VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (46,610)

page 2065 of 2,331
  • CVE-2023-3021MedMay 31, 2023
    risk 0.00cvss 5.4epss 0.00

    Cross-site Scripting (XSS) - Stored in GitHub repository mkucej/i-librarian-free prior to 5.10.4.

  • CVE-2023-3020MedMay 31, 2023
    risk 0.00cvss 6.1epss 0.01

    Cross-site Scripting (XSS) - Reflected in GitHub repository mkucej/i-librarian-free prior to 5.10.4.

  • CVE-2023-33186HigMay 30, 2023
    risk 0.00cvss 8.2epss 0.01

    Zulip is an open-source team collaboration tool with unique topic-based threading that combines the best of email and chat to make remote work productive and delightful. The main development branch of Zulip Server from May 2, 2023 and later, including beta versions 7.0-beta1 and…

  • CVE-2023-32685MedMay 30, 2023
    risk 0.00cvss 4.4epss 0.01

    Kanboard is project management software that focuses on the Kanban methodology. Due to improper handling of elements under the `contentEditable` element, maliciously crafted clipboard content can inject arbitrary HTML tags into the DOM. A low-privileged attacker with permission…

  • CVE-2023-2954MedMay 29, 2023
    risk 0.00cvss 5.4epss 0.00

    Cross-site Scripting (XSS) - Stored in GitHub repository liangliangyy/djangoblog prior to master.

  • CVE-2023-2949MedMay 28, 2023
    risk 0.00cvss 6.1epss 0.01

    Cross-site Scripting (XSS) - Reflected in GitHub repository openemr/openemr prior to 7.0.1.

  • CVE-2022-42225MedMay 24, 2023
    risk 0.00cvss 5.4epss 0.01

    Jumpserver 2.10.0 <= version <= 2.26.0 contains multiple stored XSS vulnerabilities because of improper filtering of user input, which can execute any javascript under admin's permission.

  • CVE-2023-31779MedMay 22, 2023
    risk 0.00cvss 5.4epss 0.01

    Wekan v6.84 and earlier is vulnerable to Cross Site Scripting (XSS). An attacker with user privilege on kanban board can insert JavaScript code in in "Reaction to comment" feature.

  • CVE-2021-46888MedMay 21, 2023
    risk 0.00cvss 5.4epss 0.01

    An issue was discovered in hledger before 1.23. A Stored Cross-Site Scripting (XSS) vulnerability exists in toBloodhoundJson that allows an attacker to execute JavaScript by encoding user-controlled values in a payload with base64 and parsing them with the atob function.

  • CVE-2023-32066MedMay 9, 2023
    risk 0.00cvss 5.4epss 0.00

    Time Tracker is an open source time tracking system. The week view plugin in Time Tracker versions 1.22.11.5782 and prior was not escaping titles for notes in week view table. Because of that, it was possible for a logged in user to enter notes with elements of JavaScript. Such…

  • CVE-2023-2566MedMay 8, 2023
    risk 0.00cvss 4.8epss 0.01

    Cross-site Scripting (XSS) - Stored in GitHub repository openemr/openemr prior to 7.0.1.

  • CVE-2023-2553MedMay 5, 2023
    risk 0.00cvss 5.4epss 0.00

    Cross-site Scripting (XSS) - Stored in GitHub repository unilogies/bumsys prior to 2.2.0.

  • CVE-2017-20183LowMay 5, 2023
    risk 0.00cvss 3.5epss 0.01

    A vulnerability was found in External Media without Import Plugin up to 1.0.0 on WordPress. It has been declared as problematic. This vulnerability affects the function print_media_new_panel of the file external-media-without-import.php. The manipulation of the argument…

  • CVE-2018-25085LowMay 1, 2023
    risk 0.00cvss 2.4epss 0.00

    A vulnerability classified as problematic was found in Responsive Menus 7.x-1.x-dev on Drupal. Affected by this vulnerability is the function responsive_menus_admin_form_submit of the file responsive_menus.module of the component Configuration Setting Handler. The manipulation…

  • CVE-2023-25314MedApr 25, 2023
    risk 0.00cvss 6.1epss 0.00

    Cross Site Scripting (XSS) vulnerability in World Wide Broadcast Network AVideo before 12.4, allows attackers to gain sensitive information via the success parameter to /user.

  • CVE-2023-30627CriApr 24, 2023
    risk 0.00cvss 9.0epss 0.01

    jellyfin-web is the web client for Jellyfin, a free-software media system. Starting in version 10.1.0 and prior to version 10.8.10, a stored cross-site scripting vulnerability in device.js can be used to make arbitrary calls to the `REST` endpoints with admin privileges. When…

  • CVE-2023-2109MedApr 17, 2023
    risk 0.00cvss 6.1epss 0.00

    Cross-site Scripting (XSS) - DOM in GitHub repository chatwoot/chatwoot prior to 2.14.0.

  • CVE-2023-26123MedApr 14, 2023
    risk 0.00cvss 6.1epss 0.01

    Versions of the package raysan5/raylib before 4.5.0 are vulnerable to Cross-site Scripting (XSS) such that the SetClipboardText API does not properly escape the ' character, allowing attacker-controlled input to break out of the string and execute arbitrary JavaScript via…

  • CVE-2023-24182MedApr 11, 2023
    risk 0.00cvss 5.4epss 0.01

    LuCI openwrt-22.03 branch git-22.361.69894-438c598 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the component /system/sshkeys.js.

  • CVE-2018-25084LowApr 10, 2023
    risk 0.00cvss 3.5epss 0.01

    A vulnerability, which was classified as problematic, has been found in Ping Identity Self-Service Account Manager 1.1.2. Affected by this issue is some unknown functionality of the file src/main/java/com/unboundid/webapp/ssam/SSAMController.java. The manipulation leads to cross…