VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (46,610)

page 2063 of 2,331
  • CVE-2023-39000MedAug 9, 2023
    risk 0.00cvss 6.1epss 0.01

    A reflected cross-site scripting (XSS) vulnerability in the component /ui/diagnostics/log/core/ of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allows attackers to inject arbitrary JavaScript via the URL path.

  • CVE-2023-39518MedAug 8, 2023
    risk 0.00cvss 5.4epss 0.00

    social-media-skeleton is an uncompleted social media project implemented using PHP, MySQL, CSS, JavaScript, and HTML. Versions 1.0.0 until 1.0.3 have a stored cross-site scripting vulnerability. The problem is patched in v1.0.3.

  • CVE-2023-4189MedAug 5, 2023
    risk 0.00cvss 4.8epss 0.00

    Cross-site Scripting (XSS) - Reflected in GitHub repository instantsoft/icms2 prior to 2.16.1-git.

  • CVE-2023-4187MedAug 5, 2023
    risk 0.00cvss 4.8epss 0.00

    Cross-site Scripting (XSS) - Stored in GitHub repository instantsoft/icms2 prior to 2.16.1-git.

  • CVE-2023-4158MedAug 4, 2023
    risk 0.00cvss 5.4epss 0.00

    Cross-site Scripting (XSS) - Stored in GitHub repository omeka/omeka-s prior to 4.0.3.

  • CVE-2023-37467MedJul 28, 2023
    risk 0.00cvss 6.8epss 0.00

    Discourse is an open source discussion platform. Prior to version 3.1.0.beta7 of the `beta` and `tests-passed` branches, a CSP (Content Security Policy) nonce reuse vulnerability was discovered could allow cross-site scripting (XSS) attacks to bypass CSP protection for anonymous…

  • CVE-2023-3982MedJul 27, 2023
    risk 0.00cvss 4.8epss 0.00

    Cross-site Scripting (XSS) - Stored in GitHub repository omeka/omeka-s prior to 4.0.2.

  • CVE-2023-3980MedJul 27, 2023
    risk 0.00cvss 4.8epss 0.00

    Cross-site Scripting (XSS) - Stored in GitHub repository omeka/omeka-s prior to 4.0.2.

  • CVE-2023-3973MedJul 27, 2023
    risk 0.00cvss 6.1epss 0.00

    Cross-site Scripting (XSS) - Reflected in GitHub repository jgraph/drawio prior to 21.6.3.

  • CVE-2023-37623MedJul 26, 2023
    risk 0.00cvss 4.8epss 0.01

    Netdisco before v2.063000 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /Web/TypeAhead.pm.

  • CVE-2023-36656MedJul 17, 2023
    risk 0.00cvss 5.4epss 0.01

    Cross Site Scripting (XSS) vulnerability in Jaegertracing Jaeger UI before v.1.31.0 allows a remote attacker to execute arbitrary code via the KeyValuesTable component.

  • CVE-2023-37067MedJul 7, 2023
    risk 0.00cvss 4.8epss 0.00

    Chamilo 1.11.x up to 1.11.20 allows users with admin privilege account to insert XSS in the classes/usergroups management section.

  • CVE-2023-37066MedJul 7, 2023
    risk 0.00cvss 4.8epss 0.00

    Chamilo 1.11.x up to 1.11.20 allows users with admin privilege account to insert XSS in the skills wheel.

  • CVE-2023-37065MedJul 7, 2023
    risk 0.00cvss 4.8epss 0.00

    Chamilo 1.11.x up to 1.11.20 allows users with admin privilege account to insert XSS in the session category management section.

  • CVE-2023-37064MedJul 7, 2023
    risk 0.00cvss 4.8epss 0.00

    Chamilo 1.11.x up to 1.11.20 allows users with admin privilege account to insert XSS in the extra fields management section.

  • CVE-2023-37063MedJul 7, 2023
    risk 0.00cvss 4.8epss 0.00

    Chamilo 1.11.x up to 1.11.20 allows users with admin privilege account to insert XSS in the careers & promotions management section.

  • CVE-2023-37062MedJul 7, 2023
    risk 0.00cvss 4.8epss 0.00

    Chamilo 1.11.x up to 1.11.20 allows users with admin privilege account to insert XSS in the course categories' definition.

  • CVE-2023-37061MedJul 7, 2023
    risk 0.00cvss 4.8epss 0.00

    Chamilo 1.11.x up to 1.11.20 allows users with an admin privilege account to insert XSS in the languages management section.

  • CVE-2023-3532MedJul 7, 2023
    risk 0.00cvss 5.4epss 0.01

    Cross-site Scripting (XSS) - Stored in GitHub repository outline/outline prior to 0.70.1.

  • CVE-2023-36459CriJul 6, 2023
    risk 0.00cvss 9.3epss 0.01

    Mastodon is a free, open-source social network server based on ActivityPub. Starting in version 1.3 and prior to versions 3.5.9, 4.0.5, and 4.1.3, an attacker using carefully crafted oEmbed data can bypass the HTML sanitization performed by Mastodon and include arbitrary HTML in…