CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Description
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85
CVEs mapped to this weakness (46,610)
page 2077 of 2,331| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-34189 | Med | 0.00 | 5.4 | 0.01 | Jun 23, 2022 | Jenkins Image Tag Parameter Plugin 1.10 and earlier does not escape the name and description of Image Tag parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission. | ||
| CVE-2022-34185 | Med | 0.00 | 5.4 | 0.01 | Jun 23, 2022 | Jenkins Date Parameter Plugin 0.0.4 and earlier does not escape the name and description of Date parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission. | ||
| CVE-2022-32159 | 0.00 | — | 0.01 | Jun 22, 2022 | In openlibrary versions deploy-2016-07-0 through deploy-2021-12-22 are vulnerable to Stored XSS. | |||
| CVE-2022-23081 | 0.00 | — | 0.01 | Jun 22, 2022 | In openlibrary versions deploy-2016-07-0 through deploy-2021-12-22 are vulnerable to Reflected XSS. | |||
| CVE-2022-23077 | Med | 0.00 | 6.1 | 0.01 | Jun 22, 2022 | In habitica versions v4.119.0 through v4.232.2 are vulnerable to DOM XSS via the login page. | ||
| CVE-2022-23058 | 0.00 | — | 0.01 | Jun 22, 2022 | ERPNext in versions v12.0.9-v13.0.3 are affected by a stored XSS vulnerability that allows low privileged users to store malicious scripts in the ‘username’ field in ‘my settings’ which can lead to full account takeover. | |||
| CVE-2022-23057 | Med | 0.00 | 5.4 | 0.01 | Jun 22, 2022 | In ERPNext, versions v12.0.9--v13.0.3 are vulnerable to Stored Cross-Site-Scripting (XSS), due to user input not being validated properly. A low privileged attacker could inject arbitrary code into input fields when editing his profile. | ||
| CVE-2022-23056 | 0.00 | — | 0.01 | Jun 22, 2022 | In ERPNext, versions v13.0.0-beta.13 through v13.30.0 are vulnerable to Stored XSS at the Patient History page which allows a low privilege user to conduct an account takeover attack. | |||
| CVE-2021-41924 | Med | 0.00 | 6.1 | 0.01 | Jun 21, 2022 | Webkul krayin crm before 1.2.2 is vulnerable to Cross Site Scripting (XSS). | ||
| CVE-2022-23074 | 0.00 | — | 0.01 | Jun 21, 2022 | In Recipes, versions 0.17.0 through 1.2.5 are vulnerable to Stored Cross-Site Scripting (XSS), in the ‘Name’ field of Keyword, Food and Unit components. When a victim accesses the Keyword/Food/Unit endpoints, the XSS payload will trigger. A low privileged attacker will have… | |||
| CVE-2022-23073 | 0.00 | — | 0.01 | Jun 21, 2022 | In Recipes, versions 1.0.5 through 1.2.5 are vulnerable to Stored Cross-Site Scripting (XSS), in copy to clipboard functionality. When a victim accesses the food list page, then adds a new Food with a malicious javascript payload in the ‘Name’ parameter and clicks on the… | |||
| CVE-2022-23072 | 0.00 | — | 0.01 | Jun 21, 2022 | In Recipes, versions 1.0.5 through 1.2.5 are vulnerable to Stored Cross-Site Scripting (XSS), in “Add to Cart” functionality. When a victim accesses the food list page, then adds a new Food with a malicious javascript payload in the ‘Name’ parameter and clicks on the Add… | |||
| CVE-2022-2113 | Med | 0.00 | 5.4 | 0.01 | Jun 17, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository inventree/inventree prior to 0.7.2. | ||
| CVE-2022-31059 | Med | 0.00 | 6.5 | 0.01 | Jun 14, 2022 | Discourse Calendar is a calendar plugin for Discourse, an open-source messaging app. Prior to version 1.0.1, parsing and rendering of Event names can be susceptible to cross-site scripting (XSS) attacks. This vulnerability only affects sites which have modified or disabled… | ||
| CVE-2022-24876 | Med | 0.00 | 5.4 | 0.01 | Jun 9, 2022 | GLPI is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. Kanban is a GLPI view to display Projects, Tickets, Changes or Problems on a task board. In versions prior to 10.0.1 a user can exploit a… | ||
| CVE-2022-2029 | Med | 0.00 | 5.4 | 0.01 | Jun 9, 2022 | Cross-site Scripting (XSS) - DOM in GitHub repository kromitgmbh/titra prior to 0.77.0. | ||
| CVE-2022-2028 | Med | 0.00 | 5.4 | 0.01 | Jun 9, 2022 | Cross-site Scripting (XSS) - Generic in GitHub repository kromitgmbh/titra prior to 0.77.0. | ||
| CVE-2022-2026 | Med | 0.00 | 5.4 | 0.01 | Jun 9, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository kromitgmbh/titra prior to 0.77.0. | ||
| CVE-2022-2015 | Med | 0.00 | 5.4 | 0.01 | Jun 9, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository jgraph/drawio prior to 19.0.2. | ||
| CVE-2022-2022 | Med | 0.00 | 5.4 | 0.01 | Jun 7, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository nocodb/nocodb prior to 0.91.7. |
- risk 0.00cvss 5.4epss 0.01
Jenkins Image Tag Parameter Plugin 1.10 and earlier does not escape the name and description of Image Tag parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.
