CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Description
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85
CVEs mapped to this weakness (46,610)
page 2066 of 2,331| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-24181 | Med | 0.00 | 5.4 | 0.01 | Apr 10, 2023 | LuCI openwrt-22.03 branch git-22.361.69894-438c598 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /openvpn/pageswitch.htm. | ||
| CVE-2022-31889 | Med | 0.00 | 6.1 | 0.01 | Apr 5, 2023 | Cross Site Scripting (XSS) vulnerability in audit/templates/auditlogs.tmpl.php in osTicket osTicket-plugins before commit a7842d494889fd5533d13deb3c6a7789768795ae. | ||
| CVE-2020-21487 | Cri | 0.00 | 9.6 | 0.01 | Apr 4, 2023 | Cross Site Scripting vulnerability found in Netgate pfSense 2.4.4 and ACME package v.0.6.3 allows attackers to execute arbitrary code via the RootFolder field of acme_certificates.php. | ||
| CVE-2023-28629 | Med | 0.00 | 5.4 | 0.01 | Mar 27, 2023 | GoCD is an open source continuous delivery server. GoCD versions before 23.1.0 are vulnerable to a stored XSS vulnerability, where pipeline configuration with a malicious pipeline label configuration can affect browser display of pipeline runs generated from that configuration.… | ||
| CVE-2023-27054 | Med | 0.00 | 6.1 | 0.01 | Mar 22, 2023 | A cross-site scripting (XSS) vulnerability in MiroTalk P2P before commit f535b35 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter under the settings module. | ||
| CVE-2023-1527 | Med | 0.00 | 5.4 | 0.01 | Mar 21, 2023 | Cross-site Scripting (XSS) - Generic in GitHub repository tsolucio/corebos prior to 8.0. | ||
| CVE-2023-25172 | Med | 0.00 | 4.4 | 0.01 | Mar 17, 2023 | Discourse is an open-source discussion platform. Prior to version 3.0.1 of the `stable` branch and version 3.1.0.beta2 of the `beta` and `tests-passed` branches, a maliciously crafted URL can be included in a user's full name field to to carry out cross-site scripting attacks on… | ||
| CVE-2023-26040 | Med | 0.00 | 6.5 | 0.00 | Mar 17, 2023 | Discourse is an open-source discussion platform. Between versions 3.1.0.beta2 and 3.1.0.beta3 of the `tests-passed` branch, editing or responding to a chat message containing malicious content could lead to a cross-site scripting attack. This issue is patched in version… | ||
| CVE-2023-27130 | Med | 0.00 | 4.8 | 0.01 | Mar 16, 2023 | Cross Site Scripting vulnerability found in Typecho v.1.2.0 allows a remote attacker to execute arbitrary code via an arbitrarily supplied URL parameter. | ||
| CVE-2023-1320 | Med | 0.00 | 6.1 | 0.01 | Mar 10, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository osticket/osticket prior to v1.16.6. | ||
| CVE-2023-1319 | Med | 0.00 | 4.8 | 0.00 | Mar 10, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository osticket/osticket prior to v1.16.6. | ||
| CVE-2023-1318 | Med | 0.00 | 5.4 | 0.01 | Mar 10, 2023 | Cross-site Scripting (XSS) - Generic in GitHub repository osticket/osticket prior to v1.16.6. | ||
| CVE-2023-1317 | Med | 0.00 | 5.4 | 0.01 | Mar 10, 2023 | Cross-site Scripting (XSS) - Reflected in GitHub repository osticket/osticket prior to v1.16.6. | ||
| CVE-2023-1316 | Med | 0.00 | 5.4 | 0.01 | Mar 10, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository osticket/osticket prior to v1.16.6. | ||
| CVE-2023-1315 | Med | 0.00 | 5.4 | 0.01 | Mar 10, 2023 | Cross-site Scripting (XSS) - Reflected in GitHub repository osticket/osticket prior to v1.16.6. | ||
| CVE-2023-1270 | Med | 0.00 | 5.4 | 0.00 | Mar 8, 2023 | Cross-site Scripting in GitHub repository btcpayserver/btcpayserver prior to 1.8.3. | ||
| CVE-2023-1212 | Med | 0.00 | 4.8 | 0.00 | Mar 7, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository phpipam/phpipam prior to v1.5.2. | ||
| CVE-2023-27472 | Hig | 0.00 | 8.2 | 0.00 | Mar 6, 2023 | quickentity-editor-next is an open source, system local, video game asset editor. In affected versions HTML tags in entity names are not sanitised (XSS vulnerability). Allows arbitrary code execution within the browser sandbox, among other things, simply from loading a file… | ||
| CVE-2022-4930 | Low | 0.00 | 3.5 | 0.01 | Mar 6, 2023 | A vulnerability classified as problematic was found in nuxsmin sysPass up to 3.2.4. Affected by this vulnerability is an unknown functionality of the component URL Handler. The manipulation leads to cross site scripting. The attack can be launched remotely. Upgrading to version… | ||
| CVE-2022-4929 | Low | 0.00 | 3.5 | 0.01 | Mar 6, 2023 | A vulnerability was found in icplayer up to 0.818. It has been rated as problematic. Affected by this issue is some unknown functionality of the file addons/Commons/src/tts-utils.js. The manipulation leads to cross site scripting. The attack may be launched remotely. Upgrading… |
- risk 0.00cvss 5.4epss 0.01
LuCI openwrt-22.03 branch git-22.361.69894-438c598 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /openvpn/pageswitch.htm.
