VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (46,541)

page 1 of 2,328
  • CVE-2019-3929CriKEVApr 30, 2019
    risk 0.87cvss 9.8epss 0.99

    The Crestron AM-100 firmware 1.6.0.2, Crestron AM-101 firmware 2.7.0.1, Barco wePresent WiPG-1000P firmware 2.3.0.10, Barco wePresent WiPG-1600W before firmware 2.4.1.19, Extron ShareLink 200/250 firmware 2.0.3.4, Teq AV IT WIPS710 firmware 1.1.0.7, SHARP PN-L703WA firmware…

  • CVE-2023-34192CriKEVJul 6, 2023
    risk 0.77cvss 9.0epss 0.77

    Cross Site Scripting vulnerability in Zimbra ZCS v.8.8.15 allows a remote authenticated attacker to execute arbitrary code via a crafted script to the /h/autoSaveDraft function.

  • CVE-2019-18426HigKEVJan 21, 2020
    risk 0.74cvss 8.2epss 0.68

    A vulnerability in WhatsApp Desktop versions prior to 0.3.9309 when paired with WhatsApp for iPhone versions prior to 2.20.10 allows cross-site scripting and local file reading. Exploiting the vulnerability requires the victim to click a link preview from a specially crafted…

  • CVE-2024-42009CriKEVAug 5, 2024
    risk 0.72cvss 9.3epss 0.82

    A Cross-Site Scripting vulnerability in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to steal and send emails of a victim via a crafted e-mail message that abuses a Desanitization issue in message_body() in program/actions/mail/show.php.

  • CVE-2018-19943HigKEVOct 28, 2020
    risk 0.71cvss 8.0epss 0.18

    If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code. QNAP has already fixed these issues in the following QTS versions. QTS 4.4.2.1270 build 20200410 and later QTS 4.4.1.1261 build 20200330 and later QTS 4.3.6.1263 build…

  • CVE-2026-42897HigKEVMay 14, 2026
    risk 0.70cvss 8.1epss 0.71

    Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.

  • CVE-2022-47523CriJan 5, 2023
    risk 0.69cvss 9.8epss 0.71

    Zoho ManageEngine Access Manager Plus before 4309, Password Manager Pro before 12210, and PAM360 before 5801 are vulnerable to SQL Injection.

  • CVE-2025-44148CriJun 3, 2025
    risk 0.68cvss 9.8epss 0.61

    Cross Site Scripting (XSS) vulnerability in MailEnable before v10 allows a remote attacker to execute arbitrary code via the failure.aspx component

  • CVE-2021-31761CriApr 25, 2021
    risk 0.68cvss 9.6epss 0.34

    Webmin 1.973 is affected by reflected Cross Site Scripting (XSS) to achieve Remote Command Execution through Webmin's running process feature.

  • CVE-2023-50231CriMay 3, 2024
    risk 0.67cvss 9.6epss 0.53

    NETGEAR ProSAFE Network Management System saveNodeLabel Cross-Site Scripting Privilege Escalation Vulnerability. This vulnerability allows remote attackers to escalate privileges on affected installations of NETGEAR ProSAFE Network Management System. Minimal user interaction is…

  • CVE-2024-28741HigApr 6, 2024
    risk 0.66cvss 8.8epss 0.78

    Cross Site Scripting vulnerability in EginDemirbilek NorthStar C2 v1 allows a remote attacker to execute arbitrary code via the login.php component.

  • CVE-2023-49785CriMar 12, 2024
    risk 0.66cvss 9.1epss 0.83

    NextChat, also known as ChatGPT-Next-Web, is a cross-platform chat user interface for use with ChatGPT. Versions 2.11.2 and prior are vulnerable to server-side request forgery and cross-site scripting. This vulnerability enables read access to internal HTTP endpoints but also…

  • CVE-2023-48974CriFeb 8, 2024
    risk 0.66cvss 9.6epss 0.03

    Cross Site Scripting vulnerability in Axigen WebMail prior to 10.3.3.61 allows a remote attacker to escalate privileges via a crafted script to the serverName_input parameter.

  • CVE-2023-31546CriDec 14, 2023
    risk 0.66cvss 9.6epss 0.49

    Cross Site Scripting (XSS) vulnerability in DedeBIZ v6.0.3 allows attackers to run arbitrary code via the search feature.

  • CVE-2022-35698CriOct 14, 2022
    risk 0.66cvss 10.0epss 0.11

    Adobe Commerce versions 2.4.4-p1 (and earlier) and 2.4.5 (and earlier) are affected by a Stored Cross-site Scripting vulnerability. Exploitation of this issue does not require user interaction and could result in a post-authentication arbitrary code execution.

  • CVE-2022-28368CriApr 3, 2022
    risk 0.66cvss 9.8epss 0.82

    Dompdf 1.2.1 allows remote code execution via a .php file in the src:url field of an @font-face Cascading Style Sheets (CSS) statement (within an HTML input file).

  • CVE-2011-3642CriFeb 8, 2020
    risk 0.66cvss 9.6epss 0.09

    Cross-site scripting (XSS) vulnerability in Flowplayer Flash 3.2.7 through 3.2.16, as used in the News system (news) extension for TYPO3 and Mahara, allows remote attackers to inject arbitrary web script or HTML via the plugin configuration directive in a reference to an…

  • CVE-2025-10573CriDec 9, 2025
    risk 0.65cvss 9.6epss 0.34

    Stored XSS in Ivanti Endpoint Manager prior to version 2024 SU4 SR1 allows a remote unauthenticated attacker to execute arbitrary JavaScript in the context of an administrator session. User interaction is required.

  • CVE-2025-49410CriAug 20, 2025
    risk 0.65cvss 10.0epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Imran Emu TC Testimonials allows Stored XSS. This issue affects TC Testimonials: from n/a through 1.1.1.

  • CVE-2023-28849CriApr 5, 2023
    risk 0.65cvss 10.0epss 0.00

    GLPI is a free asset and IT management software package. Starting in version 10.0.0 and prior to version 10.0.7, GLPI inventory endpoint can be used to drive a SQL injection attack. It can also be used to store malicious code that could be used to perform XSS attack. By default,…