VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (46,607)

page 20 of 2,331
  • CVE-2022-28101CriApr 28, 2022
    risk 0.59cvss 9.0epss 0.01

    Turtlapp Turtle Note v0.7.2.6 does not filter the tag during markdown parsing, allowing attackers to execute HTML injection.

  • CVE-2022-28464CriApr 27, 2022
    risk 0.59cvss 9.0epss 0.01

    Apifox through 2.1.6 is vulnerable to Cross Site Scripting (XSS) which can lead to remote code execution.

  • CVE-2022-1175HigApr 4, 2022
    risk 0.59cvss 8.7epss 0.82

    Improper neutralization of user input in GitLab CE/EE versions 14.4 before 14.7.7, all versions starting from 14.8 before 14.8.5, all versions starting from 14.9 before 14.9.2 allowed an attacker to exploit XSS by injecting HTML in notes.

  • CVE-2021-43047CriNov 16, 2021
    risk 0.59cvss 9.0epss 0.01

    The Interior Server and Gateway Server components of TIBCO Software Inc.'s TIBCO PartnerExpress contain easily exploitable Stored and Reflected Cross Site Scripting (XSS) vulnerabilities that allow a low privileged attacker to social engineer a legitimate user with network…

  • CVE-2021-24693CriNov 8, 2021
    risk 0.59cvss 9.0epss 0.01

    The Simple Download Monitor WordPress plugin before 3.9.5 does not escape the "File Thumbnail" post meta before outputting it in some pages, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks. Given the that XSS is triggered…

  • CVE-2021-35493CriSep 14, 2021
    risk 0.59cvss 9.0epss 0.01

    The WebFOCUS Reporting Server and WebFOCUS Client components of TIBCO Software Inc.'s TIBCO WebFOCUS Client, TIBCO WebFOCUS Installer, and TIBCO WebFOCUS Reporting Server contain easily exploitable Stored and Reflected Cross Site Scripting (XSS) vulnerabilities that allow a low…

  • CVE-2021-23038CriSep 14, 2021
    risk 0.59cvss 9.0epss 0.01

    On version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3.1, 14.1.x before 14.1.4.2, 13.1.x before 13.1.4.1, and all versions of 12.1.x, a stored cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an attacker to…

  • CVE-2020-27832CriMay 27, 2021
    risk 0.59cvss 9.0epss 0.01

    A flaw was found in Red Hat Quay, where it has a persistent Cross-site Scripting (XSS) vulnerability when displaying a repository's notification. This flaw allows an attacker to trick a user into performing a malicious action to impersonate the target user. The highest threat…

  • CVE-2021-21515CriMar 1, 2021
    risk 0.59cvss 9.0epss 0.01

    Dell EMC SourceOne, versions 7.2SP10 and prior, contain a Stored Cross-Site Scripting vulnerability. A remote low privileged attacker may potentially exploit this vulnerability, to hijack user sessions or to trick a victim application user to unknowingly send arbitrary requests…

  • CVE-2020-35129CriJan 19, 2021
    risk 0.59cvss 9.0epss 0.01

    Mautic before 3.2.4 is affected by stored XSS. An attacker with access to Social Monitoring, an application feature, could attack other users, including administrators. For example, an attacker could load an externally drafted JavaScript file that would allow them to eventually…

  • CVE-2020-35128CriJan 19, 2021
    risk 0.59cvss 9.0epss 0.02

    Mautic before 3.2.4 is affected by stored XSS. An attacker with permission to manage companies, an application feature, could attack other users, including administrators. For example, by loading an externally crafted JavaScript file, an attacker could eventually perform actions…

  • CVE-2020-35717CriJan 1, 2021
    risk 0.59cvss 9.0epss 0.04

    zonote through 0.4.0 allows XSS via a crafted note, with resultant Remote Code Execution (because nodeIntegration in webPreferences is true).

  • CVE-2020-2503CriDec 24, 2020
    risk 0.59cvss 9.0epss 0.01

    If exploited, this stored cross-site scripting vulnerability could allow remote attackers to inject malicious code in File Station. QNAP has already fixed these issues in QES 2.1.1 Build 20201006 and later.

  • CVE-2020-24445CriDec 10, 2020
    risk 0.59cvss 9.0epss 0.03

    AEM's Cloud Service offering, as well as version 6.5.6.0 (and below), are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a…

  • CVE-2020-29071CriNov 25, 2020
    risk 0.59cvss 9.0epss 0.02

    An XSS issue was found in the Shares feature of LiquidFiles before 3.3.19. The issue arises from the insecure rendering of HTML files uploaded to the platform as attachments, when the -htmlview URL is directly accessed. The impact ranges from executing commands as root on the…

  • CVE-2020-15952CriNov 5, 2020
    risk 0.59cvss 9.0epss 0.02

    Immuta v2.8.2 is affected by stored XSS that allows a low-privileged user to escalate privileges to administrative permissions. Additionally, unauthenticated attackers can phish unauthenticated Immuta users to steal credentials or force actions on authenticated users through…

  • CVE-2020-7750CriOct 21, 2020
    risk 0.59cvss 9.6epss 0.06

    This affects the package scratch-svg-renderer before 0.2.0-prerelease.20201019174008. The loadString function does not escape SVG properly, which can be used to inject arbitrary elements into the DOM via the _transformMeasurements function.

  • CVE-2020-13169CriSep 17, 2020
    risk 0.59cvss 9.0epss 0.02

    Stored XSS (Cross-Site Scripting) exists in the SolarWinds Orion Platform before before 2020.2.1 on multiple forms and pages. This vulnerability may lead to the Information Disclosure and Escalation of Privileges (takeover of administrator account).

  • CVE-2020-9742CriSep 10, 2020
    risk 0.59cvss 9.0epss 0.02

    AEM versions 6.5.5.0 (and below), 6.4.8.1 (and below) and 6.3.3.8 (and below) are affected by a stored XSS vulnerability that allows users with 'Author' privileges to store malicious scripts in fields associated with the Inbox calendar feature. These scripts may be executed in a…

  • CVE-2020-9741CriSep 10, 2020
    risk 0.59cvss 9.0epss 0.02

    The AEM forms add-on for versions 6.5.5.0 (and below) and 6.4.8.2 (and below) is affected by a stored XSS vulnerability that allows users with 'Author' privileges to store malicious scripts in fields associated with the Forms component. These scripts may be executed in a…