CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Description
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85
CVEs mapped to this weakness (46,610)
page 2078 of 2,331| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-38221 | Med | 0.00 | 5.4 | 0.01 | Jun 2, 2022 | bbs-go <= 3.3.0 including Custom Edition is vulnerable to stored XSS. | ||
| CVE-2022-1909 | Med | 0.00 | 5.4 | 0.01 | May 27, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository causefx/organizr prior to 2.1.2200. | ||
| CVE-2022-29710 | Med | 0.00 | 6.1 | 0.01 | May 25, 2022 | A cross-site scripting (XSS) vulnerability in uploadConfirm.php of LimeSurvey v5.3.9 and below allows attackers to execute arbitrary web scripts or HTML via a crafted plugin. | ||
| CVE-2022-1825 | Med | 0.00 | 5.4 | 0.01 | May 23, 2022 | Cross-site Scripting (XSS) - Reflected in GitHub repository collectiveaccess/providence prior to 1.8. | ||
| CVE-2022-29183 | Med | 0.00 | 4.3 | 0.01 | May 20, 2022 | GoCD is a continuous delivery server. GoCD versions 20.2.0 until 21.4.0 are vulnerable to reflected cross-site scripting via abuse of the pipeline comparison function's error handling to render arbitrary HTML into the returned page. This could allow an attacker to trick a victim… | ||
| CVE-2022-29182 | Med | 0.00 | 4.3 | 0.01 | May 20, 2022 | GoCD is a continuous delivery server. GoCD versions 19.11.0 through 21.4.0 (inclusive) are vulnerable to a Document Object Model (DOM)-based cross-site scripting attack via a pipeline run's Stage Details > Graphs tab. It is possible for a malicious script on a attacker-hosted… | ||
| CVE-2022-1806 | Med | 0.00 | 6.1 | 0.01 | May 20, 2022 | Cross-site Scripting (XSS) - Reflected in GitHub repository rtxteam/rtx prior to checkpoint_2022-05-18. | ||
| CVE-2022-1730 | Med | 0.00 | 4.6 | 0.01 | May 19, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository jgraph/drawio prior to 18.0.4. | ||
| CVE-2022-23068 | Med | 0.00 | 5.4 | 0.01 | May 18, 2022 | ToolJet versions v0.6.0 to v1.10.2 are vulnerable to HTML injection where an attacker can inject malicious code inside the first name and last name field while inviting a new user which will be reflected in the invitational e-mail. | ||
| CVE-2022-30963 | Med | 0.00 | 5.4 | 0.01 | May 17, 2022 | Jenkins JDK Parameter Plugin 1.0 and earlier does not escape the name and description of JDK parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission. | ||
| CVE-2021-42648 | Med | 0.00 | 6.1 | 0.01 | May 11, 2022 | Cross-site scripting (XSS) vulnerability exists in Coder Code-Server before 3.12.0, allows attackers to execute arbitrary code via crafted URL. | ||
| CVE-2022-28545 | Med | 0.00 | 5.4 | 0.00 | May 6, 2022 | FUDforum 3.1.1 is vulnerable to Stored XSS. | ||
| CVE-2022-1575 | Cri | 0.00 | 9.6 | 0.02 | May 5, 2022 | Arbitrary Code Execution through Sanitizer Bypass in GitHub repository jgraph/drawio prior to 18.0.0. - Arbitrary (remote) code execution in the desktop app. - Stored XSS in the web app. | ||
| CVE-2022-23065 | Med | 0.00 | 5.4 | 0.01 | May 2, 2022 | In Vendure versions 0.1.0-alpha.2 to 1.5.1 are affected by Stored XSS vulnerability, where an attacker having catalog permission can upload a SVG file that contains malicious JavaScript into the “Assets” tab. The uploaded file will affect administrators as well as regular… | ||
| CVE-2022-23060 | Med | 0.00 | 4.8 | 0.01 | May 1, 2022 | A Stored Cross Site Scripting (XSS) vulnerability exists in Shopizer versions 2.0 through 2.17.0, where a privileged user (attacker) can inject malicious JavaScript in the filename under the “Manage files” tab | ||
| CVE-2022-1458 | Med | 0.00 | 5.4 | 0.01 | Apr 25, 2022 | Stored XSS Leads To Session Hijacking in GitHub repository openemr/openemr prior to 6.1.0.1. | ||
| CVE-2022-29589 | Med | 0.00 | 6.1 | 0.01 | Apr 22, 2022 | Crypt Server before 3.3.0 allows XSS in the index view. This is related to serial, computername, and username. | ||
| CVE-2022-24870 | Hig | 0.00 | 8.7 | 0.01 | Apr 21, 2022 | Combodo iTop is a web based IT Service Management tool. In 3.0.0 beta releases prior to 3.0.0 beta3 a malicious script can be injected in tooltips using iTop customization mechanism. This provides a stored cross site scripting attack vector to authorized users of the system.… | ||
| CVE-2022-24869 | Med | 0.00 | 4.6 | 0.01 | Apr 21, 2022 | GLPI is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. In versions prior to 10.0.0 one can use ticket's followups or setup login messages with a stylesheet link. This may allow for a cross site… | ||
| CVE-2022-24868 | Hig | 0.00 | 7.3 | 0.01 | Apr 21, 2022 | GLPI is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. In versions prior to 10.0.0 one can exploit a lack of sanitization on SVG file uploads and inject javascript into their user avatar. As a… |
- risk 0.00cvss 5.4epss 0.01
bbs-go <= 3.3.0 including Custom Edition is vulnerable to stored XSS.
