VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (46,610)

page 2080 of 2,331
  • CVE-2021-43725MedMar 28, 2022
    risk 0.00cvss 6.1epss 0.03

    There is a Cross Site Scripting (XSS) vulnerability in SpotPage_login.php of Spotweb 1.5.1 and below, which allows remote attackers to inject arbitrary web script or HTML via the data[performredirect] parameter.

  • CVE-2022-27920MedMar 25, 2022
    risk 0.00cvss 6.1epss 0.01

    libkiwix 10.0.0 and 10.0.1 allows XSS in the built-in webserver functionality via the search suggestions URL parameter. This is fixed in 10.1.0.

  • CVE-2022-26573MedMar 25, 2022
    risk 0.00cvss 6.1epss 0.01

    Maccms v10 was discovered to contain multiple reflected cross-site scripting (XSS) vulnerabilities in /admin.php/admin/art/data.html via the select and input parameters.

  • CVE-2021-46426MedMar 25, 2022
    risk 0.00cvss 6.1epss 0.01

    phpIPAM 1.4.4 allows Reflected XSS and CSRF via app/admin/subnets/find_free_section_subnets.php of the subnets functionality.

  • CVE-2021-23648MedMar 16, 2022
    risk 0.00cvss 5.4epss 0.01

    The package @braintree/sanitize-url before 6.0.0 are vulnerable to Cross-site Scripting (XSS) due to improper sanitization in sanitizeUrl function.

  • CVE-2022-0986MedMar 16, 2022
    risk 0.00cvss 6.1epss 0.01

    Reflected Cross-site Scripting (XSS) Vulnerability in GitHub repository hestiacp/hestiacp prior to 1.5.11.

  • CVE-2022-27212MedMar 15, 2022
    risk 0.00cvss 5.4epss 0.01

    Jenkins List Git Branches Parameter Plugin 0.0.9 and earlier does not escape the name of the 'List Git branches (and more)' parameter, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.

  • CVE-2022-26874MedMar 11, 2022
    risk 0.00cvss 5.4epss 0.01

    lib/Horde/Mime/Viewer/Ooo.php in Horde Mime_Viewer before 2.2.4 allows XSS via an OpenOffice document, leading to account takeover in Horde Groupware Webmail Edition. This occurs after XSLT rendering.

  • CVE-2022-0822MedMar 11, 2022
    risk 0.00cvss 5.4epss 0.01

    Cross-site Scripting (XSS) - Reflected in GitHub repository orchardcms/orchardcore prior to 1.3.0.

  • CVE-2022-0820MedMar 11, 2022
    risk 0.00cvss 6.1epss 0.01

    Cross-site Scripting (XSS) - Stored in GitHub repository orchardcms/orchardcore prior to 1.3.0.

  • CVE-2022-25069CriMar 5, 2022
    risk 0.00cvss 9.6epss 0.02

    Mark Text v0.16.3 was discovered to contain a DOM-based cross-site scripting (XSS) vulnerability which allows attackers to perform remote code execution (RCE) via injecting a crafted payload into /lib/contentState/pasteCtrl.js.

  • CVE-2022-0752MedMar 4, 2022
    risk 0.00cvss 6.1epss 0.01

    Cross-site Scripting (XSS) - Generic in GitHub repository hestiacp/hestiacp prior to 1.5.9.

  • CVE-2022-0838MedMar 4, 2022
    risk 0.00cvss 6.1epss 0.01

    Cross-site Scripting (XSS) - Reflected in GitHub repository hestiacp/hestiacp prior to 1.5.10.

  • CVE-2022-0753MedMar 3, 2022
    risk 0.00cvss 6.1epss 0.01

    Cross-site Scripting (XSS) - Reflected in GitHub repository hestiacp/hestiacp prior to 1.5.9.

  • CVE-2022-23656MedMar 2, 2022
    risk 0.00cvss 4.6epss 0.01

    Zulip is an open source team chat app. The `main` development branch of Zulip Server from June 2021 and later is vulnerable to a cross-site scripting vulnerability on the recent topics page. An attacker could maliciously craft a full name for their account and send messages to a…

  • CVE-2021-44662MedFeb 24, 2022
    risk 0.00cvss 6.1epss 0.01

    A Site Scripting (XSS) vulnerability exists in the Xerte Project Xerte through 3.8.4 via the link parameter in print.php.

  • CVE-2022-24708MedFeb 24, 2022
    risk 0.00cvss 6.5epss 0.01

    Anuko Time Tracker is an open source, web-based time tracking application written in PHP. ttUser.class.php in Time Tracker versions prior to 1.20.0.5646 was not escaping primary group name for display. Because of that, it was possible for a logged in user to modify primary group…

  • CVE-2021-44566MedFeb 24, 2022
    risk 0.00cvss 5.4epss 0.01

    A Cross Site Scripting (XSS) vulnerability exists in RosarioSIS before 4.3 via the SanitizeMarkDown function in ProgramFunctions/MarkDownHTML.fnc.php.

  • CVE-2021-44565MedFeb 24, 2022
    risk 0.00cvss 5.4epss 0.01

    A Cross Site Scripting (XSS) vulnerability exists in RosarioSIS before 7.6.1 via the xss_clean function in classes/Security.php, which allows remote malicious users to inject arbitrary JavaScript or HTML. An example of affected components are all Markdown input fields.

  • CVE-2022-23054MedFeb 20, 2022
    risk 0.00cvss 6.1epss 0.01

    Openmct versions 1.3.0 to 1.7.7 are vulnerable against stored XSS via the “Summary Widget” element, that allows the injection of malicious JavaScript into the ‘URL’ field. This issue affects: nasa openmct 1.7.7 version and prior versions; 1.3.0 version and later versions.