CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Description
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85
CVEs mapped to this weakness (46,610)
page 2075 of 2,331| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-39270 | Med | 0.00 | 5.4 | 0.00 | Oct 6, 2022 | DiscoTOC is a Discourse theme component that generates a table of contents for topics. Users that can create topics in TOC-enabled categories (and have sufficient trust level - configured in component's settings) are able to inject arbitrary HTML on that topic's page. The issue… | ||
| CVE-2022-32172 | 0.00 | — | 0.01 | Oct 6, 2022 | In Zinc, versions v0.1.9 through v0.3.1 are vulnerable to Stored Cross-Site Scripting when using the delete template functionality. When an authenticated user deletes a template with a XSS payload in the name field, the Javascript payload will be executed and allow an attacker… | |||
| CVE-2022-32171 | 0.00 | — | 0.01 | Oct 6, 2022 | In Zinc, versions v0.1.9 through v0.3.1 are vulnerable to Stored Cross-Site Scripting when using the delete user functionality. When an authenticated user deletes a user having a XSS payload in the user id field, the javascript payload will be executed and allow an attacker to… | |||
| CVE-2022-42247 | Med | 0.00 | 6.1 | 0.03 | Oct 3, 2022 | pfSense v2.5.2 was discovered to contain a cross-site scripting (XSS) vulnerability in the browser.php component. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into a file name. | ||
| CVE-2022-1719 | Med | 0.00 | 5.4 | 0.01 | Sep 29, 2022 | Reflected XSS on ticket filter function in GitHub repository polonel/trudesk prior to 1.2.2. This vulnerability is capable of executing a malicious javascript code in web page | ||
| CVE-2022-3223 | Med | 0.00 | 6.1 | 0.01 | Sep 16, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository jgraph/drawio prior to 20.3.1. | ||
| CVE-2022-35945 | Med | 0.00 | 6.3 | 0.01 | Sep 14, 2022 | GLPI stands for Gestionnaire Libre de Parc Informatique and is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. Information associated to registration key are not properly escaped in registration… | ||
| CVE-2022-31187 | Med | 0.00 | 6.8 | 0.01 | Sep 14, 2022 | GLPI stands for Gestionnaire Libre de Parc Informatique and is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. Affected versions were found to not properly neutralize HTML tags in the global… | ||
| CVE-2022-39207 | Med | 0.00 | 5.4 | 0.01 | Sep 13, 2022 | Onedev is an open source, self-hosted Git Server with CI/CD and Kanban. During CI/CD builds, it is possible to save build artifacts for later retrieval. They can be accessed through OneDev's web UI after the successful run of a build. These artifact files are served by the… | ||
| CVE-2022-40317 | Med | 0.00 | 5.4 | 0.01 | Sep 9, 2022 | OpenKM 6.3.11 allows stored XSS related to the javascript: substring in an A element. | ||
| CVE-2022-3148 | Med | 0.00 | 6.1 | 0.01 | Sep 8, 2022 | Cross-site Scripting (XSS) - Generic in GitHub repository jgraph/drawio prior to 20.3.0. | ||
| CVE-2022-3138 | Med | 0.00 | 6.1 | 0.01 | Sep 8, 2022 | Cross-site Scripting (XSS) - Generic in GitHub repository jgraph/drawio prior to 20.3.0. | ||
| CVE-2022-36080 | Med | 0.00 | 6.1 | 0.00 | Sep 7, 2022 | Wikmd is a file based wiki that uses markdown. Prior to version 1.7.1, an attacker could capture user's session cookies or execute malicious Javascript when a victim edits a markdown file. Version 1.7.1 fixes this issue. | ||
| CVE-2022-36057 | Med | 0.00 | 5.4 | 0.00 | Sep 6, 2022 | Discourse-Chat is an asynchronous messaging plugin for the Discourse open-source discussion platform. Users of Discourse Chat can be affected by admin users inserting HTML into chat titles and descriptions, causing a Cross-Site Scripting (XSS) attack. Version 0.9 contains a… | ||
| CVE-2022-3127 | Med | 0.00 | 5.4 | 0.01 | Sep 5, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository jgraph/drawio prior to 20.2.8. | ||
| CVE-2022-3123 | Med | 0.00 | 6.1 | 0.01 | Sep 5, 2022 | Cross-site Scripting (XSS) - Reflected in GitHub repository splitbrain/dokuwiki prior to 2022-07-31a. | ||
| CVE-2022-2829 | Med | 0.00 | 5.4 | 0.01 | Aug 23, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0. | ||
