VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (46,607)

page 12 of 2,331
  • CVE-2024-49038CriNov 26, 2024
    risk 0.61cvss 9.3epss 0.01

    Improper neutralization of input during web page generation ('Cross-site Scripting') in Copilot Studio by an unauthorized attacker leads to elevation of privilege over a network.

  • CVE-2024-7873CriSep 17, 2024
    risk 0.61cvss epss 0.00

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting'), Improper Encoding or Escaping of Output, CWE - 83 Improper Neutralization of Script in Attributes in a Web Page vulnerability in Veribilim Software Veribase Order allows Stored XSS,…

  • CVE-2024-38108CriAug 13, 2024
    risk 0.61cvss 9.3epss 0.01

    Azure Stack Hub Spoofing Vulnerability

  • CVE-2024-6886CriAug 6, 2024
    risk 0.61cvss epss 0.33

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Gitea Gitea Open Source Git Server allows Stored XSS.This issue affects Gitea Open Source Git Server: 1.22.0.

  • CVE-2024-1451HigFeb 22, 2024
    risk 0.61cvss 8.7epss 0.51

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.9 before 16.9.1. A crafted payload added to the user profile page could lead to a stored XSS on the client side, allowing attackers to perform arbitrary actions on behalf of victims."

  • CVE-2024-23786CriFeb 14, 2024
    risk 0.61cvss 9.3epss 0.01

    Cross-site scripting vulnerability in Energy Management Controller with Cloud Services JH-RVB1 /JH-RV11 Ver.B0.1.9.1 and earlier allows a network-adjacent unauthenticated attacker to execute an arbitrary script on the web browser of the user who is accessing the management page…

  • CVE-2023-4523CriSep 27, 2023
    risk 0.61cvss 9.4epss 0.00

    Real Time Automation 460 Series products with versions prior to v8.9.8 are vulnerable to cross-site scripting, which could allow an attacker to run any JavaScript reference from the URL string. If this were to occur, the gateway's HTTP interface would redirect to the main page,…

  • CVE-2022-3572CriJan 26, 2023
    risk 0.61cvss 9.3epss 0.01

    A cross-site scripting issue has been discovered in GitLab CE/EE affecting all versions from 13.5 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2. It was possible to exploit a vulnerability in setting the Jira Connect integration which could lead to a reflected…

  • CVE-2022-43568HigNov 4, 2022
    risk 0.61cvss 8.8epss 0.43

    In Splunk Enterprise versions below 8.1.12, 8.2.9, and 9.0.2, a View allows for a Reflected Cross Site Scripting via JavaScript Object Notation (JSON) in a query parameter when output_mode=radio.

  • CVE-2021-32989CriMay 25, 2022
    risk 0.61cvss 9.3epss 0.02

    When a non-existent resource is requested, the LCDS LAquis SCADA application (version 4.3.1.1011 and prior) returns error messages which may allow reflected cross-site scripting.

  • CVE-2021-27442CriMay 16, 2022
    risk 0.61cvss 9.4epss 0.01

    The Weintek cMT product line is vulnerable to a cross-site scripting vulnerability, which could allow an unauthenticated remote attacker to inject malicious JavaScript code.

  • CVE-2021-43409CriNov 19, 2021
    risk 0.61cvss 9.3epss 0.01

    The “WPO365 | LOGIN” WordPress plugin (up to and including version 15.3) by wpo365.com is vulnerable to a persistent Cross-Site Scripting (XSS) vulnerability (also known as Stored or Second-Order XSS). Persistent XSS vulnerabilities occur when the application stores and…

  • CVE-2021-39906HigNov 5, 2021
    risk 0.61cvss 8.7epss 0.61

    Improper validation of ipynb files in GitLab CE/EE version 13.5 and above allows an attacker to execute arbitrary JavaScript code on the victim's behalf.

  • CVE-2021-24581HigAug 30, 2021
    risk 0.61cvss 8.8epss 0.04

    The Blue Admin WordPress plugin through 21.06.01 does not sanitise or escape its "Logo Title" setting before outputting in a page, leading to a Stored Cross-Site Scripting issue. Furthermore, the plugin does not have CSRF check in place when saving its settings, allowing the…

  • CVE-2021-32671CriJun 7, 2021
    risk 0.61cvss 10.0epss 0.40

    Flarum is a forum software for building communities. Flarum's translation system allowed for string inputs to be converted into HTML DOM nodes when rendered. This change was made after v0.1.0-beta.16 (our last beta before v1.0.0) and was not noticed or documented. This allowed…

  • CVE-2020-3955CriApr 29, 2020
    risk 0.61cvss 9.3epss 0.01

    ESXi 6.5 without patch ESXi650-201912104-SG and ESXi 6.7 without patch ESXi670-202004103-SG do not properly neutralize script-related HTML when viewing virtual machines attributes. VMware has evaluated the severity of this issue to be in the Important severity range with a…

  • CVE-2014-3919CriFeb 13, 2020
    risk 0.61cvss 9.3epss 0.01

    A vulnerability exists in Netgear CG3100 devices before 3.9.2421.13.mp3 V0027 via an embed malicious script in an unspecified page, which could let a malicious user obtain sensitive information.

  • CVE-2019-18345CriDec 12, 2019
    risk 0.61cvss 9.3epss 0.02

    A reflected XSS issue was discovered in DAViCal through 1.1.8. It echoes the action parameter without encoding. If a user visits an attacker-supplied link, the attacker can view all data the attacked user can view, as well as perform all actions in the name of the user. If the…

  • CVE-2019-5397CriAug 9, 2019
    risk 0.61cvss 9.4epss 0.05

    A remote bypass of security restrictions vulnerability was discovered in HPE 3PAR Service Processor version(s): prior to 5.0.5.1.

  • CVE-2019-9164HigMar 28, 2019
    risk 0.61cvss 8.8epss 0.46

    Command injection in Nagios XI before 5.5.11 allows an authenticated users to execute arbitrary remote commands via a new autodiscovery job.