VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (46,543)

page 11 of 2,328
  • CVE-2020-5948CriDec 11, 2020
    risk 0.62cvss 9.6epss 0.01

    On BIG-IP versions 16.0.0-16.0.0.1, 15.1.0-15.1.0.5, 14.1.0-14.1.2.7, 13.1.0-13.1.3.4, 12.1.0-12.1.5.2, and 11.6.1-11.6.5.2, undisclosed endpoints in iControl REST allow for a reflected XSS attack, which could lead to a complete compromise of the BIG-IP system if the victim user…

  • CVE-2020-18766CriOct 26, 2020
    risk 0.62cvss 9.6epss 0.01

    A cross-site scripting (XSS) vulnerability AntSword v2.0.7 can remotely execute system commands.

  • CVE-2020-13340HigOct 8, 2020
    risk 0.62cvss 8.7epss 0.69

    An issue has been discovered in GitLab affecting all versions prior to 13.2.10, 13.3.7 and 13.4.2: Stored XSS in CI Job Log

  • CVE-2020-15781CriAug 14, 2020
    risk 0.62cvss 9.6epss 0.01

    A vulnerability has been identified in SICAM WEB firmware for SICAM A8000 RTUs (All versions < V05.30). The login screen does not sufficiently sanitize input, which enables an attacker to generate specially crafted log messages. If an unsuspecting victim views the log messages…

  • CVE-2014-5039CriJan 31, 2020
    risk 0.62cvss 9.6epss 0.01

    Cross-site scripting (XSS) vulnerability in Eucalyptus Management Console (EMC) 4.0.x before 4.0.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2019-17330CriNov 12, 2019
    risk 0.62cvss 9.6epss 0.01

    The Web server component of TIBCO Software Inc.'s TIBCO EBX contains multiple vulnerabilities that theoretically allow authenticated users to perform stored cross-site scripting (XSS) attacks, and unauthenticated users to perform reflected cross-site scripting attacks. Affected…

  • CVE-2019-18873CriNov 12, 2019
    risk 0.62cvss 9.0epss 0.08

    FUDForum 3.0.9 is vulnerable to Stored XSS via the User-Agent HTTP header. This may result in remote code execution. An attacker can use a user account to fully compromise the system via a GET request. When the admin visits user information under "User Manager" in the control…

  • CVE-2019-13923CriSep 13, 2019
    risk 0.62cvss 9.6epss 0.01

    A vulnerability has been identified in IE/WSN-PA Link WirelessHART Gateway (All versions). The integrated configuration web server of the affected device could allow Cross-Site Scripting (XSS) attacks if unsuspecting users are tricked into accessing a malicious link. User…

  • CVE-2019-7671CriJun 5, 2019
    risk 0.62cvss 9.0epss 0.08

    Prima Systems FlexAir, Versions 2.3.38 and prior. Parameters sent to scripts are not properly sanitized before being returned to the user, which may allow an attacker to execute arbitrary code in a user’s browser session in context of an affected site.

  • CVE-2014-1427CriApr 22, 2019
    risk 0.62cvss 9.6epss 0.01

    A vulnerability in the REST API of Ubuntu MAAS allows an attacker to cause a logged-in user to execute commands via cross-site scripting. This issue affects MAAS versions prior to 1.9.2.

  • CVE-2017-2336CriJul 17, 2017
    risk 0.62cvss 9.6epss 0.01

    A reflected cross site scripting vulnerability in NetScreen WebUI of Juniper Networks Juniper NetScreen Firewall+VPN running ScreenOS allows a network based attacker to inject HTML/JavaScript content into the management session of other users including the administrator. This…

  • CVE-2025-8668CriFeb 11, 2026
    risk 0.61cvss 9.4epss 0.00

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in E-Kalite Software Hardware Engineering Design and Internet Services Industry and Trade Ltd. Co. Turboard allows Reflected XSS. This issue affects Turboard: from 2025.07…

  • CVE-2025-64537CriDec 10, 2025
    risk 0.61cvss 9.3epss 0.01

    Adobe Experience Manager versions 6.5.23 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could lead to arbitrary code execution. An attacker could exploit this vulnerability by injecting malicious scripts into a web page that are executed in…

  • CVE-2025-54299CriJul 28, 2025
    risk 0.61cvss epss 0.00

    A stored XSS vulnerability in No Boss Testimonials component 1.0.0-3.0.0 and 4.0.0-4.0.2 for Joomla was discovered.

  • CVE-2025-54298CriJul 28, 2025
    risk 0.61cvss epss 0.00

    A stored XSS vulnerability in CommentBox component 1.0.0-1.1.0 for Joomla was discovered.

  • CVE-2024-10865CriMay 14, 2025
    risk 0.61cvss epss 0.00

    Improper Input validation leads to XSS or Cross-site Scripting vulnerability in OpenText Advanced Authentication. This issue affects Advanced Authentication versions before 6.5.

  • CVE-2024-57428CriFeb 6, 2025
    risk 0.61cvss 9.3epss 0.01

    A stored cross-site scripting (XSS) vulnerability in PHPJabbers Cinema Booking System v2.0 exists due to unsanitized input in file upload fields (event_img, seat_maps) and seat number configurations (number[new_X] in pjActionCreate). Attackers can inject persistent JavaScript,…

  • CVE-2024-54036CriDec 10, 2024
    risk 0.61cvss 9.3epss 0.01

    Adobe Connect versions 12.6, 11.4.7 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they…

  • CVE-2024-54034CriDec 10, 2024
    risk 0.61cvss 9.3epss 0.01

    Adobe Connect versions 12.6, 11.4.7 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the…

  • CVE-2024-54032CriDec 10, 2024
    risk 0.61cvss 9.3epss 0.01

    Adobe Connect versions 12.6, 11.4.7 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they…