CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Description
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85
CVEs mapped to this weakness (46,610)
page 2079 of 2,331| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-41162 | Cri | 0.00 | 9.3 | 0.01 | Apr 21, 2022 | Combodo iTop is a web based IT Service Management tool. In 3.0.0 beta releases prior to beta6 the `ajax.render.php?operation=wizard_helper` page did not properly escape the user supplied parameters, allowing for a cross site scripting attack vector. Users are advised to upgrade.… | ||
| CVE-2021-41161 | Cri | 0.00 | 9.3 | 0.01 | Apr 21, 2022 | Combodo iTop is a web based IT Service Management tool. In versions prior to 3.0.0-beta6 the export CSV page don't properly escape the user supplied parameters, allowing for javascript injection into rendered csv files. Users are advised to upgrade. There are no known… | ||
| CVE-2022-1022 | Med | 0.00 | 5.4 | 0.04 | Apr 21, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository chatwoot/chatwoot prior to 2.5.0. | ||
| CVE-2022-24864 | Med | 0.00 | 4.1 | 0.01 | Apr 20, 2022 | Origin Protocol is a blockchain based project. The Origin Protocol project website allows for malicious users to inject malicious Javascript via a POST request to `/presale/join`. User-controlled data is passed with no sanitization to SendGrid and injected into an email that is… | ||
| CVE-2022-24799 | Cri | 0.00 | 9.6 | 0.01 | Apr 20, 2022 | wire-webapp is the web application interface for the wire messaging service. Insufficient escaping in markdown “code highlighting” in the wire-webapp resulted in the possibility of injecting and executing arbitrary HTML code and thus also JavaScript. If a user receives and… | ||
| CVE-2022-24851 | Hig | 0.00 | 8.1 | 0.01 | Apr 15, 2022 | LDAP Account Manager (LAM) is an open source web frontend for managing entries stored in an LDAP directory. The profile editor tool has an edit profile functionality, the parameters on this page are not properly sanitized and hence leads to stored XSS attacks. An authenticated… | ||
| CVE-2022-1231 | Med | 0.00 | 6.1 | 0.02 | Apr 15, 2022 | XSS via Embedded SVG in SVG Diagram Format in GitHub repository plantuml/plantuml prior to 1.2022.4. Stored XSS in the context of the diagram embedder. Depending on the actual context, this ranges from stealing secrets to account hijacking or even to code execution for example… | ||
| CVE-2021-43288 | Med | 0.00 | 5.4 | 0.01 | Apr 14, 2022 | An issue was discovered in ThoughtWorks GoCD before 21.3.0. An attacker in control of a GoCD Agent can plant malicious JavaScript into a failed Job Report. | ||
| CVE-2022-1347 | Hig | 0.00 | 8.4 | 0.01 | Apr 13, 2022 | Stored XSS in the "Username" & "Email" input fields leads to account takeover of Admin & Co-admin users in GitHub repository causefx/organizr prior to 2.1.1810. Account takeover and privilege escalation | ||
| CVE-2022-1346 | Cri | 0.00 | 9.0 | 0.01 | Apr 13, 2022 | Multiple Stored XSS in GitHub repository causefx/organizr prior to 2.1.1810. This allows attackers to execute malicious scripts in the user's browser and it can lead to session hijacking, sensitive data exposure, and worse. | ||
| CVE-2022-1344 | Cri | 0.00 | 9.0 | 0.01 | Apr 13, 2022 | Stored XSS due to no sanitization in the filename in GitHub repository causefx/organizr prior to 2.1.1810. This allows attackers to execute malicious scripts in the user's browser and it can lead to session hijacking, sensitive data exposure, and worse. | ||
| CVE-2022-27475 | Med | 0.00 | 6.1 | 0.01 | Apr 13, 2022 | Cross site scripting (XSS) vulnerability in tramyardg hotel-mgmt-system, allows attackers to execute arbitrary code when when /admin.php is loaded. | ||
| CVE-2022-0936 | Med | 0.00 | 5.4 | 0.01 | Apr 11, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository autolab/autolab prior to 2.8.0. | ||
| CVE-2022-1290 | Med | 0.00 | 5.4 | 0.02 | Apr 10, 2022 | Stored XSS in "Name", "Group Name" & "Title" in GitHub repository polonel/trudesk prior to v1.2.0. This allows attackers to execute malicious scripts in the user's browser and it can lead to session hijacking, sensitive data exposure, and worse. | ||
| CVE-2022-1234 | Med | 0.00 | 6.1 | 0.01 | Apr 6, 2022 | XSS in livehelperchat in GitHub repository livehelperchat/livehelperchat prior to 3.97. This vulnerability has the potential to deface websites, result in compromised user accounts, and can run malicious code on web pages, which can lead to a compromise of the user’s device. | ||
| CVE-2022-24811 | Med | 0.00 | 5.4 | 0.01 | Apr 5, 2022 | Combodi iTop is a web based IT Service Management tool. Prior to versions 2.7.6 and 3.0.0, cross-site scripting is possible for scripts outside of script tags when displaying HTML attachments. This issue is fixed in versions 2.7.6 and 3.0.0. There are currently no known… | ||
| CVE-2022-27462 | Med | 0.00 | 6.1 | 0.01 | Apr 5, 2022 | Cross Site Scripting (XSS) vulnerability in objects/function.php in function getDeviceID in WWBN AVideo through 11.6, via the yptDevice parameter to view/include/head.php. | ||
| CVE-2022-24814 | Hig | 0.00 | 8.8 | 0.01 | Apr 4, 2022 | Directus is a real-time API and App dashboard for managing SQL database content. Prior to version 9.7.0, unauthorized JavaScript (JS) can be executed by inserting an iframe into the rich text html interface that links to a file uploaded HTML file that loads another uploaded JS… | ||
| CVE-2022-21830 | Med | 0.00 | 6.1 | 0.01 | Apr 1, 2022 | A blind self XSS vulnerability exists in RocketChat LiveChat <v1.9 that could allow an attacker to trick a victim pasting malicious code in their chat instance. | ||
| CVE-2022-1180 | Low | 0.00 | 3.5 | 0.01 | Mar 30, 2022 | Reflected Cross Site Scripting in GitHub repository openemr/openemr prior to 6.0.0.4. |
- risk 0.00cvss 9.3epss 0.01
Combodo iTop is a web based IT Service Management tool. In 3.0.0 beta releases prior to beta6 the `ajax.render.php?operation=wizard_helper` page did not properly escape the user supplied parameters, allowing for a cross site scripting attack vector. Users are advised to upgrade.…
- risk 0.00cvss 9.3epss 0.01
Combodo iTop is a web based IT Service Management tool. In versions prior to 3.0.0-beta6 the export CSV page don't properly escape the user supplied parameters, allowing for javascript injection into rendered csv files. Users are advised to upgrade. There are no known…
- risk 0.00cvss 5.4epss 0.04
Cross-site Scripting (XSS) - Stored in GitHub repository chatwoot/chatwoot prior to 2.5.0.
