VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (46,610)

page 2069 of 2,331
  • CVE-2023-23010MedJan 20, 2023
    risk 0.00cvss 6.1epss 0.01

    Cross Site Scripting (XSS) vulnerability in Ecommerce-CodeIgniter-Bootstrap thru commit d5904379ca55014c5df34c67deda982c73dc7fe5 (on Dec 27, 2022), allows attackers to execute arbitrary code via the languages and trans_load parameters in file add_product.php.

  • CVE-2022-4892LowJan 19, 2023
    risk 0.00cvss 3.5epss 0.01

    A vulnerability was found in MyCMS. It has been classified as problematic. This affects the function build_view of the file lib/gener/view.php of the component Visitors Module. The manipulation of the argument original/converted leads to cross site scripting. It is possible to…

  • CVE-2020-36654LowJan 18, 2023
    risk 0.00cvss 3.5epss 0.01

    A vulnerability classified as problematic has been found in GENI Portal. This affects the function no_invocation_id_error of the file portal/www/portal/sliceresource.php. The manipulation of the argument invocation_id/invocation_user leads to cross site scripting. It is possible…

  • CVE-2020-36653LowJan 18, 2023
    risk 0.00cvss 3.5epss 0.01

    A vulnerability was found in GENI Portal. It has been rated as problematic. Affected by this issue is some unknown functionality of the file portal/www/portal/error-text.php. The manipulation of the argument error leads to cross site scripting. The attack may be launched…

  • CVE-2022-40704MedJan 17, 2023
    risk 0.00cvss 6.1epss 0.01

    A XSS vulnerability was found in phoromatic_r_add_test_details.php in phoronix-test-suite.

  • CVE-2023-0338MedJan 17, 2023
    risk 0.00cvss 6.1epss 0.00

    Cross-site Scripting (XSS) - Reflected in GitHub repository lirantal/daloradius prior to master-branch.

  • CVE-2023-0337MedJan 17, 2023
    risk 0.00cvss 6.1epss 0.00

    Cross-site Scripting (XSS) - Reflected in GitHub repository lirantal/daloradius prior to master-branch.

  • CVE-2023-0327LowJan 16, 2023
    risk 0.00cvss 3.5epss 0.01

    A vulnerability was found in saemorris TheRadSystem. It has been classified as problematic. Affected is an unknown function of the file users.php. The manipulation of the argument q leads to cross site scripting. It is possible to launch the attack remotely. VDB-218454 is the…

  • CVE-2023-0301MedJan 14, 2023
    risk 0.00cvss 5.4epss 0.00

    Cross-site Scripting (XSS) - Stored in GitHub repository alfio-event/alf.io prior to Alf.io 2.0-M4-2301.

  • CVE-2023-0300MedJan 14, 2023
    risk 0.00cvss 5.4epss 0.00

    Cross-site Scripting (XSS) - Reflected in GitHub repository alfio-event/alf.io prior to 2.0-M4-2301.

  • CVE-2021-4312LowJan 13, 2023
    risk 0.00cvss 3.5epss 0.01

    ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability classified as problematic has been found in Th3-822 Rapidleech. This affects the function zip_go of the file classes/options/zip.php. The manipulation of the argument archive leads to cross site scripting. It is possible to…

  • CVE-2023-0289MedJan 13, 2023
    risk 0.00cvss 5.4epss 0.01

    Cross-site Scripting (XSS) - Stored in GitHub repository craigk5n/webcalendar prior to master.

  • CVE-2021-46872MedJan 13, 2023
    risk 0.00cvss 6.1epss 0.01

    An issue was discovered in Nim before 1.6.2. The RST module of the Nim language stdlib, as used in NimForum and other products, permits the javascript: URI scheme and thus can lead to XSS in some applications. (Nim versions 1.6.2 and later are fixed; there may be backports of…

  • CVE-2018-25073LowJan 11, 2023
    risk 0.00cvss 3.5epss 0.01

    A vulnerability has been found in Newcomer1989 TSN-Ranksystem up to 1.2.6 and classified as problematic. This vulnerability affects the function getlog of the file webinterface/bot.php. The manipulation leads to cross site scripting. The attack can be initiated remotely.…

  • CVE-2022-4882LowJan 9, 2023
    risk 0.00cvss 2.6epss 0.01

    A vulnerability was found in kaltura mwEmbed up to 2.91. It has been rated as problematic. Affected by this issue is some unknown functionality of the file modules/KalturaSupport/components/share/share.js of the component Share Plugin. The manipulation of the argument res leads…

  • CVE-2021-4310LowJan 9, 2023
    risk 0.00cvss 3.5epss 0.01

    A vulnerability was found in 01-Scripts 01-Artikelsystem. It has been classified as problematic. Affected is an unknown function of the file 01article.php. The manipulation of the argument $_SERVER['PHP_SELF'] leads to cross site scripting. It is possible to launch the attack…

  • CVE-2021-4309LowJan 8, 2023
    risk 0.00cvss 3.5epss 0.01

    A vulnerability, which was classified as problematic, has been found in 01-Scripts 01ACP. This issue affects some unknown processing. The manipulation of the argument $_SERVER['SCRIPT_NAME'] leads to cross site scripting. The attack may be initiated remotely. The identifier of…

  • CVE-2022-4881MedJan 8, 2023
    risk 0.00cvss 4.3epss 0.01

    A vulnerability was found in CapsAdmin PAC3. It has been rated as problematic. Affected by this issue is some unknown functionality of the file lua/pac3/core/shared/http.lua. The manipulation of the argument url leads to cross site scripting. The attack may be launched remotely.…

  • CVE-2023-22475MedJan 6, 2023
    risk 0.00cvss 6.3epss 0.01

    Canarytokens is an open source tool which helps track activity and actions on your network. A Cross-Site Scripting vulnerability was identified in the history page of triggered Canarytokens prior to sha-fb61290. An attacker who discovers an HTTP-based Canarytoken (a URL) can use…

  • CVE-2023-22455MedJan 5, 2023
    risk 0.00cvss 6.8epss 0.00

    Discourse is an option source discussion platform. Prior to version 2.8.14 on the `stable` branch and version 3.0.0.beta16 on the `beta` and `tests-passed` branches, tag descriptions, which can be updated by moderators, can be used for cross-site scripting attacks. This…