VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (46,610)

page 2064 of 2,331
  • CVE-2023-3521MedJul 6, 2023
    risk 0.00cvss 6.1epss 0.01

    Cross-site Scripting (XSS) - Reflected in GitHub repository fossbilling/fossbilling prior to 0.5.4.

  • CVE-2023-3479MedJun 30, 2023
    risk 0.00cvss 6.1epss 0.01

    Cross-site Scripting (XSS) - Reflected in GitHub repository hestiacp/hestiacp prior to 1.7.8.

  • CVE-2023-36463MedJun 27, 2023
    risk 0.00cvss 5.3epss 0.00

    Meldekarten generator is an open source project to create a program, running locally in the browser without the need for an internet-connection, to create, store and print registration cards for volunteers. All text fields on the webpage are vulnerable to XSS attacks. The user…

  • CVE-2023-36666MedJun 25, 2023
    risk 0.00cvss 6.1epss 0.00

    INEX IXP-Manager before 6.3.1 allows XSS. list-preamble.foil.php, page-header-preamble.foil.php, edit-form.foil.php, page-header-preamble.foil.php, overview.foil.php, cust.foil.php, and view.foil.php may be affected.

  • CVE-2023-35131MedJun 22, 2023
    risk 0.00cvss 6.1epss 0.01

    Content on the groups page required additional sanitizing to prevent an XSS risk. This flaw affects Moodle versions 4.2, 4.1 to 4.1.3, 4.0 to 4.0.8 and 3.11 to 3.11.14.

  • CVE-2023-34796MedJun 22, 2023
    risk 0.00cvss 6.1epss 0.01

    Cross site scripting (XSS) vulnerabiliy in dmarcts-report-viewer dashboard versions 1.1 and thru commit 8a1d882b4c481a05e296e9b38a7961e912146a0f, allows unauthenticated attackers to execute arbitrary code via the org_name or domain values.

  • CVE-2023-3294MedJun 16, 2023
    risk 0.00cvss 6.1epss 0.00

    Cross-site Scripting (XSS) - DOM in GitHub repository saleor/react-storefront prior to c29aab226f07ca980cc19787dcef101e11b83ef7.

  • CVE-2023-3293MedJun 16, 2023
    risk 0.00cvss 4.8epss 0.01

    Cross-site Scripting (XSS) - Stored in GitHub repository salesagility/suitecrm-core prior to 8.3.0.

  • CVE-2023-34961MedJun 8, 2023
    risk 0.00cvss 6.1epss 0.00

    Chamilo v1.11.x up to v1.11.18 was discovered to contain a cross-site scripting (XSS) vulnerability via the /feedback/comment field.

  • CVE-2017-20185LowJun 6, 2023
    risk 0.00cvss 3.5epss 0.00

    ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in Fuzzy SWMP. It has been rated as problematic. This issue affects some unknown processing of the file swmp.php of the component GET Parameter Handler. The manipulation of the argument theme leads to cross site…

  • CVE-2023-33969MedJun 5, 2023
    risk 0.00cvss 6.4epss 0.01

    Kanboard is open source project management software that focuses on the Kanban methodology. A stored Cross site scripting (XSS) allows an attacker to execute arbitrary Javascript and any user who views the task containing the malicious code will be exposed to the XSS attack.…

  • CVE-2023-34408MedJun 5, 2023
    risk 0.00cvss 5.4epss 0.01

    DokuWiki before 2023-04-04a allows XSS via RSS titles.

  • CVE-2023-3085LowJun 3, 2023
    risk 0.00cvss 3.5epss 0.00

    A vulnerability, which was classified as problematic, has been found in X-WRT luci up to 22.10_b202303061504. This issue affects the function run_action of the file modules/luci-base/ucode/dispatcher.uc of the component 404 Error Template Handler. The manipulation of the…

  • CVE-2023-3073MedJun 2, 2023
    risk 0.00cvss 5.4epss 0.00

    Cross-site Scripting (XSS) - Stored in GitHub repository tsolucio/corebos prior to 8 via evvtgendoc.

  • CVE-2023-3074MedJun 2, 2023
    risk 0.00cvss 5.4epss 0.01

    Cross-site Scripting (XSS) - Stored in GitHub repository tsolucio/corebos prior to 8.

  • CVE-2023-3071MedJun 2, 2023
    risk 0.00cvss 5.4epss 0.01

    Cross-site Scripting (XSS) - Stored in GitHub repository tsolucio/corebos prior to 8.

  • CVE-2023-3070MedJun 2, 2023
    risk 0.00cvss 5.4epss 0.01

    Cross-site Scripting (XSS) - Stored in GitHub repository tsolucio/corebos prior to 8.

  • CVE-2023-3067MedJun 2, 2023
    risk 0.00cvss 5.4epss 0.00

    Cross-site Scripting (XSS) - Stored in GitHub repository zadam/trilium prior to 0.59.4.

  • CVE-2018-25086LowJun 1, 2023
    risk 0.00cvss 3.5epss 0.01

    A vulnerability was found in sea75300 FanPress CM up to 3.6.3. It has been classified as problematic. This affects the function getArticlesPreview of the file inc/controller/action/system/templatepreview.php of the component Template Preview. The manipulation leads to cross site…

  • CVE-2023-3026MedJun 1, 2023
    risk 0.00cvss 6.1epss 0.01

    Cross-site Scripting (XSS) - Stored in GitHub repository jgraph/drawio prior to 21.2.8.