VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (46,610)

page 2079 of 2,331
  • CVE-2021-41162CriApr 21, 2022
    risk 0.00cvss 9.3epss 0.01

    Combodo iTop is a web based IT Service Management tool. In 3.0.0 beta releases prior to beta6 the `ajax.render.php?operation=wizard_helper` page did not properly escape the user supplied parameters, allowing for a cross site scripting attack vector. Users are advised to upgrade.…

  • CVE-2021-41161CriApr 21, 2022
    risk 0.00cvss 9.3epss 0.01

    Combodo iTop is a web based IT Service Management tool. In versions prior to 3.0.0-beta6 the export CSV page don't properly escape the user supplied parameters, allowing for javascript injection into rendered csv files. Users are advised to upgrade. There are no known…

  • CVE-2022-1022MedApr 21, 2022
    risk 0.00cvss 5.4epss 0.04

    Cross-site Scripting (XSS) - Stored in GitHub repository chatwoot/chatwoot prior to 2.5.0.

  • CVE-2022-24864MedApr 20, 2022
    risk 0.00cvss 4.1epss 0.01

    Origin Protocol is a blockchain based project. The Origin Protocol project website allows for malicious users to inject malicious Javascript via a POST request to `/presale/join`. User-controlled data is passed with no sanitization to SendGrid and injected into an email that is…

  • CVE-2022-24799CriApr 20, 2022
    risk 0.00cvss 9.6epss 0.01

    wire-webapp is the web application interface for the wire messaging service. Insufficient escaping in markdown “code highlighting” in the wire-webapp resulted in the possibility of injecting and executing arbitrary HTML code and thus also JavaScript. If a user receives and…

  • CVE-2022-24851HigApr 15, 2022
    risk 0.00cvss 8.1epss 0.01

    LDAP Account Manager (LAM) is an open source web frontend for managing entries stored in an LDAP directory. The profile editor tool has an edit profile functionality, the parameters on this page are not properly sanitized and hence leads to stored XSS attacks. An authenticated…

  • CVE-2022-1231MedApr 15, 2022
    risk 0.00cvss 6.1epss 0.02

    XSS via Embedded SVG in SVG Diagram Format in GitHub repository plantuml/plantuml prior to 1.2022.4. Stored XSS in the context of the diagram embedder. Depending on the actual context, this ranges from stealing secrets to account hijacking or even to code execution for example…

  • CVE-2021-43288MedApr 14, 2022
    risk 0.00cvss 5.4epss 0.01

    An issue was discovered in ThoughtWorks GoCD before 21.3.0. An attacker in control of a GoCD Agent can plant malicious JavaScript into a failed Job Report.

  • CVE-2022-1347HigApr 13, 2022
    risk 0.00cvss 8.4epss 0.01

    Stored XSS in the "Username" & "Email" input fields leads to account takeover of Admin & Co-admin users in GitHub repository causefx/organizr prior to 2.1.1810. Account takeover and privilege escalation

  • CVE-2022-1346CriApr 13, 2022
    risk 0.00cvss 9.0epss 0.01

    Multiple Stored XSS in GitHub repository causefx/organizr prior to 2.1.1810. This allows attackers to execute malicious scripts in the user's browser and it can lead to session hijacking, sensitive data exposure, and worse.

  • CVE-2022-1344CriApr 13, 2022
    risk 0.00cvss 9.0epss 0.01

    Stored XSS due to no sanitization in the filename in GitHub repository causefx/organizr prior to 2.1.1810. This allows attackers to execute malicious scripts in the user's browser and it can lead to session hijacking, sensitive data exposure, and worse.

  • CVE-2022-27475MedApr 13, 2022
    risk 0.00cvss 6.1epss 0.01

    Cross site scripting (XSS) vulnerability in tramyardg hotel-mgmt-system, allows attackers to execute arbitrary code when when /admin.php is loaded.

  • CVE-2022-0936MedApr 11, 2022
    risk 0.00cvss 5.4epss 0.01

    Cross-site Scripting (XSS) - Stored in GitHub repository autolab/autolab prior to 2.8.0.

  • CVE-2022-1290MedApr 10, 2022
    risk 0.00cvss 5.4epss 0.02

    Stored XSS in "Name", "Group Name" & "Title" in GitHub repository polonel/trudesk prior to v1.2.0. This allows attackers to execute malicious scripts in the user's browser and it can lead to session hijacking, sensitive data exposure, and worse.

  • CVE-2022-1234MedApr 6, 2022
    risk 0.00cvss 6.1epss 0.01

    XSS in livehelperchat in GitHub repository livehelperchat/livehelperchat prior to 3.97. This vulnerability has the potential to deface websites, result in compromised user accounts, and can run malicious code on web pages, which can lead to a compromise of the user’s device.

  • CVE-2022-24811MedApr 5, 2022
    risk 0.00cvss 5.4epss 0.01

    Combodi iTop is a web based IT Service Management tool. Prior to versions 2.7.6 and 3.0.0, cross-site scripting is possible for scripts outside of script tags when displaying HTML attachments. This issue is fixed in versions 2.7.6 and 3.0.0. There are currently no known…

  • CVE-2022-27462MedApr 5, 2022
    risk 0.00cvss 6.1epss 0.01

    Cross Site Scripting (XSS) vulnerability in objects/function.php in function getDeviceID in WWBN AVideo through 11.6, via the yptDevice parameter to view/include/head.php.

  • CVE-2022-24814HigApr 4, 2022
    risk 0.00cvss 8.8epss 0.01

    Directus is a real-time API and App dashboard for managing SQL database content. Prior to version 9.7.0, unauthorized JavaScript (JS) can be executed by inserting an iframe into the rich text html interface that links to a file uploaded HTML file that loads another uploaded JS…

  • CVE-2022-21830MedApr 1, 2022
    risk 0.00cvss 6.1epss 0.01

    A blind self XSS vulnerability exists in RocketChat LiveChat <v1.9 that could allow an attacker to trick a victim pasting malicious code in their chat instance.

  • CVE-2022-1180LowMar 30, 2022
    risk 0.00cvss 3.5epss 0.01

    Reflected Cross Site Scripting in GitHub repository openemr/openemr prior to 6.0.0.4.