- risk 0.00cvss 4.1epss 0.01
Origin Protocol is a blockchain based project. The Origin Protocol project website allows for malicious users to inject malicious Javascript via a POST request to `/presale/join`. User-controlled data is passed with no sanitization to SendGrid and injected into an email that is…
- risk 0.00cvss 9.6epss 0.01
wire-webapp is the web application interface for the wire messaging service. Insufficient escaping in markdown “code highlighting” in the wire-webapp resulted in the possibility of injecting and executing arbitrary HTML code and thus also JavaScript. If a user receives and…
- risk 0.00cvss 8.1epss 0.01
LDAP Account Manager (LAM) is an open source web frontend for managing entries stored in an LDAP directory. The profile editor tool has an edit profile functionality, the parameters on this page are not properly sanitized and hence leads to stored XSS attacks. An authenticated…
- risk 0.00cvss 6.1epss 0.02
XSS via Embedded SVG in SVG Diagram Format in GitHub repository plantuml/plantuml prior to 1.2022.4. Stored XSS in the context of the diagram embedder. Depending on the actual context, this ranges from stealing secrets to account hijacking or even to code execution for example…
- risk 0.00cvss 5.4epss 0.01
An issue was discovered in ThoughtWorks GoCD before 21.3.0. An attacker in control of a GoCD Agent can plant malicious JavaScript into a failed Job Report.
- risk 0.00cvss 8.4epss 0.01
Stored XSS in the "Username" & "Email" input fields leads to account takeover of Admin & Co-admin users in GitHub repository causefx/organizr prior to 2.1.1810. Account takeover and privilege escalation
- risk 0.00cvss 9.0epss 0.01
Multiple Stored XSS in GitHub repository causefx/organizr prior to 2.1.1810. This allows attackers to execute malicious scripts in the user's browser and it can lead to session hijacking, sensitive data exposure, and worse.
- risk 0.00cvss 9.0epss 0.01
Stored XSS due to no sanitization in the filename in GitHub repository causefx/organizr prior to 2.1.1810. This allows attackers to execute malicious scripts in the user's browser and it can lead to session hijacking, sensitive data exposure, and worse.
- risk 0.00cvss 6.1epss 0.01
Cross site scripting (XSS) vulnerability in tramyardg hotel-mgmt-system, allows attackers to execute arbitrary code when when /admin.php is loaded.
- risk 0.00cvss 5.4epss 0.01
Cross-site Scripting (XSS) - Stored in GitHub repository autolab/autolab prior to 2.8.0.
- risk 0.00cvss 5.4epss 0.02
Stored XSS in "Name", "Group Name" & "Title" in GitHub repository polonel/trudesk prior to v1.2.0. This allows attackers to execute malicious scripts in the user's browser and it can lead to session hijacking, sensitive data exposure, and worse.
- risk 0.00cvss 6.1epss 0.01
XSS in livehelperchat in GitHub repository livehelperchat/livehelperchat prior to 3.97. This vulnerability has the potential to deface websites, result in compromised user accounts, and can run malicious code on web pages, which can lead to a compromise of the user’s device.
- risk 0.00cvss 5.4epss 0.01
Combodi iTop is a web based IT Service Management tool. Prior to versions 2.7.6 and 3.0.0, cross-site scripting is possible for scripts outside of script tags when displaying HTML attachments. This issue is fixed in versions 2.7.6 and 3.0.0. There are currently no known…
- risk 0.00cvss 6.1epss 0.01
Cross Site Scripting (XSS) vulnerability in objects/function.php in function getDeviceID in WWBN AVideo through 11.6, via the yptDevice parameter to view/include/head.php.
- risk 0.00cvss 8.8epss 0.01
Directus is a real-time API and App dashboard for managing SQL database content. Prior to version 9.7.0, unauthorized JavaScript (JS) can be executed by inserting an iframe into the rich text html interface that links to a file uploaded HTML file that loads another uploaded JS…
- risk 0.00cvss 6.1epss 0.01
A blind self XSS vulnerability exists in RocketChat LiveChat <v1.9 that could allow an attacker to trick a victim pasting malicious code in their chat instance.
- risk 0.00cvss 3.5epss 0.01
Reflected Cross Site Scripting in GitHub repository openemr/openemr prior to 6.0.0.4.