VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (46,608)

page 112 of 2,331
  • CVE-2015-8256MedApr 17, 2017
    risk 0.47cvss 6.1epss 0.51

    Multiple cross-site scripting (XSS) vulnerabilities in Axis network cameras.

  • CVE-2016-1000119HigOct 21, 2016
    risk 0.47cvss 7.2epss 0.02

    SQLi and XSS in Huge IT catalog extension v1.0.4 for Joomla

  • CVE-2016-1000118HigOct 21, 2016
    risk 0.47cvss 7.2epss 0.02

    XSS & SQLi in HugeIT slideshow v1.0.4

  • CVE-2016-1000117HigOct 21, 2016
    risk 0.47cvss 7.2epss 0.02

    XSS & SQLi in HugeIT slideshow v1.0.4

  • CVE-2016-1000116HigOct 21, 2016
    risk 0.47cvss 7.2epss 0.02

    Huge-IT Portfolio Gallery manager v1.1.0 SQL Injection and XSS

  • CVE-2016-1000115HigOct 21, 2016
    risk 0.47cvss 7.2epss 0.03

    Huge-IT Portfolio Gallery manager v1.1.0 SQL Injection and XSS

  • CVE-2026-81760HigAug 28, 2026
    risk 0.46cvss 7.1epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetEngine allows Reflected XSS. This issue affects JetEngine: from n/a through 3.8.14.2.

  • CVE-2026-78293HigAug 27, 2026
    risk 0.46cvss 7.1epss 0.00

    Unauthenticated Cross Site Scripting (XSS) in WP w3all phpBB <= 3.0.6 versions.

  • CVE-2026-78289HigAug 27, 2026
    risk 0.46cvss 7.1epss 0.00

    Unauthenticated Cross Site Scripting (XSS) in CozyStay <= 1.10.0 versions.

  • CVE-2026-78283HigAug 27, 2026
    risk 0.46cvss 7.1epss 0.00

    Unauthenticated Cross Site Scripting (XSS) in Music Player for WooCommerce <= 1.8.9 versions.

  • CVE-2026-78281HigAug 27, 2026
    risk 0.46cvss 7.1epss 0.00

    Unauthenticated Cross Site Scripting (XSS) in CP Media Player <= 1.3.0 versions.

  • CVE-2026-78261HigAug 27, 2026
    risk 0.46cvss 7.1epss 0.00

    Unauthenticated Cross Site Scripting (XSS) in Realtyna Organic IDX plugin <= 5.4.1 versions.

  • CVE-2026-32258HigAug 26, 2026
    risk 0.46cvss 8.1epss 0.00

    Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. From 1.2.10 through 1.2.12, authenticated backend users with the backend.manage_editor permission can store custom Markup Styles that are compiled by the LESS parser and rendered…

  • CVE-2026-32257HigAug 26, 2026
    risk 0.46cvss 8.1epss 0.00

    Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. Prior to 1.2.13, custom CSS supplied through the Brand Settings Styles field by a backend user with the backend.manage_branding permission is compiled by the LESS parser and…

  • CVE-2026-16231HigAug 25, 2026
    risk 0.46cvss 8.1epss 0.00

    hbs is an Express view engine that wraps Handlebars. Its registerAsyncHelper API bypasses Handlebars' automatic HTML escaping: an async helper returns an opaque placeholder during the first render pass, so the double-brace expression escapes only the placeholder, and after…

  • CVE-2026-78282HigAug 24, 2026
    risk 0.46cvss 7.1epss 0.00

    Unauthenticated Cross Site Scripting (XSS) in Stripe Payments <= 2.1.2 versions.

  • CVE-2026-78264HigAug 24, 2026
    risk 0.46cvss 7.1epss 0.00

    Unauthenticated Cross Site Scripting (XSS) in Toolset Blocks <= 1.6.26 versions.

  • CVE-2026-78263HigAug 24, 2026
    risk 0.46cvss 7.1epss 0.00

    Unauthenticated Cross Site Scripting (XSS) in Event Tickets <= 5.29.2.1 versions.

  • CVE-2026-32556HigAug 24, 2026
    risk 0.46cvss 7.1epss 0.00

    Unauthenticated Cross Site Scripting (XSS) in Boost <= 2.0.4 versions.

  • CVE-2026-66623HigAug 24, 2026
    risk 0.46cvss 7.1epss 0.00

    Unauthenticated Cross Site Scripting (XSS) in Social Media & Share Icons <= 2.9.9 versions.