CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Description
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85
CVEs mapped to this weakness (46,610)
page 2062 of 2,331| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-5555 | Med | 0.00 | 6.1 | 0.00 | Oct 12, 2023 | Cross-site Scripting (XSS) - Generic in GitHub repository frappe/lms prior to 5614a6203fb7d438be8e2b1e3030e4528d170ec4. | ||
| CVE-2023-44393 | Cri | 0.00 | 9.3 | 0.01 | Oct 9, 2023 | Piwigo is an open source photo gallery application. Prior to version 14.0.0beta4, a reflected cross-site scripting (XSS) vulnerability is in the` /admin.php?page=plugins&tab=new&installstatus=ok&plugin_id=[here]` page. This vulnerability can be exploited by an attacker to inject… | ||
| CVE-2023-5351 | Med | 0.00 | 5.4 | 0.00 | Oct 3, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository salesagility/suitecrm prior to 7.14.1. | ||
| CVE-2023-43657 | Hig | 0.00 | 7.2 | 0.00 | Sep 28, 2023 | discourse-encrypt is a plugin that provides a secure communication channel through Discourse. Improper escaping of encrypted topic titles could lead to a cross site scripting (XSS) issue when a site has content security policy (CSP) headers disabled. Having CSP disabled is a… | ||
| CVE-2023-44276 | Med | 0.00 | 5.4 | 0.01 | Sep 28, 2023 | OPNsense before 23.7.5 allows XSS via the index.php sequence parameter to the Lobby Dashboard. | ||
| CVE-2023-44275 | Med | 0.00 | 5.4 | 0.01 | Sep 28, 2023 | OPNsense before 23.7.5 allows XSS via the index.php column_count parameter to the Lobby Dashboard. | ||
| CVE-2023-5084 | Low | 0.00 | 3.9 | 0.00 | Sep 20, 2023 | Cross-site Scripting (XSS) - Reflected in GitHub repository hestiacp/hestiacp prior to 1.8.8. | ||
| CVE-2023-42452 | Med | 0.00 | 6.1 | 0.00 | Sep 19, 2023 | Mastodon is a free, open-source social network server based on ActivityPub. In versions on the 4.x branch prior to versions 4.0.10, 4.2.8, and 4.2.0-rc2, under certain conditions, attackers can abuse the translation feature to bypass the server-side HTML sanitization, allowing… | ||
| CVE-2023-39612 | Cri | 0.00 | 9.0 | 0.01 | Sep 16, 2023 | A cross-site scripting (XSS) vulnerability in FileBrowser before v2.23.0 allows an authenticated attacker to escalate privileges to Administrator via user interaction with a crafted HTML file or URL. | ||
| CVE-2023-4879 | Med | 0.00 | 4.8 | 0.00 | Sep 10, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository instantsoft/icms2 prior to 2.16.1.-git. | ||
| CVE-2023-41316 | Med | 0.00 | 5.5 | 0.00 | Sep 7, 2023 | Tolgee is an open-source localization platform. Due to lack of validation field - Org Name, bad actor can send emails with HTML injected code to the victims. Registered users can inject HTML into unsanitized emails from the Tolgee instance to other users. This unsanitized HTML… | ||
| CVE-2023-4655 | Med | 0.00 | 6.1 | 0.00 | Aug 31, 2023 | Cross-site Scripting (XSS) - Reflected in GitHub repository instantsoft/icms2 prior to 2.16.1. | ||
| CVE-2023-4653 | Med | 0.00 | 4.8 | 0.00 | Aug 31, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository instantsoft/icms2 prior to 2.16.1-git. | ||
| CVE-2023-4652 | Med | 0.00 | 5.4 | 0.01 | Aug 31, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository instantsoft/icms2 prior to 2.16.1-git. | ||
| CVE-2023-4561 | Med | 0.00 | 4.8 | 0.01 | Aug 28, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository omeka/omeka-s prior to 4.0.4. | ||
| CVE-2020-19952 | Med | 0.00 | 6.1 | 0.01 | Aug 11, 2023 | Cross Site Scripting (XSS) vulnerability in Rendering Engine in jbt Markdown Editor thru commit 2252418c27dffbb35147acd8ed324822b8919477, allows remote attackers to execute arbirary code via crafted payload or opening malicious .md file. | ||
| CVE-2023-39955 | Low | 0.00 | 3.5 | 0.01 | Aug 10, 2023 | Notes is a note-taking app for Nextcloud, an open-source cloud platform. Starting in version 4.4.0 and prior to version 4.8.0, when creating a note file with HTML, the content is rendered in the preview instead of the file being offered to download. Nextcloud Notes app version… | ||
| CVE-2023-39007 | Cri | 0.00 | 9.6 | 0.03 | Aug 9, 2023 | /ui/cron/item/open in the Cron component of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allows XSS via openAction in app/controllers/OPNsense/Cron/ItemController.php. | ||
| CVE-2023-39006 | Med | 0.00 | 5.4 | 0.00 | Aug 9, 2023 | The Crash Reporter (crash_reporter.php) component of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 mishandles input sanitization. | ||
| CVE-2023-39002 | Med | 0.00 | 6.1 | 0.01 | Aug 9, 2023 | A cross-site scripting (XSS) vulnerability in the act parameter of system_certmanager.php in OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload. |
- risk 0.00cvss 6.1epss 0.00
Cross-site Scripting (XSS) - Generic in GitHub repository frappe/lms prior to 5614a6203fb7d438be8e2b1e3030e4528d170ec4.
