VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (46,608)

page 111 of 2,331
  • CVE-2022-0834HigMar 23, 2022
    risk 0.47cvss 7.2epss 0.01

    The Amelia WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and sanitization of the lastName parameter found in the ~/src/Application/Controller/User/Customer/AddCustomerController.php file which allows attackers to inject arbitrary web scripts…

  • CVE-2022-25307HigFeb 24, 2022
    risk 0.47cvss 7.2epss 0.01

    The WP Statistics WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and sanitization of the platform parameter found in the ~/includes/class-wp-statistics-hits.php file which allows attackers to inject arbitrary web scripts onto several pages…

  • CVE-2022-25306HigFeb 24, 2022
    risk 0.47cvss 7.2epss 0.01

    The WP Statistics WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and sanitization of the browser parameter found in the ~/includes/class-wp-statistics-visitor.php file which allows attackers to inject arbitrary web scripts onto several pages…

  • CVE-2022-0020MedFeb 10, 2022
    risk 0.47cvss 6.8epss 0.02

    A stored cross-site scripting (XSS) vulnerability in Palo Alto Network Cortex XSOAR web interface enables an authenticated network-based attacker to store a persistent javascript payload that will perform arbitrary actions in the Cortex XSOAR web interface on behalf of…

  • CVE-2021-42119HigNov 30, 2021
    risk 0.47cvss 7.3epss 0.01

    Persistent Cross Site Scripting in Web Applications operating on Business-DNA Solutions GmbH’s TopEase® Platform Version <= 7.1.27 via the Search Functionality allows authenticated users with Object Modification privileges to inject arbitrary HTML and JavaScript in object…

  • CVE-2021-32745HigJul 21, 2021
    risk 0.47cvss 7.3epss 0.01

    Collabora Online is a collaborative online office suite. A reflected XSS vulnerability was found in Collabora Online prior to version 6.4.9-5. An attacker could inject unescaped HTML into a variable as they created the Collabora Online iframe, and execute scripts inside the…

  • CVE-2021-32670HigJun 7, 2021
    risk 0.47cvss 7.2epss 0.01

    Datasette is an open source multi-tool for exploring and publishing data. The `?_trace=1` debugging feature in Datasette does not correctly escape generated HTML, resulting in a [reflected cross-site scripting](https://owasp.org/www-community/attacks/xss/#reflected-xss-attacks)…

  • CVE-2021-26812MedApr 14, 2021
    risk 0.47cvss 6.1epss 0.97

    Cross Site Scripting (XSS) in the Jitsi Meet 2.7 through 2.8.3 plugin for Moodle via the "sessionpriv.php" module. This allows attackers to craft a malicious URL, which when clicked on by users, can inject javascript code to be run by the application.

  • CVE-2021-20080MedApr 9, 2021
    risk 0.47cvss 6.1epss 0.93

    Insufficient output sanitization in ManageEngine ServiceDesk Plus before version 11200 and ManageEngine AssetExplorer before version 6800 allows a remote, unauthenticated attacker to conduct persistent cross-site scripting (XSS) attacks by uploading a crafted XML asset file.

  • CVE-2021-25299MedFeb 15, 2021
    risk 0.47cvss 6.1epss 0.98

    Nagios XI version xi-5.7.5 is affected by cross-site scripting (XSS). The vulnerability exists in the file /usr/local/nagiosxi/html/admin/sshterm.php due to improper sanitization of user-controlled input. A maliciously crafted URL, when clicked by an admin user, can be used to…

  • CVE-2020-35730MedKEVDec 28, 2020
    risk 0.47cvss 6.1epss 0.33

    An XSS issue was discovered in Roundcube Webmail before 1.2.13, 1.3.x before 1.3.16, and 1.4.x before 1.4.10. The attacker can send a plain text e-mail message, with JavaScript in a link reference element that is mishandled by linkref_addindex in rcube_string_replacer.php.

  • CVE-2020-13337HigOct 2, 2020
    risk 0.47cvss 7.2epss 0.01

    An issue has been discovered in GitLab affecting versions from 12.10 to 12.10.12 that allowed for a stored XSS payload to be added as a group name.

  • CVE-2020-15092HigJul 9, 2020
    risk 0.47cvss 7.2epss 0.01

    In TimelineJS before version 3.7.0, some user data renders as HTML. An attacker could implement an XSS exploit with maliciously crafted content in a number of data fields. This risk is present whether the source data for the timeline is stored on Google Sheets or in a JSON…

  • CVE-2020-1943MedApr 1, 2020
    risk 0.47cvss 6.1epss 0.97

    Data sent with contentId to /control/stream is not sanitized, allowing XSS attacks in Apache OFBiz 16.11.01 to 16.11.07.

  • CVE-2019-10475MedOct 23, 2019
    risk 0.47cvss 6.1epss 0.58

    A reflected cross-site scripting vulnerability in Jenkins build-metrics Plugin allows attackers to inject arbitrary HTML and JavaScript into web pages provided by this plugin.

  • CVE-2018-20911HigAug 1, 2019
    risk 0.47cvss 7.2epss 0.02

    cPanel before 70.0.23 allows code execution because "." is in @INC during a Perl syntax check of cpaddonsup (SEC-359).

  • CVE-2019-7255MedJul 2, 2019
    risk 0.47cvss 6.1epss 0.56

    Linear eMerge E3-Series devices allow XSS.

  • CVE-2019-3776HigMar 7, 2019
    risk 0.47cvss 7.2epss 0.01

    Pivotal Operations Manager, 2.1.x versions prior to 2.1.20, 2.2.x versions prior to 2.2.16, 2.3.x versions prior to 2.3.10, 2.4.x versions prior to 2.4.3, contains a reflected cross site scripting vulnerability. A remote user that is able to convince an Operations Manager user…

  • CVE-2018-14392MedJul 19, 2018
    risk 0.47cvss 6.1epss 0.49

    The New Threads plugin before 1.2 for MyBB has XSS.

  • CVE-2018-8831MedApr 18, 2018
    risk 0.47cvss 6.1epss 0.53

    A Persistent XSS vulnerability exists in Kodi (formerly XBMC) through 17.6 that allows the execution of arbitrary HTML/script code in the context of the victim user's browser via a playlist.