VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (46,610)

page 2075 of 2,331
  • CVE-2022-39270MedOct 6, 2022
    risk 0.00cvss 5.4epss 0.00

    DiscoTOC is a Discourse theme component that generates a table of contents for topics. Users that can create topics in TOC-enabled categories (and have sufficient trust level - configured in component's settings) are able to inject arbitrary HTML on that topic's page. The issue…

  • CVE-2022-32172Oct 6, 2022
    risk 0.00cvss epss 0.01

    In Zinc, versions v0.1.9 through v0.3.1 are vulnerable to Stored Cross-Site Scripting when using the delete template functionality. When an authenticated user deletes a template with a XSS payload in the name field, the Javascript payload will be executed and allow an attacker…

  • CVE-2022-32171Oct 6, 2022
    risk 0.00cvss epss 0.01

    In Zinc, versions v0.1.9 through v0.3.1 are vulnerable to Stored Cross-Site Scripting when using the delete user functionality. When an authenticated user deletes a user having a XSS payload in the user id field, the javascript payload will be executed and allow an attacker to…

  • CVE-2022-42247MedOct 3, 2022
    risk 0.00cvss 6.1epss 0.03

    pfSense v2.5.2 was discovered to contain a cross-site scripting (XSS) vulnerability in the browser.php component. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into a file name.

  • CVE-2022-1719MedSep 29, 2022
    risk 0.00cvss 5.4epss 0.01

    Reflected XSS on ticket filter function in GitHub repository polonel/trudesk prior to 1.2.2. This vulnerability is capable of executing a malicious javascript code in web page

  • CVE-2022-3223MedSep 16, 2022
    risk 0.00cvss 6.1epss 0.01

    Cross-site Scripting (XSS) - Stored in GitHub repository jgraph/drawio prior to 20.3.1.

  • CVE-2022-35945MedSep 14, 2022
    risk 0.00cvss 6.3epss 0.01

    GLPI stands for Gestionnaire Libre de Parc Informatique and is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. Information associated to registration key are not properly escaped in registration…

  • CVE-2022-31187MedSep 14, 2022
    risk 0.00cvss 6.8epss 0.01

    GLPI stands for Gestionnaire Libre de Parc Informatique and is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. Affected versions were found to not properly neutralize HTML tags in the global…

  • CVE-2022-39207MedSep 13, 2022
    risk 0.00cvss 5.4epss 0.01

    Onedev is an open source, self-hosted Git Server with CI/CD and Kanban. During CI/CD builds, it is possible to save build artifacts for later retrieval. They can be accessed through OneDev's web UI after the successful run of a build. These artifact files are served by the…

  • CVE-2022-40317MedSep 9, 2022
    risk 0.00cvss 5.4epss 0.01

    OpenKM 6.3.11 allows stored XSS related to the javascript: substring in an A element.

  • CVE-2022-3148MedSep 8, 2022
    risk 0.00cvss 6.1epss 0.01

    Cross-site Scripting (XSS) - Generic in GitHub repository jgraph/drawio prior to 20.3.0.

  • CVE-2022-3138MedSep 8, 2022
    risk 0.00cvss 6.1epss 0.01

    Cross-site Scripting (XSS) - Generic in GitHub repository jgraph/drawio prior to 20.3.0.

  • CVE-2022-36080MedSep 7, 2022
    risk 0.00cvss 6.1epss 0.00

    Wikmd is a file based wiki that uses markdown. Prior to version 1.7.1, an attacker could capture user's session cookies or execute malicious Javascript when a victim edits a markdown file. Version 1.7.1 fixes this issue.

  • CVE-2022-36057MedSep 6, 2022
    risk 0.00cvss 5.4epss 0.00

    Discourse-Chat is an asynchronous messaging plugin for the Discourse open-source discussion platform. Users of Discourse Chat can be affected by admin users inserting HTML into chat titles and descriptions, causing a Cross-Site Scripting (XSS) attack. Version 0.9 contains a…

  • CVE-2022-3127MedSep 5, 2022
    risk 0.00cvss 5.4epss 0.01

    Cross-site Scripting (XSS) - Stored in GitHub repository jgraph/drawio prior to 20.2.8.

  • CVE-2022-3123MedSep 5, 2022
    risk 0.00cvss 6.1epss 0.01

    Cross-site Scripting (XSS) - Reflected in GitHub repository splitbrain/dokuwiki prior to 2022-07-31a.

  • CVE-2022-2829MedAug 23, 2022
    risk 0.00cvss 5.4epss 0.01

    Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0.

  • CVE-2022-0542MedAug 19, 2022
    risk 0.00cvss 6.1epss 0.01

    Cross-site Scripting (XSS) - DOM in GitHub repository chatwoot/chatwoot prior to 2.7.0.

  • CVE-2022-35910MedAug 19, 2022
    risk 0.00cvss 5.4epss 0.01

    In Jellyfin before 10.8, stored XSS allows theft of an admin access token.

  • CVE-2022-1021MedAug 19, 2022
    risk 0.00cvss 5.4epss 0.01

    Insecure Storage of Sensitive Information in GitHub repository chatwoot/chatwoot prior to 2.6.0.