VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (46,608)

page 104 of 2,331
  • CVE-2023-53155HigJul 25, 2025
    risk 0.47cvss 7.2epss 0.01

    goform/formTest in EmbedThis GoAhead 2.5 allows HTML injection via the name parameter.

  • CVE-2025-54075HigJul 18, 2025
    risk 0.47cvss 8.3epss 0.00

    MDC is a tool to take regular Markdown and write documents interacting deeply with a Vue component. Prior to version 0.17.2, a remote script-inclusion / stored cross-site scripting vulnerability in @nuxtjs/mdc lets a Markdown author inject a ``…

  • CVE-2025-3774HigJun 17, 2025
    risk 0.47cvss 7.2epss 0.00

    The Wise Chat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the X-Forwarded-For header in all versions up to, and including, 3.3.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject…

  • CVE-2025-48920HigJun 13, 2025
    risk 0.47cvss 7.3epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal etracker allows Cross-Site Scripting (XSS).This issue affects etracker: from 0.0.0 before 3.1.0.

  • CVE-2025-5303HigJun 7, 2025
    risk 0.47cvss 7.2epss 0.00

    The LTL Freight Quotes – Freightview Edition, LTL Freight Quotes – Daylight Edition and LTL Freight Quotes – Day & Ross Edition plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the expiry_date parameter in all versions up to, and including, 1.0.11,…

  • CVE-2025-4224HigJun 3, 2025
    risk 0.47cvss 7.2epss 0.00

    The wpForo + wpForo Advanced Attachments plugin for WordPress is vulnerable to Stored Cross-Site Scripting via media upload names in all versions up to, and including, 3.1.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…

  • CVE-2025-31501HigMay 28, 2025
    risk 0.47cvss 7.2epss 0.00

    Best Practical RT (Request Tracker) 5.0 through 5.0.7 allows XSS via JavaScript injection in an RT permalink.

  • CVE-2025-31500HigMay 28, 2025
    risk 0.47cvss 7.2epss 0.00

    Best Practical RT (Request Tracker) 5.0 through 5.0.7 allows XSS via JavaScript injection in an Asset name.

  • CVE-2025-30087HigMay 28, 2025
    risk 0.47cvss 7.2epss 0.00

    Best Practical RT (Request Tracker) 4.4 through 4.4.7 and 5.0 through 5.0.7 allows XSS via injection of crafted parameters in a search URL.

  • CVE-2025-4579HigMay 15, 2025
    risk 0.47cvss 7.2epss 0.00

    The WP Content Security Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the blocked-uri and effective-directive parameters in all versions up to, and including, 2.3 due to insufficient input sanitization and output escaping. This makes it possible…

  • CVE-2015-4582HigApr 28, 2025
    risk 0.47cvss 7.2epss 0.00

    The TheCartPress boot-store (aka Boot Store) theme 1.6.4 for WordPress allows header.php tcp_register_error XSS. NOTE: CVE-2015-4582 is not assigned to any Oracle product.

  • CVE-2025-46657HigApr 27, 2025
    risk 0.47cvss 7.2epss 0.00

    Karaz Karazal through 2025-04-14 allows reflected XSS via the lang parameter to the default URI.

  • CVE-2025-1294HigApr 24, 2025
    risk 0.47cvss 7.2epss 0.00

    The eForm - WordPress Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 4.18.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary…

  • CVE-2025-3809HigApr 19, 2025
    risk 0.47cvss 7.2epss 0.00

    The Debug Log Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the auto-refresh debug log in all versions up to, and including, 2.3.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to…

  • CVE-2025-30090HigApr 2, 2025
    risk 0.47cvss 7.2epss 0.00

    mime.php in SquirrelMail through 1.4.23-svn-20250401 and 1.5.x through 1.5.2-svn-20250401 allows XSS via e-mail headers, because JavaScript payloads are mishandled after $encoded has been set to true.

  • CVE-2025-3019HigMar 31, 2025
    risk 0.47cvss 7.2epss 0.00

    KNIME Business Hub is affected by several cross-site scripting vulnerabilities in its web pages. If a user clicks on a malicious link or opens a malicious web page, arbitrary Java Script may be executed with this user's permissions. This can lead to information loss and/or…

  • CVE-2024-58130HigMar 28, 2025
    risk 0.47cvss 7.2epss 0.00

    In app/Controller/Component/RestResponseComponent.php in MISP before 2.4.193, REST endpoints have a lack of sanitization for non-JSON responses.

  • CVE-2024-13690HigMar 25, 2025
    risk 0.47cvss 7.2epss 0.00

    The WP Church Donation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several donation form submission parameters in all versions up to, and including, 1.7 due to insufficient input sanitization and output escaping. This makes it possible for…

  • CVE-2025-25035HigMar 21, 2025
    risk 0.47cvss 7.3epss 0.00

    Improper Neutralization of Input During Web Page Generation Cross-site Scripting vulnerability in Jalios JPlatform 10 allows for Reflected XSS and Stored XSS.This issue affects JPlatform 10: before 10.0.8 (SP8), before 10.0.7 (SP7), before 10.0.6 (SP6) and Jalios Workplace 6.2,…

  • CVE-2025-2325HigMar 15, 2025
    risk 0.47cvss 7.2epss 0.00

    The WP Test Email plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Email Logs in all versions up to, and including, 1.1.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web…