- risk 0.00cvss 5.4epss 0.01
Jenkins Date Parameter Plugin 0.0.4 and earlier does not escape the name and description of Date parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.
- CVE-2022-32159Jun 22, 2022risk 0.00cvss —epss 0.01
In openlibrary versions deploy-2016-07-0 through deploy-2021-12-22 are vulnerable to Stored XSS.
- CVE-2022-23081Jun 22, 2022risk 0.00cvss —epss 0.01
In openlibrary versions deploy-2016-07-0 through deploy-2021-12-22 are vulnerable to Reflected XSS.
- risk 0.00cvss 6.1epss 0.01
In habitica versions v4.119.0 through v4.232.2 are vulnerable to DOM XSS via the login page.
- CVE-2022-23058Jun 22, 2022risk 0.00cvss —epss 0.01
ERPNext in versions v12.0.9-v13.0.3 are affected by a stored XSS vulnerability that allows low privileged users to store malicious scripts in the ‘username’ field in ‘my settings’ which can lead to full account takeover.
- risk 0.00cvss 5.4epss 0.01
In ERPNext, versions v12.0.9--v13.0.3 are vulnerable to Stored Cross-Site-Scripting (XSS), due to user input not being validated properly. A low privileged attacker could inject arbitrary code into input fields when editing his profile.
- CVE-2022-23056Jun 22, 2022risk 0.00cvss —epss 0.01
In ERPNext, versions v13.0.0-beta.13 through v13.30.0 are vulnerable to Stored XSS at the Patient History page which allows a low privilege user to conduct an account takeover attack.
- risk 0.00cvss 6.1epss 0.01
Webkul krayin crm before 1.2.2 is vulnerable to Cross Site Scripting (XSS).
- CVE-2022-23074Jun 21, 2022risk 0.00cvss —epss 0.01
In Recipes, versions 0.17.0 through 1.2.5 are vulnerable to Stored Cross-Site Scripting (XSS), in the ‘Name’ field of Keyword, Food and Unit components. When a victim accesses the Keyword/Food/Unit endpoints, the XSS payload will trigger. A low privileged attacker will have…
- CVE-2022-23073Jun 21, 2022risk 0.00cvss —epss 0.01
In Recipes, versions 1.0.5 through 1.2.5 are vulnerable to Stored Cross-Site Scripting (XSS), in copy to clipboard functionality. When a victim accesses the food list page, then adds a new Food with a malicious javascript payload in the ‘Name’ parameter and clicks on the…
- CVE-2022-23072Jun 21, 2022risk 0.00cvss —epss 0.01
In Recipes, versions 1.0.5 through 1.2.5 are vulnerable to Stored Cross-Site Scripting (XSS), in “Add to Cart” functionality. When a victim accesses the food list page, then adds a new Food with a malicious javascript payload in the ‘Name’ parameter and clicks on the Add…
- risk 0.00cvss 5.4epss 0.01
Cross-site Scripting (XSS) - Stored in GitHub repository inventree/inventree prior to 0.7.2.
- risk 0.00cvss 6.5epss 0.01
Discourse Calendar is a calendar plugin for Discourse, an open-source messaging app. Prior to version 1.0.1, parsing and rendering of Event names can be susceptible to cross-site scripting (XSS) attacks. This vulnerability only affects sites which have modified or disabled…
- risk 0.00cvss 5.4epss 0.01
GLPI is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. Kanban is a GLPI view to display Projects, Tickets, Changes or Problems on a task board. In versions prior to 10.0.1 a user can exploit a…
- risk 0.00cvss 5.4epss 0.01
Cross-site Scripting (XSS) - DOM in GitHub repository kromitgmbh/titra prior to 0.77.0.
- risk 0.00cvss 5.4epss 0.01
Cross-site Scripting (XSS) - Generic in GitHub repository kromitgmbh/titra prior to 0.77.0.
- risk 0.00cvss 5.4epss 0.01
Cross-site Scripting (XSS) - Stored in GitHub repository kromitgmbh/titra prior to 0.77.0.
- risk 0.00cvss 5.4epss 0.01
Cross-site Scripting (XSS) - Stored in GitHub repository jgraph/drawio prior to 19.0.2.
- risk 0.00cvss 5.4epss 0.01
Cross-site Scripting (XSS) - Stored in GitHub repository nocodb/nocodb prior to 0.91.7.