VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (46,610)

page 2062 of 2,331
  • CVE-2023-5555MedOct 12, 2023
    risk 0.00cvss 6.1epss 0.00

    Cross-site Scripting (XSS) - Generic in GitHub repository frappe/lms prior to 5614a6203fb7d438be8e2b1e3030e4528d170ec4.

  • CVE-2023-44393CriOct 9, 2023
    risk 0.00cvss 9.3epss 0.01

    Piwigo is an open source photo gallery application. Prior to version 14.0.0beta4, a reflected cross-site scripting (XSS) vulnerability is in the` /admin.php?page=plugins&tab=new&installstatus=ok&plugin_id=[here]` page. This vulnerability can be exploited by an attacker to inject…

  • CVE-2023-5351MedOct 3, 2023
    risk 0.00cvss 5.4epss 0.00

    Cross-site Scripting (XSS) - Stored in GitHub repository salesagility/suitecrm prior to 7.14.1.

  • CVE-2023-43657HigSep 28, 2023
    risk 0.00cvss 7.2epss 0.00

    discourse-encrypt is a plugin that provides a secure communication channel through Discourse. Improper escaping of encrypted topic titles could lead to a cross site scripting (XSS) issue when a site has content security policy (CSP) headers disabled. Having CSP disabled is a…

  • CVE-2023-44276MedSep 28, 2023
    risk 0.00cvss 5.4epss 0.01

    OPNsense before 23.7.5 allows XSS via the index.php sequence parameter to the Lobby Dashboard.

  • CVE-2023-44275MedSep 28, 2023
    risk 0.00cvss 5.4epss 0.01

    OPNsense before 23.7.5 allows XSS via the index.php column_count parameter to the Lobby Dashboard.

  • CVE-2023-5084LowSep 20, 2023
    risk 0.00cvss 3.9epss 0.00

    Cross-site Scripting (XSS) - Reflected in GitHub repository hestiacp/hestiacp prior to 1.8.8.

  • CVE-2023-42452MedSep 19, 2023
    risk 0.00cvss 6.1epss 0.00

    Mastodon is a free, open-source social network server based on ActivityPub. In versions on the 4.x branch prior to versions 4.0.10, 4.2.8, and 4.2.0-rc2, under certain conditions, attackers can abuse the translation feature to bypass the server-side HTML sanitization, allowing…

  • CVE-2023-39612CriSep 16, 2023
    risk 0.00cvss 9.0epss 0.01

    A cross-site scripting (XSS) vulnerability in FileBrowser before v2.23.0 allows an authenticated attacker to escalate privileges to Administrator via user interaction with a crafted HTML file or URL.

  • CVE-2023-4879MedSep 10, 2023
    risk 0.00cvss 4.8epss 0.00

    Cross-site Scripting (XSS) - Stored in GitHub repository instantsoft/icms2 prior to 2.16.1.-git.

  • CVE-2023-41316MedSep 7, 2023
    risk 0.00cvss 5.5epss 0.00

    Tolgee is an open-source localization platform. Due to lack of validation field - Org Name, bad actor can send emails with HTML injected code to the victims. Registered users can inject HTML into unsanitized emails from the Tolgee instance to other users. This unsanitized HTML…

  • CVE-2023-4655MedAug 31, 2023
    risk 0.00cvss 6.1epss 0.00

    Cross-site Scripting (XSS) - Reflected in GitHub repository instantsoft/icms2 prior to 2.16.1.

  • CVE-2023-4653MedAug 31, 2023
    risk 0.00cvss 4.8epss 0.00

    Cross-site Scripting (XSS) - Stored in GitHub repository instantsoft/icms2 prior to 2.16.1-git.

  • CVE-2023-4652MedAug 31, 2023
    risk 0.00cvss 5.4epss 0.01

    Cross-site Scripting (XSS) - Stored in GitHub repository instantsoft/icms2 prior to 2.16.1-git.

  • CVE-2023-4561MedAug 28, 2023
    risk 0.00cvss 4.8epss 0.01

    Cross-site Scripting (XSS) - Stored in GitHub repository omeka/omeka-s prior to 4.0.4.

  • CVE-2020-19952MedAug 11, 2023
    risk 0.00cvss 6.1epss 0.01

    Cross Site Scripting (XSS) vulnerability in Rendering Engine in jbt Markdown Editor thru commit 2252418c27dffbb35147acd8ed324822b8919477, allows remote attackers to execute arbirary code via crafted payload or opening malicious .md file.

  • CVE-2023-39955LowAug 10, 2023
    risk 0.00cvss 3.5epss 0.01

    Notes is a note-taking app for Nextcloud, an open-source cloud platform. Starting in version 4.4.0 and prior to version 4.8.0, when creating a note file with HTML, the content is rendered in the preview instead of the file being offered to download. Nextcloud Notes app version…

  • CVE-2023-39007CriAug 9, 2023
    risk 0.00cvss 9.6epss 0.03

    /ui/cron/item/open in the Cron component of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allows XSS via openAction in app/controllers/OPNsense/Cron/ItemController.php.

  • CVE-2023-39006MedAug 9, 2023
    risk 0.00cvss 5.4epss 0.00

    The Crash Reporter (crash_reporter.php) component of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 mishandles input sanitization.

  • CVE-2023-39002MedAug 9, 2023
    risk 0.00cvss 6.1epss 0.01

    A cross-site scripting (XSS) vulnerability in the act parameter of system_certmanager.php in OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.