VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (46,610)

page 2071 of 2,331
  • CVE-2018-25051LowDec 28, 2022
    risk 0.00cvss 2.4epss 0.00

    A vulnerability, which was classified as problematic, was found in JmPotato Pomash. This affects an unknown part of the file Pomash/theme/clean/templates/editor.html. The manipulation of the argument article.title/content.title/article.tag leads to cross site scripting. It is…

  • CVE-2021-4293LowDec 28, 2022
    risk 0.00cvss 3.5epss 0.01

    ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability classified as problematic has been found in gnuboard youngcart5 up to 5.4.5.1. Affected is an unknown function of the file adm/menu_list_update.php. The manipulation of the argument me_link leads to cross site scripting. It is…

  • CVE-2022-23544HigDec 28, 2022
    risk 0.00cvss 7.2epss 0.02

    MeterSphere is a one-stop open source continuous testing platform, covering test management, interface testing, UI testing and performance testing. Versions prior to 2.5.0 are subject to a Server-Side Request Forgery that leads to Cross-Site Scripting. A Server-Side request…

  • CVE-2021-4292LowDec 27, 2022
    risk 0.00cvss 3.5epss 0.01

    A vulnerability was found in OpenMRS Admin UI Module up to 1.4.x. It has been rated as problematic. This issue affects some unknown processing of the file omod/src/main/webapp/pages/metadata/privileges/privilege.gsp of the component Manage Privilege Page. The manipulation leads…

  • CVE-2021-4291LowDec 27, 2022
    risk 0.00cvss 3.5epss 0.01

    A vulnerability was found in OpenMRS Admin UI Module up to 1.5.x. It has been declared as problematic. This vulnerability affects unknown code of the file omod/src/main/webapp/pages/metadata/locations/location.gsp. The manipulation leads to cross site scripting. The attack can…

  • CVE-2022-4733MedDec 27, 2022
    risk 0.00cvss 4.8epss 0.01

    Cross-site Scripting (XSS) - Stored in GitHub repository openemr/openemr prior to 7.0.0.2.

  • CVE-2022-4727LowDec 27, 2022
    risk 0.00cvss 3.5epss 0.01

    A vulnerability, which was classified as problematic, was found in OpenMRS Appointment Scheduling Module up to 1.16.x. This affects the function getNotes of the file api/src/main/java/org/openmrs/module/appointmentscheduling/AppointmentRequest.java of the component Notes…

  • CVE-2021-4289LowDec 27, 2022
    risk 0.00cvss 3.5epss 0.01

    A vulnerability classified as problematic was found in OpenMRS openmrs-module-referenceapplication up to 2.11.x. Affected by this vulnerability is the function post of the file omod/src/main/java/org/openmrs/module/referenceapplication/page/controller/UserAppPageController.java…

  • CVE-2021-4288LowDec 27, 2022
    risk 0.00cvss 3.5epss 0.01

    A vulnerability was found in OpenMRS openmrs-module-referenceapplication up to 2.11.x. It has been rated as problematic. This issue affects some unknown processing of the file omod/src/main/webapp/pages/userApp.gsp. The manipulation leads to cross site scripting. The attack may…

  • CVE-2021-4285LowDec 27, 2022
    risk 0.00cvss 3.5epss 0.02

    A vulnerability classified as problematic was found in Nagios NCPA. This vulnerability affects unknown code of the file agent/listener/templates/tail.html. The manipulation of the argument name leads to cross site scripting. The attack can be initiated remotely. Upgrading to…

  • CVE-2022-4755LowDec 27, 2022
    risk 0.00cvss 3.5epss 0.01

    A vulnerability was found in FlatPress and classified as problematic. This issue affects the function main of the file fp-plugins/mediamanager/panels/panel.mediamanager.file.php of the component Media Manager Plugin. The manipulation of the argument mm-newgallery-name leads to…

  • CVE-2021-4284LowDec 27, 2022
    risk 0.00cvss 3.5epss 0.01

    A vulnerability classified as problematic has been found in OpenMRS HTML Form Entry UI Framework Integration Module up to 1.x. This affects an unknown part. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. Upgrading to version 2.0.0…

  • CVE-2021-4283LowDec 27, 2022
    risk 0.00cvss 2.4epss 0.01

    A vulnerability was found in FreeBPX voicemail. It has been rated as problematic. Affected by this issue is some unknown functionality of the file views/ssettings.php of the component Settings Handler. The manipulation of the argument key leads to cross site scripting. The…

  • CVE-2021-4282LowDec 27, 2022
    risk 0.00cvss 3.5epss 0.01

    A vulnerability was found in FreePBX voicemail. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file page.voicemail.php. The manipulation leads to cross site scripting. The attack can be launched remotely. Upgrading to…

  • CVE-2022-4736LowDec 25, 2022
    risk 0.00cvss 3.5epss 0.01

    A vulnerability was found in Venganzas del Pasado and classified as problematic. Affected by this issue is some unknown functionality. The manipulation of the argument the_title leads to cross site scripting. The attack may be launched remotely. The name of the patch is…

  • CVE-2019-25084LowDec 25, 2022
    risk 0.00cvss 3.5epss 0.01

    A vulnerability, which was classified as problematic, has been found in Hide Files on GitHub up to 2.x. This issue affects the function addEventListener of the file extension/options.js. The manipulation leads to cross site scripting. The attack may be initiated remotely.…

  • CVE-2022-4735LowDec 25, 2022
    risk 0.00cvss 3.5epss 0.01

    A vulnerability classified as problematic was found in asrashley dash-live. This vulnerability affects the function ready of the file static/js/media.js of the component DOM Node Handler. The manipulation leads to cross site scripting. The attack can be initiated remotely. The…

  • CVE-2022-4731LowDec 25, 2022
    risk 0.00cvss 2.4epss 0.01

    A vulnerability, which was classified as problematic, was found in myapnea up to 29.0.x. Affected is an unknown function of the component Title Handler. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. Upgrading to version 29.1.0 is…

  • CVE-2022-4642LowDec 21, 2022
    risk 0.00cvss 3.5epss 0.01

    A vulnerability was found in tatoeba2. It has been classified as problematic. This affects an unknown part of the component Profile Name Handler. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the…

  • CVE-2022-4637LowDec 21, 2022
    risk 0.00cvss 3.5epss 0.01

    A vulnerability classified as problematic has been found in ep3-bs up to 1.7.x. This affects an unknown part. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. Upgrading to version 1.8.0 is able to address this issue. The name of the…