VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (46,539)

page 10 of 2,327
  • CVE-2022-45938CriJun 2, 2023
    risk 0.62cvss 9.0epss 0.45

    An issue was discovered in Comcast Defined Technologies microeisbss through 2021. An attacker can inject a stored XSS payload in the Device ID field under Inventory Management to achieve Remote Code Execution and privilege escalation..

  • CVE-2023-31703CriMay 17, 2023
    risk 0.62cvss 9.0epss 0.04

    Cross Site Scripting (XSS) in the edit user form in Microworld Technologies eScan management console 14.0.1400.2281 allows remote attacker to inject arbitrary code via the from parameter.

  • CVE-2020-19947CriMar 16, 2023
    risk 0.62cvss 9.6epss 0.01

    Cross Site Scripting vulnerability found in Markdown Edit allows a remote attacker to execute arbitrary code via the edit parameter of the webpage.

  • CVE-2021-33387CriFeb 24, 2023
    risk 0.62cvss 9.6epss 0.01

    Cross Site Scripting Vulnerability in MiniCMS v.1.10 allows attacker to execute arbitrary code via a crafted get request.

  • CVE-2022-40004CriDec 15, 2022
    risk 0.62cvss 9.6epss 0.01

    Cross Site Scripting (XSS) vulnerability in Things Board 3.4.1 allows remote attackers to escalate privilege via crafted URL to the Audit Log.

  • CVE-2022-46332CriDec 6, 2022
    risk 0.62cvss 9.6epss 0.01

    The Admin Smart Search feature in Proofpoint Enterprise Protection (PPS/PoD) contains a stored cross-site scripting vulnerability that enables an anonymous email sender to gain admin privileges within the user interface. This affects all versions 8.19.0 and below.

  • CVE-2022-36180CriNov 22, 2022
    risk 0.62cvss 9.6epss 0.01

    Fusiondirectory 1.3 is vulnerable to Cross Site Scripting (XSS) via /fusiondirectory/index.php?message=[injection], /fusiondirectory/index.php?message=invalidparameter&plug={Injection], /fusiondirectory/index.php?signout=1&message=[injection]&plug=106.

  • CVE-2022-43143CriNov 21, 2022
    risk 0.62cvss 9.6epss 0.01

    A cross-site scripting (XSS) vulnerability in Beekeeper Studio v3.6.6 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the error modal container.

  • CVE-2022-42711CriOct 12, 2022
    risk 0.62cvss 9.6epss 0.01

    In Progress WhatsUp Gold before 22.1.0, an SNMP MIB Walker application endpoint failed to adequately sanitize malicious input. This could allow an unauthenticated attacker to execute arbitrary code in a victim's browser.

  • CVE-2022-38339CriSep 19, 2022
    risk 0.62cvss 9.6epss 0.01

    Safe Software FME Server v2021.2.5, v2022.0.0.2 and below contains a cross-site scripting (XSS) vulnerability which allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the login page.

  • CVE-2022-29168CriJun 25, 2022
    risk 0.62cvss 9.6epss 0.01

    Wire is a secure messaging application. Wire is vulnerable to arbitrary HTML and Javascript execution via insufficient escaping when rendering `@mentions` in the wire-webapp. If a user receives and views a malicious message, arbitrary code is injected and executed in the context…

  • CVE-2021-42136CriApr 13, 2022
    risk 0.62cvss 9.0epss 0.05

    A stored Cross-Site Scripting (XSS) vulnerability in the Missing Data Codes functionality of REDCap before 11.4.0 allows remote attackers to execute JavaScript code in the client's browser by storing said code as a Missing Data Code value. This can then be leveraged to execute a…

  • CVE-2021-37208CriMar 8, 2022
    risk 0.62cvss 9.6epss 0.01

    A vulnerability has been identified in RUGGEDCOM i800, RUGGEDCOM i800NC, RUGGEDCOM i801, RUGGEDCOM i801NC, RUGGEDCOM i802, RUGGEDCOM i802NC, RUGGEDCOM i803, RUGGEDCOM i803NC, RUGGEDCOM M2100, RUGGEDCOM M2100F, RUGGEDCOM M2100NC, RUGGEDCOM M2200, RUGGEDCOM M2200F, RUGGEDCOM…

  • CVE-2022-25395CriMar 2, 2022
    risk 0.62cvss 9.6epss 0.01

    Cosmetics and Beauty Product Online Store v1.0 was discovered to contain multiple reflected cross-site scripting (XSS) attacks via the search parameter under the /cbpos/ app.

  • CVE-2015-20105CriDec 2, 2021
    risk 0.62cvss 9.6epss 0.01

    The ClickBank Affiliate Ads WordPress plugin through 1.20 does not have CSRF check when saving its settings, allowing attacker to make logged in admin change them via a CSRF attack. Furthermore, due to the lack of escaping when they are outputting, it could also lead to Stored…

  • CVE-2021-23037CriSep 14, 2021
    risk 0.62cvss 9.6epss 0.01

    On all versions of 16.1.x, 16.0.x, 15.1.x, 14.1.x, 13.1.x, 12.1.x, and 11.6.x, a reflected cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an attacker to execute JavaScript in the context of the currently…

  • CVE-2021-22242HigAug 25, 2021
    risk 0.62cvss 8.7epss 0.64

    Insufficient input sanitization in Mermaid markdown in GitLab CE/EE version 11.4 and up allows an attacker to exploit a stored cross-site scripting vulnerability via a specially-crafted markdown

  • CVE-2021-22234CriAug 5, 2021
    risk 0.62cvss 9.6epss 0.01

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.11 before 13.11.7, all versions starting from 13.12 before 13.12.8, and all versions starting from 14.0 before 14.0.4. A specially crafted design image allowed attackers to read arbitrary files…

  • CVE-2021-29459CriApr 20, 2021
    risk 0.62cvss 9.6epss 0.01

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It is possible to persistently inject scripts in XWiki versions prior to 12.6.3 and 12.8. Unregistred users can fill simple text fields. Registered users can fill in their…

  • CVE-2021-28827CriApr 20, 2021
    risk 0.62cvss 9.6epss 0.01

    The Administration GUI component of TIBCO Software Inc.'s TIBCO Administrator - Enterprise Edition, TIBCO Administrator - Enterprise Edition, TIBCO Administrator - Enterprise Edition Distribution for TIBCO Silver Fabric, TIBCO Administrator - Enterprise Edition Distribution for…