| CVE-2022-0542 | Med | 0.00 | 6.1 | 0.01 | Aug 19, 2022 | Cross-site Scripting (XSS) - DOM in GitHub repository chatwoot/chatwoot prior to 2.7.0. | ||
| CVE-2022-35910 | Med | 0.00 | 5.4 | 0.01 | Aug 19, 2022 | In Jellyfin before 10.8, stored XSS allows theft of an admin access token. | ||
| CVE-2022-1021 | Med | 0.00 | 5.4 | 0.01 | Aug 19, 2022 | Insecure Storage of Sensitive Information in GitHub repository chatwoot/chatwoot prior to 2.6.0. |
- risk 0.00cvss 5.4epss 0.00
DiscoTOC is a Discourse theme component that generates a table of contents for topics. Users that can create topics in TOC-enabled categories (and have sufficient trust level - configured in component's settings) are able to inject arbitrary HTML on that topic's page. The issue…
- CVE-2022-32172Oct 6, 2022risk 0.00cvss —epss 0.01
In Zinc, versions v0.1.9 through v0.3.1 are vulnerable to Stored Cross-Site Scripting when using the delete template functionality. When an authenticated user deletes a template with a XSS payload in the name field, the Javascript payload will be executed and allow an attacker…
- CVE-2022-32171Oct 6, 2022risk 0.00cvss —epss 0.01
In Zinc, versions v0.1.9 through v0.3.1 are vulnerable to Stored Cross-Site Scripting when using the delete user functionality. When an authenticated user deletes a user having a XSS payload in the user id field, the javascript payload will be executed and allow an attacker to…
- risk 0.00cvss 6.1epss 0.03
pfSense v2.5.2 was discovered to contain a cross-site scripting (XSS) vulnerability in the browser.php component. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into a file name.
- risk 0.00cvss 5.4epss 0.01
Reflected XSS on ticket filter function in GitHub repository polonel/trudesk prior to 1.2.2. This vulnerability is capable of executing a malicious javascript code in web page
- risk 0.00cvss 6.1epss 0.01
Cross-site Scripting (XSS) - Stored in GitHub repository jgraph/drawio prior to 20.3.1.
- risk 0.00cvss 6.3epss 0.01
GLPI stands for Gestionnaire Libre de Parc Informatique and is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. Information associated to registration key are not properly escaped in registration…
- risk 0.00cvss 6.8epss 0.01
GLPI stands for Gestionnaire Libre de Parc Informatique and is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. Affected versions were found to not properly neutralize HTML tags in the global…
- risk 0.00cvss 5.4epss 0.01
Onedev is an open source, self-hosted Git Server with CI/CD and Kanban. During CI/CD builds, it is possible to save build artifacts for later retrieval. They can be accessed through OneDev's web UI after the successful run of a build. These artifact files are served by the…
- risk 0.00cvss 5.4epss 0.01
OpenKM 6.3.11 allows stored XSS related to the javascript: substring in an A element.
- risk 0.00cvss 6.1epss 0.01
Cross-site Scripting (XSS) - Generic in GitHub repository jgraph/drawio prior to 20.3.0.
- risk 0.00cvss 6.1epss 0.01
Cross-site Scripting (XSS) - Generic in GitHub repository jgraph/drawio prior to 20.3.0.
- risk 0.00cvss 6.1epss 0.00
Wikmd is a file based wiki that uses markdown. Prior to version 1.7.1, an attacker could capture user's session cookies or execute malicious Javascript when a victim edits a markdown file. Version 1.7.1 fixes this issue.
- risk 0.00cvss 5.4epss 0.00
Discourse-Chat is an asynchronous messaging plugin for the Discourse open-source discussion platform. Users of Discourse Chat can be affected by admin users inserting HTML into chat titles and descriptions, causing a Cross-Site Scripting (XSS) attack. Version 0.9 contains a…
- risk 0.00cvss 5.4epss 0.01
Cross-site Scripting (XSS) - Stored in GitHub repository jgraph/drawio prior to 20.2.8.
- risk 0.00cvss 6.1epss 0.01
Cross-site Scripting (XSS) - Reflected in GitHub repository splitbrain/dokuwiki prior to 2022-07-31a.
- risk 0.00cvss 5.4epss 0.01
Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0.
- risk 0.00cvss 6.1epss 0.01
Cross-site Scripting (XSS) - DOM in GitHub repository chatwoot/chatwoot prior to 2.7.0.
- risk 0.00cvss 5.4epss 0.01
In Jellyfin before 10.8, stored XSS allows theft of an admin access token.
- risk 0.00cvss 5.4epss 0.01
Insecure Storage of Sensitive Information in GitHub repository chatwoot/chatwoot prior to 2.6.0.