VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (46,608)

page 103 of 2,331
  • CVE-2025-7429HigNov 11, 2025
    risk 0.47cvss 7.3epss 0.00

    Zohocorp ManageEngine Exchange Reporter Plus versions 5723 and below are vulnerable to the Stored XSS Vulnerability in the Mails Deleted or Moved report.

  • CVE-2025-54167HigNov 7, 2025
    risk 0.47cvss epss 0.01

    A cross-site scripting (XSS) vulnerability has been reported to affect Notification Center. If a remote attacker gains an administrator account, they can then exploit the vulnerability to bypass security mechanisms or read application data. We have already fixed the…

  • CVE-2025-63417HigNov 5, 2025
    risk 0.47cvss 7.2epss 0.00

    A Stored Cross-Site Scripting (XSS) vulnerability in the chat functionality of the SelfBest platform 2023.3 allows authenticated attackers to inject arbitrary web scripts or HTML via the chat message input field. This malicious content is stored and then executed in the context…

  • CVE-2025-63441HigNov 3, 2025
    risk 0.47cvss 7.3epss 0.00

    Open Source Social Network (OSSN) 8.6 is vulnerable to Cross Site Scripting (XSS) via the parameter param` at endpoint u/administrator/friends.

  • CVE-2025-11995HigNov 1, 2025
    risk 0.47cvss 7.2epss 0.00

    The Community Events plugin for WordPress is vulnerable to Stored Cross-Site Scripting via event details parameter in all versions up to, and including, 1.5.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to…

  • CVE-2025-60880HigOct 10, 2025
    risk 0.47cvss 8.3epss 0.00

    An authenticated stored XSS vulnerability exists in the Bagisto 2.3.6 admin panel's product creation path, allowing an attacker to upload a crafted SVG file containing malicious JavaScript code. This vulnerability can be exploited by an authenticated admin user to execute…

  • CVE-2025-60869HigOct 10, 2025
    risk 0.47cvss 7.3epss 0.00

    Publii CMS v0.46.5 (build 17089) allows persistent Cross-Site Scripting (XSS) via unsanitized input in configuration fields such as "Site Description" and "Footer Follow Buttons". An attacker can inject arbitrary JavaScript, which is stored in the project and executed in the…

  • CVE-2025-11189HigOct 10, 2025
    risk 0.47cvss 7.3epss 0.00

    The Kiwire Captive Portal contains a reflected cross-site scripting (XSS) vulnerability within the login-url parameter, allowing for Javascript execution.

  • CVE-2025-60967HigOct 6, 2025
    risk 0.47cvss 7.3epss 0.00

    Cross Site Scripting (XSS) vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0076-000 Ver 4.00 allows attackers to gain sensitive information.

  • CVE-2025-60958HigOct 6, 2025
    risk 0.47cvss 7.3epss 0.00

    Cross Site Scripting (XSS) vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 Ver 4.00 allows attackers to gain sensitive information.

  • CVE-2025-50538HigOct 6, 2025
    risk 0.47cvss 8.2epss 0.13

    Flowise before 3.0.5 allows XSS via an IFRAME element when an admin views the chat log.

  • CVE-2025-57424HigSep 29, 2025
    risk 0.47cvss 7.3epss 0.00

    A stored cross-site scripting (XSS) vulnerability exists in the MyCourts v3 application within the LTA number profile field. An attacker can insert arbitrary JavaScript into their profile, which executes in the browser of any user viewing it, including administrators. Due to the…

  • CVE-2025-55888HigSep 22, 2025
    risk 0.47cvss 7.3epss 0.00

    Cross-Site Scripting (XSS) vulnerability was discovered in the Ajax transaction manager endpoint of ARD. An attacker can intercept the Ajax response and inject malicious JavaScript into the accountName field. This input is not properly sanitized or encoded when rendered,…

  • CVE-2025-57150HigSep 3, 2025
    risk 0.47cvss 7.2epss 0.01

    phpgurukul Complaint Management System in PHP 2.0 is vulnerable to Cross Site Scripting (XSS) in admin/subcategory.php via the categoryName parameter.

  • CVE-2025-55618HigAug 27, 2025
    risk 0.47cvss 7.3epss 0.00

    In Hyundai Navigation App STD5W.EUR.HMC.230516.afa908d, an attacker can inject HTML payloads in the profile name field in navigation app which then get rendered.

  • CVE-2025-50891HigAug 19, 2025
    risk 0.47cvss 7.2epss 0.00

    The server-side backend for Adform Site Tracking before 2025-08-28 allows attackers to inject HTML or execute arbitrary code via cookie hijacking. NOTE: a customer does not need to take any action to update locally installed software (such as Adform Site Tracking 1.1).

  • CVE-2025-8798HigAug 10, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was found in oitcode samarium up to 0.9.6. It has been classified as critical. Affected is an unknown function of the file /dashboard/product of the component Create Product Page. The manipulation leads to unrestricted upload. It is possible to launch the attack…

  • CVE-2025-7050HigAug 5, 2025
    risk 0.47cvss 7.2epss 0.00

    The Use-your-Drive | Google Drive plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' parameter in file metadata in all versions up to, and including, 3.3.1 due to insufficient input sanitization and output escaping. This makes…

  • CVE-2025-26065HigAug 4, 2025
    risk 0.47cvss 7.3epss 0.00

    A cross-site scripting (XSS) vulnerability in Intelbras RX1500 v2.2.9 and RX3000 v1.0.11 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the name of a visiting Wi-Fi network.

  • CVE-2025-7725HigAug 1, 2025
    risk 0.47cvss 7.2epss 0.00

    The Photos, Files, YouTube, Twitter, Instagram, TikTok, Ecommerce Contest Gallery – Upload, Vote, Sell via PayPal or Stripe, Social Share Buttons, OpenAI plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the comment feature in all versions up to, and…