- risk 0.00cvss 9.3epss 0.01
Piwigo is an open source photo gallery application. Prior to version 14.0.0beta4, a reflected cross-site scripting (XSS) vulnerability is in the` /admin.php?page=plugins&tab=new&installstatus=ok&plugin_id=[here]` page. This vulnerability can be exploited by an attacker to inject…
- risk 0.00cvss 5.4epss 0.00
Cross-site Scripting (XSS) - Stored in GitHub repository salesagility/suitecrm prior to 7.14.1.
- risk 0.00cvss 7.2epss 0.00
discourse-encrypt is a plugin that provides a secure communication channel through Discourse. Improper escaping of encrypted topic titles could lead to a cross site scripting (XSS) issue when a site has content security policy (CSP) headers disabled. Having CSP disabled is a…
- risk 0.00cvss 5.4epss 0.01
OPNsense before 23.7.5 allows XSS via the index.php sequence parameter to the Lobby Dashboard.
- risk 0.00cvss 5.4epss 0.01
OPNsense before 23.7.5 allows XSS via the index.php column_count parameter to the Lobby Dashboard.
- risk 0.00cvss 3.9epss 0.00
Cross-site Scripting (XSS) - Reflected in GitHub repository hestiacp/hestiacp prior to 1.8.8.
- risk 0.00cvss 6.1epss 0.00
Mastodon is a free, open-source social network server based on ActivityPub. In versions on the 4.x branch prior to versions 4.0.10, 4.2.8, and 4.2.0-rc2, under certain conditions, attackers can abuse the translation feature to bypass the server-side HTML sanitization, allowing…
- risk 0.00cvss 9.0epss 0.01
A cross-site scripting (XSS) vulnerability in FileBrowser before v2.23.0 allows an authenticated attacker to escalate privileges to Administrator via user interaction with a crafted HTML file or URL.
- risk 0.00cvss 4.8epss 0.00
Cross-site Scripting (XSS) - Stored in GitHub repository instantsoft/icms2 prior to 2.16.1.-git.
- risk 0.00cvss 5.5epss 0.00
Tolgee is an open-source localization platform. Due to lack of validation field - Org Name, bad actor can send emails with HTML injected code to the victims. Registered users can inject HTML into unsanitized emails from the Tolgee instance to other users. This unsanitized HTML…
- risk 0.00cvss 6.1epss 0.00
Cross-site Scripting (XSS) - Reflected in GitHub repository instantsoft/icms2 prior to 2.16.1.
- risk 0.00cvss 4.8epss 0.00
Cross-site Scripting (XSS) - Stored in GitHub repository instantsoft/icms2 prior to 2.16.1-git.
- risk 0.00cvss 5.4epss 0.01
Cross-site Scripting (XSS) - Stored in GitHub repository instantsoft/icms2 prior to 2.16.1-git.
- risk 0.00cvss 4.8epss 0.01
Cross-site Scripting (XSS) - Stored in GitHub repository omeka/omeka-s prior to 4.0.4.
- risk 0.00cvss 6.1epss 0.01
Cross Site Scripting (XSS) vulnerability in Rendering Engine in jbt Markdown Editor thru commit 2252418c27dffbb35147acd8ed324822b8919477, allows remote attackers to execute arbirary code via crafted payload or opening malicious .md file.
- risk 0.00cvss 3.5epss 0.01
Notes is a note-taking app for Nextcloud, an open-source cloud platform. Starting in version 4.4.0 and prior to version 4.8.0, when creating a note file with HTML, the content is rendered in the preview instead of the file being offered to download. Nextcloud Notes app version…
- risk 0.00cvss 9.6epss 0.03
/ui/cron/item/open in the Cron component of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allows XSS via openAction in app/controllers/OPNsense/Cron/ItemController.php.
- risk 0.00cvss 5.4epss 0.00
The Crash Reporter (crash_reporter.php) component of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 mishandles input sanitization.
- risk 0.00cvss 6.1epss 0.01
A cross-site scripting (XSS) vulnerability in the act parameter of system_certmanager.php in OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.