CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Description
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85
CVEs mapped to this weakness (46,610)
page 2064 of 2,331| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-3521 | Med | 0.00 | 6.1 | 0.01 | Jul 6, 2023 | Cross-site Scripting (XSS) - Reflected in GitHub repository fossbilling/fossbilling prior to 0.5.4. | ||
| CVE-2023-3479 | Med | 0.00 | 6.1 | 0.01 | Jun 30, 2023 | Cross-site Scripting (XSS) - Reflected in GitHub repository hestiacp/hestiacp prior to 1.7.8. | ||
| CVE-2023-36463 | Med | 0.00 | 5.3 | 0.00 | Jun 27, 2023 | Meldekarten generator is an open source project to create a program, running locally in the browser without the need for an internet-connection, to create, store and print registration cards for volunteers. All text fields on the webpage are vulnerable to XSS attacks. The user… | ||
| CVE-2023-36666 | Med | 0.00 | 6.1 | 0.00 | Jun 25, 2023 | INEX IXP-Manager before 6.3.1 allows XSS. list-preamble.foil.php, page-header-preamble.foil.php, edit-form.foil.php, page-header-preamble.foil.php, overview.foil.php, cust.foil.php, and view.foil.php may be affected. | ||
| CVE-2023-35131 | Med | 0.00 | 6.1 | 0.01 | Jun 22, 2023 | Content on the groups page required additional sanitizing to prevent an XSS risk. This flaw affects Moodle versions 4.2, 4.1 to 4.1.3, 4.0 to 4.0.8 and 3.11 to 3.11.14. | ||
| CVE-2023-34796 | Med | 0.00 | 6.1 | 0.01 | Jun 22, 2023 | Cross site scripting (XSS) vulnerabiliy in dmarcts-report-viewer dashboard versions 1.1 and thru commit 8a1d882b4c481a05e296e9b38a7961e912146a0f, allows unauthenticated attackers to execute arbitrary code via the org_name or domain values. | ||
| CVE-2023-3294 | Med | 0.00 | 6.1 | 0.00 | Jun 16, 2023 | Cross-site Scripting (XSS) - DOM in GitHub repository saleor/react-storefront prior to c29aab226f07ca980cc19787dcef101e11b83ef7. | ||
| CVE-2023-3293 | Med | 0.00 | 4.8 | 0.01 | Jun 16, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository salesagility/suitecrm-core prior to 8.3.0. | ||
| CVE-2023-34961 | Med | 0.00 | 6.1 | 0.00 | Jun 8, 2023 | Chamilo v1.11.x up to v1.11.18 was discovered to contain a cross-site scripting (XSS) vulnerability via the /feedback/comment field. | ||
| CVE-2017-20185 | Low | 0.00 | 3.5 | 0.00 | Jun 6, 2023 | ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in Fuzzy SWMP. It has been rated as problematic. This issue affects some unknown processing of the file swmp.php of the component GET Parameter Handler. The manipulation of the argument theme leads to cross site… | ||
| CVE-2023-33969 | Med | 0.00 | 6.4 | 0.01 | Jun 5, 2023 | Kanboard is open source project management software that focuses on the Kanban methodology. A stored Cross site scripting (XSS) allows an attacker to execute arbitrary Javascript and any user who views the task containing the malicious code will be exposed to the XSS attack.… | ||
| CVE-2023-34408 | Med | 0.00 | 5.4 | 0.01 | Jun 5, 2023 | DokuWiki before 2023-04-04a allows XSS via RSS titles. | ||
| CVE-2023-3085 | Low | 0.00 | 3.5 | 0.00 | Jun 3, 2023 | A vulnerability, which was classified as problematic, has been found in X-WRT luci up to 22.10_b202303061504. This issue affects the function run_action of the file modules/luci-base/ucode/dispatcher.uc of the component 404 Error Template Handler. The manipulation of the… | ||
| CVE-2023-3073 | Med | 0.00 | 5.4 | 0.00 | Jun 2, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository tsolucio/corebos prior to 8 via evvtgendoc. | ||
| CVE-2023-3074 | Med | 0.00 | 5.4 | 0.01 | Jun 2, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository tsolucio/corebos prior to 8. | ||
| CVE-2023-3071 | Med | 0.00 | 5.4 | 0.01 | Jun 2, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository tsolucio/corebos prior to 8. | ||
| CVE-2023-3070 | Med | 0.00 | 5.4 | 0.01 | Jun 2, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository tsolucio/corebos prior to 8. | ||
| CVE-2023-3067 | Med | 0.00 | 5.4 | 0.00 | Jun 2, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository zadam/trilium prior to 0.59.4. | ||
| CVE-2018-25086 | Low | 0.00 | 3.5 | 0.01 | Jun 1, 2023 | A vulnerability was found in sea75300 FanPress CM up to 3.6.3. It has been classified as problematic. This affects the function getArticlesPreview of the file inc/controller/action/system/templatepreview.php of the component Template Preview. The manipulation leads to cross site… | ||
| CVE-2023-3026 | Med | 0.00 | 6.1 | 0.01 | Jun 1, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository jgraph/drawio prior to 21.2.8. |
- risk 0.00cvss 6.1epss 0.01
Cross-site Scripting (XSS) - Reflected in GitHub repository fossbilling/fossbilling prior to 0.5.4.
