CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Description
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85
CVEs mapped to this weakness (46,610)
page 2067 of 2,331| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-4928 | Low | 0.00 | 3.5 | 0.01 | Mar 6, 2023 | A vulnerability was found in icplayer up to 0.819. It has been declared as problematic. Affected by this vulnerability is the function AddonText_Selection_create of the file addons/Text_Selection/src/presenter.js. The manipulation leads to cross site scripting. The attack can be… | ||
| CVE-2023-1181 | Med | 0.00 | 5.4 | 0.00 | Mar 5, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository icret/easyimages2.0 prior to 2.6.7. | ||
| CVE-2023-1148 | Med | 0.00 | 4.8 | 0.01 | Mar 2, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository flatpressblog/flatpress prior to 1.3. | ||
| CVE-2023-1147 | Med | 0.00 | 5.4 | 0.00 | Mar 2, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository flatpressblog/flatpress prior to 1.3. | ||
| CVE-2023-1146 | Med | 0.00 | 5.4 | 0.00 | Mar 2, 2023 | Cross-site Scripting (XSS) - Generic in GitHub repository flatpressblog/flatpress prior to 1.3. | ||
| CVE-2023-1107 | Med | 0.00 | 5.4 | 0.01 | Mar 2, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository flatpressblog/flatpress prior to 1.3. | ||
| CVE-2023-1106 | Med | 0.00 | 6.1 | 0.01 | Mar 2, 2023 | Cross-site Scripting (XSS) - Reflected in GitHub repository flatpressblog/flatpress prior to 1.3. | ||
| CVE-2023-1104 | Med | 0.00 | 5.4 | 0.01 | Mar 1, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository flatpressblog/flatpress prior to 1.3. | ||
| CVE-2023-25807 | Hig | 0.00 | 7.2 | 0.01 | Feb 28, 2023 | DataEase is an open source data visualization and analysis tool. When saving a dashboard on the DataEase platform saved data can be modified and store malicious code. This vulnerability can lead to the execution of malicious code stored by the attacker on the server side when… | ||
| CVE-2023-26042 | Med | 0.00 | 6.1 | 0.01 | Feb 27, 2023 | Part-DB is an open source inventory management system for your electronic components. User input was found not being properly escaped, which allowed malicious users to inject arbitrary HTML into the pages. The Content-Security-Policy forbids inline and external scripts so it is… | ||
| CVE-2023-25825 | Hig | 0.00 | 7.7 | 0.01 | Feb 25, 2023 | ZoneMinder is a free, open source Closed-circuit television software application for Linux which supports IP, USB and Analog cameras. Versions prior to 1.36.33 are vulnerable to Cross-site Scripting. Log entries can be injected into the database logs, containing a malicious… | ||
| CVE-2023-0995 | Med | 0.00 | 5.4 | 0.00 | Feb 24, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository unilogies/bumsys prior to v2.0.1. | ||
| CVE-2023-24811 | Hig | 0.00 | 7.1 | 0.00 | Feb 22, 2023 | Misskey is an open source, decentralized social media platform. In versions prior to 13.3.2 the URL preview function is subject to a cross site scripting vulnerability due to insufficient URL validation. Arbitrary JavaScript is executed when a malicious URL is loaded in the… | ||
| CVE-2021-4325 | Low | 0.00 | 3.5 | 0.01 | Feb 22, 2023 | A vulnerability, which was classified as problematic, has been found in NHN TOAST UI Chart 4.1.4. This issue affects some unknown processing of the component Legend Handler. The manipulation leads to cross site scripting. The attack may be initiated remotely. Upgrading to… | ||
| CVE-2021-32857 | Med | 0.00 | 6.1 | 0.01 | Feb 21, 2023 | Cockpit is a content management system that allows addition of content management functionality to any site. In versions 0.12.2 and prior, bad HTML sanitization in `htmleditor.js` may lead to cross-site scripting (XSS) issues. There are no known patches for this issue. | ||
| CVE-2023-26235 | Med | 0.00 | 6.1 | 0.00 | Feb 21, 2023 | JD-GUI 1.6.6 allows XSS via util/net/InterProcessCommunicationUtil.java. | ||
| CVE-2023-23922 | Med | 0.00 | 6.1 | 0.01 | Feb 17, 2023 | The vulnerability was found Moodle which exists due to insufficient sanitization of user-supplied data in blog search. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's browser in context of vulnerable… | ||
| CVE-2023-23921 | Med | 0.00 | 6.1 | 0.01 | Feb 17, 2023 | The vulnerability was found Moodle which exists due to insufficient sanitization of user-supplied data in some returnurl parameters. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's browser in context… | ||
| CVE-2023-0879 | Med | 0.00 | 6.3 | 0.00 | Feb 17, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository btcpayserver/btcpayserver prior to 1.7.12. | ||
| CVE-2023-0878 | Med | 0.00 | 6.1 | 0.01 | Feb 17, 2023 | Cross-site Scripting (XSS) - Generic in GitHub repository nuxt/framework prior to 3.2.1. |
- risk 0.00cvss 3.5epss 0.01
A vulnerability was found in icplayer up to 0.819. It has been declared as problematic. Affected by this vulnerability is the function AddonText_Selection_create of the file addons/Text_Selection/src/presenter.js. The manipulation leads to cross site scripting. The attack can be…
- risk 0.00cvss 5.4epss 0.00
Cross-site Scripting (XSS) - Stored in GitHub repository icret/easyimages2.0 prior to 2.6.7.
