VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (46,610)

page 2078 of 2,331
  • CVE-2021-38221MedJun 2, 2022
    risk 0.00cvss 5.4epss 0.01

    bbs-go <= 3.3.0 including Custom Edition is vulnerable to stored XSS.

  • CVE-2022-1909MedMay 27, 2022
    risk 0.00cvss 5.4epss 0.01

    Cross-site Scripting (XSS) - Stored in GitHub repository causefx/organizr prior to 2.1.2200.

  • CVE-2022-29710MedMay 25, 2022
    risk 0.00cvss 6.1epss 0.01

    A cross-site scripting (XSS) vulnerability in uploadConfirm.php of LimeSurvey v5.3.9 and below allows attackers to execute arbitrary web scripts or HTML via a crafted plugin.

  • CVE-2022-1825MedMay 23, 2022
    risk 0.00cvss 5.4epss 0.01

    Cross-site Scripting (XSS) - Reflected in GitHub repository collectiveaccess/providence prior to 1.8.

  • CVE-2022-29183MedMay 20, 2022
    risk 0.00cvss 4.3epss 0.01

    GoCD is a continuous delivery server. GoCD versions 20.2.0 until 21.4.0 are vulnerable to reflected cross-site scripting via abuse of the pipeline comparison function's error handling to render arbitrary HTML into the returned page. This could allow an attacker to trick a victim…

  • CVE-2022-29182MedMay 20, 2022
    risk 0.00cvss 4.3epss 0.01

    GoCD is a continuous delivery server. GoCD versions 19.11.0 through 21.4.0 (inclusive) are vulnerable to a Document Object Model (DOM)-based cross-site scripting attack via a pipeline run's Stage Details > Graphs tab. It is possible for a malicious script on a attacker-hosted…

  • CVE-2022-1806MedMay 20, 2022
    risk 0.00cvss 6.1epss 0.01

    Cross-site Scripting (XSS) - Reflected in GitHub repository rtxteam/rtx prior to checkpoint_2022-05-18.

  • CVE-2022-1730MedMay 19, 2022
    risk 0.00cvss 4.6epss 0.01

    Cross-site Scripting (XSS) - Stored in GitHub repository jgraph/drawio prior to 18.0.4.

  • CVE-2022-23068MedMay 18, 2022
    risk 0.00cvss 5.4epss 0.01

    ToolJet versions v0.6.0 to v1.10.2 are vulnerable to HTML injection where an attacker can inject malicious code inside the first name and last name field while inviting a new user which will be reflected in the invitational e-mail.

  • CVE-2022-30963MedMay 17, 2022
    risk 0.00cvss 5.4epss 0.01

    Jenkins JDK Parameter Plugin 1.0 and earlier does not escape the name and description of JDK parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.

  • CVE-2021-42648MedMay 11, 2022
    risk 0.00cvss 6.1epss 0.01

    Cross-site scripting (XSS) vulnerability exists in Coder Code-Server before 3.12.0, allows attackers to execute arbitrary code via crafted URL.

  • CVE-2022-28545MedMay 6, 2022
    risk 0.00cvss 5.4epss 0.00

    FUDforum 3.1.1 is vulnerable to Stored XSS.

  • CVE-2022-1575CriMay 5, 2022
    risk 0.00cvss 9.6epss 0.02

    Arbitrary Code Execution through Sanitizer Bypass in GitHub repository jgraph/drawio prior to 18.0.0. - Arbitrary (remote) code execution in the desktop app. - Stored XSS in the web app.

  • CVE-2022-23065MedMay 2, 2022
    risk 0.00cvss 5.4epss 0.01

    In Vendure versions 0.1.0-alpha.2 to 1.5.1 are affected by Stored XSS vulnerability, where an attacker having catalog permission can upload a SVG file that contains malicious JavaScript into the “Assets” tab. The uploaded file will affect administrators as well as regular…

  • CVE-2022-23060MedMay 1, 2022
    risk 0.00cvss 4.8epss 0.01

    A Stored Cross Site Scripting (XSS) vulnerability exists in Shopizer versions 2.0 through 2.17.0, where a privileged user (attacker) can inject malicious JavaScript in the filename under the “Manage files” tab

  • CVE-2022-1458MedApr 25, 2022
    risk 0.00cvss 5.4epss 0.01

    Stored XSS Leads To Session Hijacking in GitHub repository openemr/openemr prior to 6.1.0.1.

  • CVE-2022-29589MedApr 22, 2022
    risk 0.00cvss 6.1epss 0.01

    Crypt Server before 3.3.0 allows XSS in the index view. This is related to serial, computername, and username.

  • CVE-2022-24870HigApr 21, 2022
    risk 0.00cvss 8.7epss 0.01

    Combodo iTop is a web based IT Service Management tool. In 3.0.0 beta releases prior to 3.0.0 beta3 a malicious script can be injected in tooltips using iTop customization mechanism. This provides a stored cross site scripting attack vector to authorized users of the system.…

  • CVE-2022-24869MedApr 21, 2022
    risk 0.00cvss 4.6epss 0.01

    GLPI is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. In versions prior to 10.0.0 one can use ticket's followups or setup login messages with a stylesheet link. This may allow for a cross site…

  • CVE-2022-24868HigApr 21, 2022
    risk 0.00cvss 7.3epss 0.01

    GLPI is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. In versions prior to 10.0.0 one can exploit a lack of sanitization on SVG file uploads and inject javascript into their user avatar. As a…