- risk 0.00cvss 6.1epss 0.01
Cross-site Scripting (XSS) - Reflected in GitHub repository hestiacp/hestiacp prior to 1.7.8.
- risk 0.00cvss 5.3epss 0.00
Meldekarten generator is an open source project to create a program, running locally in the browser without the need for an internet-connection, to create, store and print registration cards for volunteers. All text fields on the webpage are vulnerable to XSS attacks. The user…
- risk 0.00cvss 6.1epss 0.00
INEX IXP-Manager before 6.3.1 allows XSS. list-preamble.foil.php, page-header-preamble.foil.php, edit-form.foil.php, page-header-preamble.foil.php, overview.foil.php, cust.foil.php, and view.foil.php may be affected.
- risk 0.00cvss 6.1epss 0.01
Content on the groups page required additional sanitizing to prevent an XSS risk. This flaw affects Moodle versions 4.2, 4.1 to 4.1.3, 4.0 to 4.0.8 and 3.11 to 3.11.14.
- risk 0.00cvss 6.1epss 0.01
Cross site scripting (XSS) vulnerabiliy in dmarcts-report-viewer dashboard versions 1.1 and thru commit 8a1d882b4c481a05e296e9b38a7961e912146a0f, allows unauthenticated attackers to execute arbitrary code via the org_name or domain values.
- risk 0.00cvss 6.1epss 0.00
Cross-site Scripting (XSS) - DOM in GitHub repository saleor/react-storefront prior to c29aab226f07ca980cc19787dcef101e11b83ef7.
- risk 0.00cvss 4.8epss 0.01
Cross-site Scripting (XSS) - Stored in GitHub repository salesagility/suitecrm-core prior to 8.3.0.
- risk 0.00cvss 6.1epss 0.00
Chamilo v1.11.x up to v1.11.18 was discovered to contain a cross-site scripting (XSS) vulnerability via the /feedback/comment field.
- risk 0.00cvss 3.5epss 0.00
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in Fuzzy SWMP. It has been rated as problematic. This issue affects some unknown processing of the file swmp.php of the component GET Parameter Handler. The manipulation of the argument theme leads to cross site…
- risk 0.00cvss 6.4epss 0.01
Kanboard is open source project management software that focuses on the Kanban methodology. A stored Cross site scripting (XSS) allows an attacker to execute arbitrary Javascript and any user who views the task containing the malicious code will be exposed to the XSS attack.…
- risk 0.00cvss 5.4epss 0.01
DokuWiki before 2023-04-04a allows XSS via RSS titles.
- risk 0.00cvss 3.5epss 0.00
A vulnerability, which was classified as problematic, has been found in X-WRT luci up to 22.10_b202303061504. This issue affects the function run_action of the file modules/luci-base/ucode/dispatcher.uc of the component 404 Error Template Handler. The manipulation of the…
- risk 0.00cvss 5.4epss 0.00
Cross-site Scripting (XSS) - Stored in GitHub repository tsolucio/corebos prior to 8 via evvtgendoc.
- risk 0.00cvss 5.4epss 0.01
Cross-site Scripting (XSS) - Stored in GitHub repository tsolucio/corebos prior to 8.
- risk 0.00cvss 5.4epss 0.01
Cross-site Scripting (XSS) - Stored in GitHub repository tsolucio/corebos prior to 8.
- risk 0.00cvss 5.4epss 0.01
Cross-site Scripting (XSS) - Stored in GitHub repository tsolucio/corebos prior to 8.
- risk 0.00cvss 5.4epss 0.00
Cross-site Scripting (XSS) - Stored in GitHub repository zadam/trilium prior to 0.59.4.
- risk 0.00cvss 3.5epss 0.01
A vulnerability was found in sea75300 FanPress CM up to 3.6.3. It has been classified as problematic. This affects the function getArticlesPreview of the file inc/controller/action/system/templatepreview.php of the component Template Preview. The manipulation leads to cross site…
- risk 0.00cvss 6.1epss 0.01
Cross-site Scripting (XSS) - Stored in GitHub repository jgraph/drawio prior to 21.2.8.