sekolah 1.0. Affected is an unknown function of the file /Admin/akun_edit.php of the component Backend. The manipulation of the argument kode leads to cross site scripting. It is possible to launch the…

  • CVE-2024-10807LowNov 5, 2024
    risk 0.16cvss 2.4epss 0.00

    A vulnerability was found in PHPGurukul Hospital Management System 4.0. It has been rated as problematic. This issue affects some unknown processing of the file hms/doctor/search.php. The manipulation of the argument searchdata leads to cross site scripting. The attack may be…

  • CVE-2024-10806LowNov 5, 2024
    risk 0.16cvss 2.4epss 0.00

    A vulnerability was found in PHPGurukul Hospital Management System 4.0. It has been declared as problematic. This vulnerability affects unknown code of the file betweendates-detailsreports.php. The manipulation of the argument fromdate/todate leads to cross site scripting. The…

  • CVE-2022-4730LowDec 27, 2022
    risk 0.16cvss 3.5epss 0.01

    A vulnerability was found in Graphite Web. It has been classified as problematic. Affected is an unknown function of the component Absolute Time Range Handler. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been…

  • CVE-2022-4729LowDec 27, 2022
    risk 0.16cvss 3.5epss 0.01

    A vulnerability was found in Graphite Web and classified as problematic. This issue affects some unknown processing of the component Template Name Handler. The manipulation leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the…

  • CVE-2022-4728LowDec 27, 2022
    risk 0.16cvss 3.5epss 0.01

    A vulnerability has been found in Graphite Web and classified as problematic. This vulnerability affects unknown code of the component Cookie Handler. The manipulation leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the…

  • CVE-2022-4638LowDec 21, 2022
    risk 0.16cvss 3.5epss 0.00

    A vulnerability classified as problematic was found in collective.contact.widget up to 1.12. This vulnerability affects the function title of the file src/collective/contact/widget/widgets.py. The manipulation leads to cross site scripting. The attack can be initiated remotely.…