- risk 0.00cvss 4.8epss 0.01
Cross-site Scripting (XSS) - Stored in GitHub repository flatpressblog/flatpress prior to 1.3.
- risk 0.00cvss 5.4epss 0.00
Cross-site Scripting (XSS) - Stored in GitHub repository flatpressblog/flatpress prior to 1.3.
- risk 0.00cvss 5.4epss 0.00
Cross-site Scripting (XSS) - Generic in GitHub repository flatpressblog/flatpress prior to 1.3.
- risk 0.00cvss 5.4epss 0.01
Cross-site Scripting (XSS) - Stored in GitHub repository flatpressblog/flatpress prior to 1.3.
- risk 0.00cvss 6.1epss 0.01
Cross-site Scripting (XSS) - Reflected in GitHub repository flatpressblog/flatpress prior to 1.3.
- risk 0.00cvss 5.4epss 0.01
Cross-site Scripting (XSS) - Stored in GitHub repository flatpressblog/flatpress prior to 1.3.
- risk 0.00cvss 7.2epss 0.01
DataEase is an open source data visualization and analysis tool. When saving a dashboard on the DataEase platform saved data can be modified and store malicious code. This vulnerability can lead to the execution of malicious code stored by the attacker on the server side when…
- risk 0.00cvss 6.1epss 0.01
Part-DB is an open source inventory management system for your electronic components. User input was found not being properly escaped, which allowed malicious users to inject arbitrary HTML into the pages. The Content-Security-Policy forbids inline and external scripts so it is…
- risk 0.00cvss 7.7epss 0.01
ZoneMinder is a free, open source Closed-circuit television software application for Linux which supports IP, USB and Analog cameras. Versions prior to 1.36.33 are vulnerable to Cross-site Scripting. Log entries can be injected into the database logs, containing a malicious…
- risk 0.00cvss 5.4epss 0.00
Cross-site Scripting (XSS) - Stored in GitHub repository unilogies/bumsys prior to v2.0.1.
- risk 0.00cvss 7.1epss 0.00
Misskey is an open source, decentralized social media platform. In versions prior to 13.3.2 the URL preview function is subject to a cross site scripting vulnerability due to insufficient URL validation. Arbitrary JavaScript is executed when a malicious URL is loaded in the…
- risk 0.00cvss 3.5epss 0.01
A vulnerability, which was classified as problematic, has been found in NHN TOAST UI Chart 4.1.4. This issue affects some unknown processing of the component Legend Handler. The manipulation leads to cross site scripting. The attack may be initiated remotely. Upgrading to…
- risk 0.00cvss 6.1epss 0.01
Cockpit is a content management system that allows addition of content management functionality to any site. In versions 0.12.2 and prior, bad HTML sanitization in `htmleditor.js` may lead to cross-site scripting (XSS) issues. There are no known patches for this issue.
- risk 0.00cvss 6.1epss 0.00
JD-GUI 1.6.6 allows XSS via util/net/InterProcessCommunicationUtil.java.
- risk 0.00cvss 6.1epss 0.01
The vulnerability was found Moodle which exists due to insufficient sanitization of user-supplied data in blog search. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's browser in context of vulnerable…
- risk 0.00cvss 6.1epss 0.01
The vulnerability was found Moodle which exists due to insufficient sanitization of user-supplied data in some returnurl parameters. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's browser in context…
- risk 0.00cvss 6.3epss 0.00
Cross-site Scripting (XSS) - Stored in GitHub repository btcpayserver/btcpayserver prior to 1.7.12.
- risk 0.00cvss 6.1epss 0.01
Cross-site Scripting (XSS) - Generic in GitHub repository nuxt/framework prior to 3.2.1.