VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (46,608)

page 110 of 2,331
  • CVE-2023-26214HigFeb 22, 2023
    risk 0.47cvss 7.3epss 0.00

    The BusinessConnect UI component of TIBCO Software Inc.'s TIBCO BusinessConnect contains easily exploitable Reflected Cross Site Scripting (XSS) vulnerabilities that allow a low privileged attacker with network access to execute scripts targeting the affected system or the…

  • CVE-2022-41567HigFeb 22, 2023
    risk 0.47cvss 7.3epss 0.00

    The BusinessConnect UI component of TIBCO Software Inc.'s TIBCO BusinessConnect contains an easily exploitable vulnerability that allows a low privileged attacker with network access to execute a cross-site scripting (XSS) attack on the affected system. Affected releases are…

  • CVE-2023-0794HigFeb 12, 2023
    risk 0.47cvss 8.3epss 0.01

    Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.11.

  • CVE-2023-0791HigFeb 12, 2023
    risk 0.47cvss 8.3epss 0.01

    Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.11.

  • CVE-2022-38758HigJan 26, 2023
    risk 0.47cvss 7.2epss 0.00

    Cross-site Scripting (XSS) vulnerability in NetIQ iManager prior to version 3.2.6 allows attacker to execute malicious scripts on the user's browser. This issue affects: Micro Focus NetIQ iManager NetIQ iManager versions prior to 3.2.6 on ALL.

  • CVE-2023-0038HigJan 3, 2023
    risk 0.47cvss 7.2epss 0.01

    The "Survey Maker – Best WordPress Survey Plugin" plugin for WordPress is vulnerable to Stored Cross-Site Scripting via survey answers in versions up to, and including, 3.1.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated…

  • CVE-2022-23519HigDec 14, 2022
    risk 0.47cvss 7.2epss 0.01

    rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. Prior to version 1.4.4, a possible XSS vulnerability with certain configurations of Rails::Html::Sanitizer may allow an attacker to inject content if the application developer has overridden…

  • CVE-2022-4035HigNov 29, 2022
    risk 0.47cvss 7.2epss 0.01

    The Appointment Hour Booking plugin for WordPress is vulnerable to iFrame Injection via the ‘email’ or general field parameters in versions up to, and including, 1.3.72 due to insufficient input sanitization and output escaping that makes injecting iFrame tags possible. This…

  • CVE-2022-4032HigNov 29, 2022
    risk 0.47cvss 7.2epss 0.01

    The Quiz and Survey Master plugin for WordPress is vulnerable to iFrame Injection via the 'question[id]' parameter in versions up to, and including, 8.0.4 due to insufficient input sanitization and output escaping that allowed iframe tags to be injected. This makes it possible…

  • CVE-2022-4027HigNov 29, 2022
    risk 0.47cvss 7.2epss 0.01

    The Simple:Press plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'postitem' parameter manipulated during a forum response in versions up to, and including, 6.8 due to insufficient input sanitization and output escaping that makes injecting object and…

  • CVE-2022-2565HigSep 5, 2022
    risk 0.47cvss 7.2epss 0.01

    The Simple Payment Donations & Subscriptions WordPress plugin before 4.2.1 does not sanitise and escape user input given in its forms, which could allow unauthenticated attackers to perform Cross-Site Scripting attacks against admins

  • CVE-2022-30575HigAug 16, 2022
    risk 0.47cvss 7.3epss 0.01

    The Web Console component of TIBCO Software Inc.'s TIBCO Data Science - Workbench, TIBCO Statistica, TIBCO Statistica - Estore Edition, and TIBCO Statistica Trial contains easily exploitable Reflected Cross Site Scripting (XSS) vulnerabilities that allow a low privileged…

  • CVE-2022-28732MedAug 4, 2022
    risk 0.47cvss 6.1epss 0.82

    A carefully crafted request on WeblogPlugin could trigger an XSS vulnerability on Apache JSPWiki, which could allow the attacker to execute javascript in the victim's browser and get some sensitive information about the victim. Apache JSPWiki users should upgrade to 2.11.3 or…

  • CVE-2020-28455HigJul 25, 2022
    risk 0.47cvss 7.3epss 0.01

    This affects all versions of package markdown-it-toc. The title of the generated toc and the contents of the header are not escaped.

  • CVE-2022-2219HigJul 25, 2022
    risk 0.47cvss 7.2epss 0.02

    The Unyson WordPress plugin before 2.7.27 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting

  • CVE-2022-33098MedJul 7, 2022
    risk 0.47cvss 6.1epss 0.53

    Magnolia CMS v6.2.19 was discovered to contain a cross-site scripting (XSS) vulnerability via the Edit Contact function. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted SVG document, with JavaScript, for a profile picture.

  • CVE-2022-31470MedJun 7, 2022
    risk 0.47cvss 6.1epss 0.53

    An XSS vulnerability in the index_mobile_changepass.hsp reset-password section of Axigen Mobile WebMail before 10.2.3.12 and 10.3.x before 10.3.3.47 allows attackers to run arbitrary Javascript code that, using an active end-user session (for a logged-in user), can access and…

  • CVE-2021-32585HigApr 6, 2022
    risk 0.47cvss 7.2epss 0.01

    An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiWAN before 4.5.9 may allow an attacker to perform a stored cross-site scripting attack via specifically crafted HTTP requests.

  • CVE-2022-28650HigApr 5, 2022
    risk 0.47cvss 7.3epss 0.01

    In JetBrains YouTrack before 2022.1.43700 it was possible to inject JavaScript into Markdown in the YouTrack Classic UI

  • CVE-2022-0889HigMar 23, 2022
    risk 0.47cvss 7.2epss 0.01

    The Ninja Forms - File Uploads Extension WordPress plugin is vulnerable to reflected cross-site scripting due to missing sanitization of the files filename parameter found in the ~/includes/ajax/controllers/uploads.php file which can be used by unauthenticated attackers to add…