VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (46,610)

page 2061 of 2,331
  • CVE-2023-46448MedNov 1, 2023
    risk 0.00cvss 6.1epss 0.00

    Reflected Cross-Site Scripting (XSS) vulnerability in dmpop Mejiro Commit Versions Prior To 3096393 allows attackers to run arbitrary code via crafted string in metadata of uploaded images.

  • CVE-2023-5896MedNov 1, 2023
    risk 0.00cvss 5.4epss 0.00

    Cross-site Scripting (XSS) - Stored in GitHub repository pkp/pkp-lib prior to 3.4.0-4.

  • CVE-2023-5895MedNov 1, 2023
    risk 0.00cvss 5.4epss 0.00

    Cross-site Scripting (XSS) - DOM in GitHub repository pkp/pkp-lib prior to 3.3.0-16.

  • CVE-2023-5894MedNov 1, 2023
    risk 0.00cvss 5.4epss 0.00

    Cross-site Scripting (XSS) - Stored in GitHub repository pkp/ojs prior to 3.3.0-16.

  • CVE-2023-5892MedNov 1, 2023
    risk 0.00cvss 5.4epss 0.00

    Cross-site Scripting (XSS) - Stored in GitHub repository pkp/pkp-lib prior to 3.3.0-16.

  • CVE-2023-5891MedNov 1, 2023
    risk 0.00cvss 5.4epss 0.00

    Cross-site Scripting (XSS) - Reflected in GitHub repository pkp/pkp-lib prior to 3.3.0-16.

  • CVE-2023-5890MedNov 1, 2023
    risk 0.00cvss 5.4epss 0.00

    Cross-site Scripting (XSS) - Stored in GitHub repository pkp/pkp-lib prior to 3.3.0-16.

  • CVE-2023-46235MedOct 31, 2023
    risk 0.00cvss 5.4epss 0.00

    FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to version 1.5.10.15, due to a lack of request sanitization in the logs, a malicious request containing XSS would be stored in a log file. When an administrator of the FOG server logged in…

  • CVE-2023-43797MedOct 30, 2023
    risk 0.00cvss 6.3epss 0.00

    BigBlueButton is an open-source virtual classroom. Prior to versions 2.6.11 and 2.7.0-beta.3, Guest Lobby was vulnerable to cross-site scripting when users wait to enter the meeting due to inserting unsanitized messages to the element using unsafe innerHTML. Text sanitizing was…

  • CVE-2023-5835LowOct 28, 2023
    risk 0.00cvss 3.5epss 0.00

    A vulnerability classified as problematic was found in hu60t hu60wap6. Affected by this vulnerability is the function markdown of the file src/class/ubbparser.php. The manipulation leads to cross site scripting. The attack can be launched remotely. This product does not use…

  • CVE-2023-5811LowOct 27, 2023
    risk 0.00cvss 2.4epss 0.01

    A vulnerability, which was classified as problematic, was found in flusity CMS. Affected is the function loadPostAddForm of the file core/tools/posts.php. The manipulation of the argument menu_id leads to cross site scripting. It is possible to launch the attack remotely. The…

  • CVE-2023-5810LowOct 27, 2023
    risk 0.00cvss 2.4epss 0.00

    A vulnerability, which was classified as problematic, has been found in flusity CMS. This issue affects the function loadPostAddForm of the file core/tools/posts.php. The manipulation of the argument edit_post_id leads to cross site scripting. The attack may be initiated…

  • CVE-2023-5793LowOct 26, 2023
    risk 0.00cvss 3.5epss 0.00

    A vulnerability was found in flusity CMS and classified as problematic. This issue affects the function loadCustomBlocCreateForm of the file /core/tools/customblock.php of the component Dashboard. The manipulation of the argument customblock_place leads to cross site scripting.…

  • CVE-2023-34447HigOct 25, 2023
    risk 0.00cvss 8.8epss 0.01

    iTop is an open source, web-based IT service management platform. Prior to versions 3.0.4 and 3.1.0, on `pages/UI.php`, cross site scripting is possible. This issue is fixed in versions 3.0.4 and 3.1.0.

  • CVE-2023-34446HigOct 25, 2023
    risk 0.00cvss 8.8epss 0.01

    iTop is an open source, web-based IT service management platform. Prior to versions 3.0.4 and 3.1.0, when displaying `pages/preferences.php`, cross site scripting is possible. This issue is fixed in versions 3.0.4 and 3.1.0.

  • CVE-2023-46287MedOct 20, 2023
    risk 0.00cvss 6.1epss 0.01

    XSS exists in NagVis before 1.9.38 via the select function in share/server/core/functions/html.php.

  • CVE-2023-45958MedOct 18, 2023
    risk 0.00cvss 6.1epss 0.00

    Thirty Bees Core v1.4.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the backup_pagination parameter at /controller/AdminController.php. This vulnerability allows attackers to execute arbitrary JavaScript in the web browser of a user via a…

  • CVE-2023-43658HigOct 16, 2023
    risk 0.00cvss 8.0epss 0.01

    dicourse-calendar is a plugin for the Discourse messaging platform which adds the ability to create a dynamic calendar in the first post of a topic. Improper escaping of event titles could lead to Cross-site Scripting (XSS) within the 'email preview' UI when a site has CSP…

  • CVE-2023-4517MedOct 13, 2023
    risk 0.00cvss 5.4epss 0.00

    Cross-site Scripting (XSS) - Stored in GitHub repository hestiacp/hestiacp prior to 1.8.6.

  • CVE-2023-5556MedOct 12, 2023
    risk 0.00cvss 6.1epss 0.01

    Cross-site Scripting (XSS) - Reflected in GitHub repository structurizr/onpremises prior to 3194.