VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (46,610)

page 2077 of 2,331
  • CVE-2022-34189MedJun 23, 2022
    risk 0.00cvss 5.4epss 0.01

    Jenkins Image Tag Parameter Plugin 1.10 and earlier does not escape the name and description of Image Tag parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.

  • CVE-2022-34185MedJun 23, 2022
    risk 0.00cvss 5.4epss 0.01

    Jenkins Date Parameter Plugin 0.0.4 and earlier does not escape the name and description of Date parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.

  • CVE-2022-32159Jun 22, 2022
    risk 0.00cvss epss 0.01

    In openlibrary versions deploy-2016-07-0 through deploy-2021-12-22 are vulnerable to Stored XSS.

  • CVE-2022-23081Jun 22, 2022
    risk 0.00cvss epss 0.01

    In openlibrary versions deploy-2016-07-0 through deploy-2021-12-22 are vulnerable to Reflected XSS.

  • CVE-2022-23077MedJun 22, 2022
    risk 0.00cvss 6.1epss 0.01

    In habitica versions v4.119.0 through v4.232.2 are vulnerable to DOM XSS via the login page.

  • CVE-2022-23058Jun 22, 2022
    risk 0.00cvss epss 0.01

    ERPNext in versions v12.0.9-v13.0.3 are affected by a stored XSS vulnerability that allows low privileged users to store malicious scripts in the ‘username’ field in ‘my settings’ which can lead to full account takeover.

  • CVE-2022-23057MedJun 22, 2022
    risk 0.00cvss 5.4epss 0.01

    In ERPNext, versions v12.0.9--v13.0.3 are vulnerable to Stored Cross-Site-Scripting (XSS), due to user input not being validated properly. A low privileged attacker could inject arbitrary code into input fields when editing his profile.

  • CVE-2022-23056Jun 22, 2022
    risk 0.00cvss epss 0.01

    In ERPNext, versions v13.0.0-beta.13 through v13.30.0 are vulnerable to Stored XSS at the Patient History page which allows a low privilege user to conduct an account takeover attack.

  • CVE-2021-41924MedJun 21, 2022
    risk 0.00cvss 6.1epss 0.01

    Webkul krayin crm before 1.2.2 is vulnerable to Cross Site Scripting (XSS).

  • CVE-2022-23074Jun 21, 2022
    risk 0.00cvss epss 0.01

    In Recipes, versions 0.17.0 through 1.2.5 are vulnerable to Stored Cross-Site Scripting (XSS), in the ‘Name’ field of Keyword, Food and Unit components. When a victim accesses the Keyword/Food/Unit endpoints, the XSS payload will trigger. A low privileged attacker will have…

  • CVE-2022-23073Jun 21, 2022
    risk 0.00cvss epss 0.01

    In Recipes, versions 1.0.5 through 1.2.5 are vulnerable to Stored Cross-Site Scripting (XSS), in copy to clipboard functionality. When a victim accesses the food list page, then adds a new Food with a malicious javascript payload in the ‘Name’ parameter and clicks on the…

  • CVE-2022-23072Jun 21, 2022
    risk 0.00cvss epss 0.01

    In Recipes, versions 1.0.5 through 1.2.5 are vulnerable to Stored Cross-Site Scripting (XSS), in “Add to Cart” functionality. When a victim accesses the food list page, then adds a new Food with a malicious javascript payload in the ‘Name’ parameter and clicks on the Add…

  • CVE-2022-2113MedJun 17, 2022
    risk 0.00cvss 5.4epss 0.01

    Cross-site Scripting (XSS) - Stored in GitHub repository inventree/inventree prior to 0.7.2.

  • CVE-2022-31059MedJun 14, 2022
    risk 0.00cvss 6.5epss 0.01

    Discourse Calendar is a calendar plugin for Discourse, an open-source messaging app. Prior to version 1.0.1, parsing and rendering of Event names can be susceptible to cross-site scripting (XSS) attacks. This vulnerability only affects sites which have modified or disabled…

  • CVE-2022-24876MedJun 9, 2022
    risk 0.00cvss 5.4epss 0.01

    GLPI is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. Kanban is a GLPI view to display Projects, Tickets, Changes or Problems on a task board. In versions prior to 10.0.1 a user can exploit a…

  • CVE-2022-2029MedJun 9, 2022
    risk 0.00cvss 5.4epss 0.01

    Cross-site Scripting (XSS) - DOM in GitHub repository kromitgmbh/titra prior to 0.77.0.

  • CVE-2022-2028MedJun 9, 2022
    risk 0.00cvss 5.4epss 0.01

    Cross-site Scripting (XSS) - Generic in GitHub repository kromitgmbh/titra prior to 0.77.0.

  • CVE-2022-2026MedJun 9, 2022
    risk 0.00cvss 5.4epss 0.01

    Cross-site Scripting (XSS) - Stored in GitHub repository kromitgmbh/titra prior to 0.77.0.

  • CVE-2022-2015MedJun 9, 2022
    risk 0.00cvss 5.4epss 0.01

    Cross-site Scripting (XSS) - Stored in GitHub repository jgraph/drawio prior to 19.0.2.

  • CVE-2022-2022MedJun 7, 2022
    risk 0.00cvss 5.4epss 0.01

    Cross-site Scripting (XSS) - Stored in GitHub repository nocodb/nocodb prior to 0.91.7.