- risk 0.00cvss 6.1epss 0.01
Cross Site Scripting (XSS) vulnerability in audit/templates/auditlogs.tmpl.php in osTicket osTicket-plugins before commit a7842d494889fd5533d13deb3c6a7789768795ae.
- risk 0.00cvss 9.6epss 0.01
Cross Site Scripting vulnerability found in Netgate pfSense 2.4.4 and ACME package v.0.6.3 allows attackers to execute arbitrary code via the RootFolder field of acme_certificates.php.
- risk 0.00cvss 5.4epss 0.01
GoCD is an open source continuous delivery server. GoCD versions before 23.1.0 are vulnerable to a stored XSS vulnerability, where pipeline configuration with a malicious pipeline label configuration can affect browser display of pipeline runs generated from that configuration.…
- risk 0.00cvss 6.1epss 0.01
A cross-site scripting (XSS) vulnerability in MiroTalk P2P before commit f535b35 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter under the settings module.
- risk 0.00cvss 5.4epss 0.01
Cross-site Scripting (XSS) - Generic in GitHub repository tsolucio/corebos prior to 8.0.
- risk 0.00cvss 4.4epss 0.01
Discourse is an open-source discussion platform. Prior to version 3.0.1 of the `stable` branch and version 3.1.0.beta2 of the `beta` and `tests-passed` branches, a maliciously crafted URL can be included in a user's full name field to to carry out cross-site scripting attacks on…
- risk 0.00cvss 6.5epss 0.00
Discourse is an open-source discussion platform. Between versions 3.1.0.beta2 and 3.1.0.beta3 of the `tests-passed` branch, editing or responding to a chat message containing malicious content could lead to a cross-site scripting attack. This issue is patched in version…
- risk 0.00cvss 4.8epss 0.01
Cross Site Scripting vulnerability found in Typecho v.1.2.0 allows a remote attacker to execute arbitrary code via an arbitrarily supplied URL parameter.
- risk 0.00cvss 6.1epss 0.01
Cross-site Scripting (XSS) - Stored in GitHub repository osticket/osticket prior to v1.16.6.
- risk 0.00cvss 4.8epss 0.00
Cross-site Scripting (XSS) - Stored in GitHub repository osticket/osticket prior to v1.16.6.
- risk 0.00cvss 5.4epss 0.01
Cross-site Scripting (XSS) - Generic in GitHub repository osticket/osticket prior to v1.16.6.
- risk 0.00cvss 5.4epss 0.01
Cross-site Scripting (XSS) - Reflected in GitHub repository osticket/osticket prior to v1.16.6.
- risk 0.00cvss 5.4epss 0.01
Cross-site Scripting (XSS) - Stored in GitHub repository osticket/osticket prior to v1.16.6.
- risk 0.00cvss 5.4epss 0.01
Cross-site Scripting (XSS) - Reflected in GitHub repository osticket/osticket prior to v1.16.6.
- risk 0.00cvss 5.4epss 0.00
Cross-site Scripting in GitHub repository btcpayserver/btcpayserver prior to 1.8.3.
- risk 0.00cvss 4.8epss 0.00
Cross-site Scripting (XSS) - Stored in GitHub repository phpipam/phpipam prior to v1.5.2.
- risk 0.00cvss 8.2epss 0.00
quickentity-editor-next is an open source, system local, video game asset editor. In affected versions HTML tags in entity names are not sanitised (XSS vulnerability). Allows arbitrary code execution within the browser sandbox, among other things, simply from loading a file…
- risk 0.00cvss 3.5epss 0.01
A vulnerability classified as problematic was found in nuxsmin sysPass up to 3.2.4. Affected by this vulnerability is an unknown functionality of the component URL Handler. The manipulation leads to cross site scripting. The attack can be launched remotely. Upgrading to version…
- risk 0.00cvss 3.5epss 0.01
A vulnerability was found in icplayer up to 0.818. It has been rated as problematic. Affected by this issue is some unknown functionality of the file addons/Commons/src/tts-utils.js. The manipulation leads to cross site scripting. The attack may be launched remotely. Upgrading…