- risk 0.00cvss 5.4epss 0.01
Cross-site Scripting (XSS) - Stored in GitHub repository causefx/organizr prior to 2.1.2200.
- risk 0.00cvss 6.1epss 0.01
A cross-site scripting (XSS) vulnerability in uploadConfirm.php of LimeSurvey v5.3.9 and below allows attackers to execute arbitrary web scripts or HTML via a crafted plugin.
- risk 0.00cvss 5.4epss 0.01
Cross-site Scripting (XSS) - Reflected in GitHub repository collectiveaccess/providence prior to 1.8.
- risk 0.00cvss 4.3epss 0.01
GoCD is a continuous delivery server. GoCD versions 20.2.0 until 21.4.0 are vulnerable to reflected cross-site scripting via abuse of the pipeline comparison function's error handling to render arbitrary HTML into the returned page. This could allow an attacker to trick a victim…
- risk 0.00cvss 4.3epss 0.01
GoCD is a continuous delivery server. GoCD versions 19.11.0 through 21.4.0 (inclusive) are vulnerable to a Document Object Model (DOM)-based cross-site scripting attack via a pipeline run's Stage Details > Graphs tab. It is possible for a malicious script on a attacker-hosted…
- risk 0.00cvss 6.1epss 0.01
Cross-site Scripting (XSS) - Reflected in GitHub repository rtxteam/rtx prior to checkpoint_2022-05-18.
- risk 0.00cvss 4.6epss 0.01
Cross-site Scripting (XSS) - Stored in GitHub repository jgraph/drawio prior to 18.0.4.
- risk 0.00cvss 5.4epss 0.01
ToolJet versions v0.6.0 to v1.10.2 are vulnerable to HTML injection where an attacker can inject malicious code inside the first name and last name field while inviting a new user which will be reflected in the invitational e-mail.
- risk 0.00cvss 5.4epss 0.01
Jenkins JDK Parameter Plugin 1.0 and earlier does not escape the name and description of JDK parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.
- risk 0.00cvss 6.1epss 0.01
Cross-site scripting (XSS) vulnerability exists in Coder Code-Server before 3.12.0, allows attackers to execute arbitrary code via crafted URL.
- risk 0.00cvss 5.4epss 0.00
FUDforum 3.1.1 is vulnerable to Stored XSS.
- risk 0.00cvss 9.6epss 0.02
Arbitrary Code Execution through Sanitizer Bypass in GitHub repository jgraph/drawio prior to 18.0.0. - Arbitrary (remote) code execution in the desktop app. - Stored XSS in the web app.
- risk 0.00cvss 5.4epss 0.01
In Vendure versions 0.1.0-alpha.2 to 1.5.1 are affected by Stored XSS vulnerability, where an attacker having catalog permission can upload a SVG file that contains malicious JavaScript into the “Assets” tab. The uploaded file will affect administrators as well as regular…
- risk 0.00cvss 4.8epss 0.01
A Stored Cross Site Scripting (XSS) vulnerability exists in Shopizer versions 2.0 through 2.17.0, where a privileged user (attacker) can inject malicious JavaScript in the filename under the “Manage files” tab
- risk 0.00cvss 5.4epss 0.01
Stored XSS Leads To Session Hijacking in GitHub repository openemr/openemr prior to 6.1.0.1.
- risk 0.00cvss 6.1epss 0.01
Crypt Server before 3.3.0 allows XSS in the index view. This is related to serial, computername, and username.
- risk 0.00cvss 8.7epss 0.01
Combodo iTop is a web based IT Service Management tool. In 3.0.0 beta releases prior to 3.0.0 beta3 a malicious script can be injected in tooltips using iTop customization mechanism. This provides a stored cross site scripting attack vector to authorized users of the system.…
- risk 0.00cvss 4.6epss 0.01
GLPI is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. In versions prior to 10.0.0 one can use ticket's followups or setup login messages with a stylesheet link. This may allow for a cross site…
- risk 0.00cvss 7.3epss 0.01
GLPI is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. In versions prior to 10.0.0 one can exploit a lack of sanitization on SVG file uploads and inject javascript into their user avatar. As a…