VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (46,610)

page 2068 of 2,331
  • CVE-2022-48327MedFeb 16, 2023
    risk 0.00cvss 6.1epss 0.01

    Multiple Cross Site Scripting (XSS) vulnerabilities in Mapos 4.39.0 allow attackers to execute arbitrary code. Affects the following parameters: (1) dataInicial, (2) dataFinal, (3) tipocliente, (4) format, (5) precoInicial, (6) precoFinal, (7) estoqueInicial, (8) estoqueFinal,…

  • CVE-2022-48326MedFeb 16, 2023
    risk 0.00cvss 6.1epss 0.01

    Multiple Cross Site Scripting (XSS) vulnerabilities in Mapos 4.39.0 allow attackers to execute arbitrary code. Affects the following parameters: (1) nome, (2) aCliente, (3) eCliente, (4) dCliente, (5) vCliente, (6) aProduto, (7) eProduto, (8) dProduto, (9) vProduto, (10)…

  • CVE-2022-48325MedFeb 16, 2023
    risk 0.00cvss 6.1epss 0.01

    Multiple Cross Site Scripting (XSS) vulnerabilities in Mapos 4.39.0 allow attackers to execute arbitrary code. Affects the following parameters: (1) year, (2) oldSenha, (3) novaSenha, (4) termo, (5) nome, (6) cnpj, (7) ie, (8) cep, (9) logradouro, (10) numero, (11) bairro, (12)…

  • CVE-2022-48324MedFeb 16, 2023
    risk 0.00cvss 6.1epss 0.01

    Multiple Cross Site Scripting (XSS) vulnerabilities in Mapos 4.39.0 allow attackers to execute arbitrary code. Affects the following parameters: (1) pesquisa, (2) data, (3) data2, (4) nome, (5) descricao, (6) idDocumentos, (7) id in file application/controllers/Arquivos.php; (8)…

  • CVE-2020-19825CriFeb 15, 2023
    risk 0.00cvss 9.6epss 0.01

    Cross Site Scripting (XSS) vulnerability in kevinpapst kimai2 1.30.0 in /src/Twig/Runtime/MarkdownExtension.php, allows attackers to gain escalated privileges.

  • CVE-2023-0810MedFeb 13, 2023
    risk 0.00cvss 5.4epss 0.01

    Cross-site Scripting (XSS) - Stored in GitHub repository btcpayserver/btcpayserver prior to 1.7.11.

  • CVE-2023-0747MedFeb 8, 2023
    risk 0.00cvss 5.5epss 0.00

    Cross-site Scripting (XSS) - Stored in GitHub repository btcpayserver/btcpayserver prior to 1.7.6.

  • CVE-2023-23942MedFeb 6, 2023
    risk 0.00cvss 5.4epss 0.01

    The Nextcloud Desktop Client is a tool to synchronize files from a Nextcloud Server with your computer. Versions prior to 3.6.3 are missing sanitisation on qml labels which are used for basic HTML elements such as `strong`, `em` and `head` lines in the UI of the desktop client.…

  • CVE-2017-20177LowFeb 6, 2023
    risk 0.00cvss 3.5epss 0.01

    A vulnerability, which was classified as problematic, has been found in WangGuard Plugin 1.8.0 on WordPress. Affected by this issue is the function wangguard_users_info of the file wangguard-user-info.php of the component WGG User List Handler. The manipulation of the argument…

  • CVE-2022-4902LowFeb 6, 2023
    risk 0.00cvss 3.5epss 0.01

    A vulnerability classified as problematic has been found in eXo Chat Application. Affected is an unknown function of the file application/src/main/webapp/vue-app/components/ExoChatMessageComposer.vue of the component Mention Handler. The manipulation leads to cross site…

  • CVE-2017-20176LowFeb 6, 2023
    risk 0.00cvss 3.5epss 0.01

    A vulnerability classified as problematic was found in ciubotaru share-on-diaspora 0.7.9. This vulnerability affects unknown code of the file new_window.php. The manipulation of the argument title/url leads to cross site scripting. The attack can be initiated remotely. The name…

  • CVE-2023-0677MedFeb 4, 2023
    risk 0.00cvss 6.1epss 0.00

    Cross-site Scripting (XSS) - Reflected in GitHub repository phpipam/phpipam prior to v1.5.1.

  • CVE-2023-0676MedFeb 4, 2023
    risk 0.00cvss 6.1epss 0.02

    Cross-site Scripting (XSS) - Reflected in GitHub repository phpipam/phpipam prior to 1.5.1.

  • CVE-2021-37518MedFeb 3, 2023
    risk 0.00cvss 6.1epss 0.01

    Universal Cross Site Scripting (UXSS) vulnerability in Vimium Extension 1.66 and earlier allows remote attackers to run arbitrary code via omnibar feature.

  • CVE-2023-0650LowFeb 2, 2023
    risk 0.00cvss 3.5epss 0.01

    A vulnerability was found in YAFNET up to 3.1.11 and classified as problematic. This issue affects some unknown processing of the component Signature Handler. The manipulation leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to…

  • CVE-2023-0607MedFeb 1, 2023
    risk 0.00cvss 4.8epss 0.01

    Cross-site Scripting (XSS) - Stored in GitHub repository projectsend/projectsend prior to r1606.

  • CVE-2023-0606MedFeb 1, 2023
    risk 0.00cvss 6.1epss 0.01

    Cross-site Scripting (XSS) - Reflected in GitHub repository ampache/ampache prior to 5.5.7.

  • CVE-2022-23552HigJan 27, 2023
    risk 0.00cvss 7.3epss 0.01

    Grafana is an open-source platform for monitoring and observability. Starting with the 8.1 branch and prior to versions 8.5.16, 9.2.10, and 9.3.4, Grafana had a stored XSS vulnerability affecting the core plugin GeoMap. The stored XSS vulnerability was possible because SVG files…

  • CVE-2023-0549LowJan 27, 2023
    risk 0.00cvss 3.5epss 0.01

    A vulnerability, which was classified as problematic, has been found in YAFNET up to 3.1.10. This issue affects some unknown processing of the file /forum/PostPrivateMessage of the component Private Message Handler. The manipulation of the argument subject/message leads to cross…

  • CVE-2023-24026MedJan 20, 2023
    risk 0.00cvss 6.1epss 0.00

    In MISP 2.4.167, app/webroot/js/event-graph.js has an XSS vulnerability via an event-graph preview payload.