VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (46,610)

page 2076 of 2,331
  • CVE-2022-35213MedAug 18, 2022
    risk 0.00cvss 6.1epss 0.01

    Ecommerce-CodeIgniter-Bootstrap before commit 56465f was discovered to contain a cross-site scripting (XSS) vulnerability via the function base_url() at /blog/blogpublish.php.

  • CVE-2021-30071MedAug 18, 2022
    risk 0.00cvss 6.1epss 0.01

    A cross-site scripting (XSS) vulnerability in /admin/list_key.html of HestiaCP before v1.3.5 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

  • CVE-2022-2731MedAug 9, 2022
    risk 0.00cvss 6.1epss 0.01

    Cross-site Scripting (XSS) - Reflected in GitHub repository openemr/openemr prior to 7.0.0.1.

  • CVE-2022-2729MedAug 9, 2022
    risk 0.00cvss 5.4epss 0.01

    Cross-site Scripting (XSS) - DOM in GitHub repository openemr/openemr prior to 7.0.0.1.

  • CVE-2022-35653MedJul 25, 2022
    risk 0.00cvss 6.1epss 0.04

    A reflected XSS issue was identified in the LTI module of Moodle. The vulnerability exists due to insufficient sanitization of user-supplied data in the LTI module. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script…

  • CVE-2022-35651MedJul 25, 2022
    risk 0.00cvss 6.1epss 0.01

    A stored XSS and blind SSRF vulnerability was found in Moodle, occurs due to insufficient sanitization of user-supplied data in the SCORM track details. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's…

  • CVE-2022-2494MedJul 22, 2022
    risk 0.00cvss 5.4epss 0.01

    Cross-site Scripting (XSS) - Stored in GitHub repository openemr/openemr prior to 7.0.0.

  • CVE-2022-27168MedJul 11, 2022
    risk 0.00cvss 6.1epss 0.01

    Cross-site scripting vulnerability in LiteCart versions prior to 2.4.2 allows a remote attacker to inject an arbitrary script via unspecified vectors.

  • CVE-2022-2365MedJul 10, 2022
    risk 0.00cvss 5.4epss 0.00

    Cross-site Scripting (XSS) - Stored in GitHub repository zadam/trilium prior to 0.53.3.

  • CVE-2022-31029MedJul 7, 2022
    risk 0.00cvss 5.9epss 0.00

    AdminLTE is a Pi-hole Dashboard for stats and configuration. In affected versions inserting code like `` in the field marked with "Domain to look for" and hitting enter (or clicking on any of the buttons) will execute the script. The user…

  • CVE-2022-31136MedJul 7, 2022
    risk 0.00cvss 6.3epss 0.01

    Bookwyrm is an open source social reading and reviewing program. Versions of Bookwyrm prior to 0.4.1 did not properly sanitize html being rendered to users. Unprivileged users are able to inject scripts into user profiles, book descriptions, and statuses. These vulnerabilities…

  • CVE-2022-31133MedJul 7, 2022
    risk 0.00cvss 5.9epss 0.01

    HumHub is an Open Source Enterprise Social Network. Affected versions of HumHub are vulnerable to a stored Cross-Site Scripting (XSS) vulnerability. For exploitation, the attacker would need a permission to administer the Spaces feature. The names of individual "spaces" are not…

  • CVE-2022-2342MedJul 7, 2022
    risk 0.00cvss 5.4epss 0.01

    Cross-site Scripting (XSS) - Stored in GitHub repository outline/outline prior to v0.64.4.

  • CVE-2022-2290MedJul 3, 2022
    risk 0.00cvss 6.1epss 0.03

    Cross-site Scripting (XSS) - Reflected in GitHub repository zadam/trilium prior to 0.52.4, 0.53.1-beta.

  • CVE-2021-37524MedJul 1, 2022
    risk 0.00cvss 6.1epss 0.01

    Cross Site Scripting (XSS) vulnerability in FusionPBX 4.5.26 allows remote unauthenticated users to inject arbitrary web script or HTML via an unsanitized "path" parameter in resources/login.php.

  • CVE-2022-31113MedJul 1, 2022
    risk 0.00cvss 6.3epss 0.01

    Canarytokens is an open source tool which helps track activity and actions on your network. A Cross-Site Scripting vulnerability was identified in the history page of triggered Canarytokens. This permits an attacker who recognised an HTTP-based Canarytoken (a URL) to execute…

  • CVE-2022-34133MedJun 28, 2022
    risk 0.00cvss 6.1epss 0.01

    Jorani v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Comment parameter at application/controllers/Leaves.php.

  • CVE-2022-31094HigJun 27, 2022
    risk 0.00cvss 7.1epss 0.01

    ScratchTools is a web extension designed to make interacting with the Scratch programming language community (Scratching) easier. In affected versions anybody who uses the Recently Viewed Projects feature is vulnerable to having their account taken over if they view a project…

  • CVE-2022-31065MedJun 27, 2022
    risk 0.00cvss 6.5epss 0.01

    BigBlueButton is an open source web conferencing system. In affected versions an attacker can embed malicious JS in their username and have it executed on the victim's client. When a user receives a private chat from the attacker (whose username contains malicious JavaScript),…

  • CVE-2022-31064MedJun 27, 2022
    risk 0.00cvss 6.5epss 0.01

    BigBlueButton is an open source web conferencing system. Users in meetings with private chat enabled are vulnerable to a cross site scripting attack in affected versions. The attack occurs when the attacker (with xss in the name) starts a chat. in the victim's client the…