VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (46,610)

page 2081 of 2,331
  • CVE-2022-23053MedFeb 20, 2022
    risk 0.00cvss 6.1epss 0.01

    Openmct versions 1.3.0 to 1.7.7 are vulnerable against stored XSS via the “Condition Widget” element, that allows the injection of malicious JavaScript into the ‘URL’ field. This issue affects: nasa openmct 1.7.7 version and prior versions; 1.3.0 version and later…

  • CVE-2022-22126MedFeb 20, 2022
    risk 0.00cvss 6.1epss 0.01

    Openmct versions 1.3.0 to 1.7.7 are vulnerable against stored XSS via the “Web Page” element, that allows the injection of malicious JavaScript into the ‘URL’ field. This issue affects: nasa openmct 1.7.7 version and prior versions; 1.3.0 version and later versions.

  • CVE-2022-25321MedFeb 18, 2022
    risk 0.00cvss 6.1epss 0.01

    An issue was discovered in Cerebrate through 1.4. XSS could occur in the bookmarks component.

  • CVE-2022-25317MedFeb 18, 2022
    risk 0.00cvss 6.1epss 0.01

    An issue was discovered in Cerebrate through 1.4. genericForm allows reflected XSS in form descriptions via a user-controlled description.

  • CVE-2021-46251MedFeb 15, 2022
    risk 0.00cvss 6.1epss 0.01

    A reflected cross-site scripting (XSS) in ScratchOAuth2 before commit 1603f04e44ef67dde6ccffe866d2dca16defb293 allows attackers to execute arbitrary web scripts or HTML via a crafted POST request.

  • CVE-2022-23637MedFeb 14, 2022
    risk 0.00cvss 6.1epss 0.00

    K-Box is a web-based application to manage documents, images, videos and geodata. Prior to version 0.33.1, a stored Cross-Site-Scripting (XSS) vulnerability is present in the markdown editor used by the document abstract and markdown file preview. A specifically crafted anchor…

  • CVE-2022-0571MedFeb 14, 2022
    risk 0.00cvss 6.1epss 0.01

    Cross-site Scripting (XSS) - Reflected in GitHub repository phoronix-test-suite/phoronix-test-suite prior to 10.8.2.

  • CVE-2022-0527MedFeb 9, 2022
    risk 0.00cvss 6.1epss 0.01

    Cross-site Scripting (XSS) - Stored in GitHub repository chatwoot/chatwoot prior to 2.2.0.

  • CVE-2022-0526MedFeb 9, 2022
    risk 0.00cvss 6.1epss 0.01

    Cross-site Scripting (XSS) - Stored in GitHub repository chatwoot/chatwoot prior to 2.2.0.

  • CVE-2021-45329MedFeb 8, 2022
    risk 0.00cvss 6.1epss 0.01

    Cross Site Scripting (XSS) vulnerability exists in Gitea before 1.5.1 via the repository settings inside the external wiki/issue tracker URL field.

  • CVE-2022-24123CriJan 29, 2022
    risk 0.00cvss 9.0epss 0.02

    MarkText through 0.16.3 does not sanitize the input of a mermaid block before rendering. This could lead to Remote Code Execution via a .md file containing a mutation Cross-Site Scripting (XSS) payload.

  • CVE-2022-21719MedJan 28, 2022
    risk 0.00cvss 6.1epss 0.01

    GLPI is a free asset and IT management software package. All GLPI versions prior to 9.5.7 are vulnerable to reflected cross-site scripting. Version 9.5.7 contains a patch for this issue. There are no known workarounds.

  • CVE-2022-23993MedJan 26, 2022
    risk 0.00cvss 6.1epss 0.02

    /usr/local/www/pkg.php in pfSense CE before 2.6.0 and pfSense Plus before 22.01 uses $_REQUEST['pkg_filter'] in a PHP echo call, causing XSS.

  • CVE-2022-22851MedJan 26, 2022
    risk 0.00cvss 5.4epss 0.01

    A Stored Cross Site Scripting (XSS) vulnerability exists in Sourcecodtester Hospital's Patient Records Management System 1.0 via the specialization parameter in doctors.php

  • CVE-2022-21710MedJan 24, 2022
    risk 0.00cvss 4.7epss 0.01

    ShortDescription is a MediaWiki extension that provides local short description support. A cross-site scripting (XSS) vulnerability exists in versions prior to 2.3.4. On a wiki that has the ShortDescription enabled, XSS can be triggered on any page or the page with the…

  • CVE-2021-3866MedJan 20, 2022
    risk 0.00cvss 5.4epss 0.01

    Cross-site Scripting (XSS) - Stored in GitHub repository zulip/zulip more than and including 44f935695d452cc3fb16845a0c6af710438b153d and prior to 3eb2791c3e9695f7d37ffe84e0c2184fae665cb6.

  • CVE-2021-4143MedJan 19, 2022
    risk 0.00cvss 6.1epss 0.01

    Cross-site Scripting (XSS) - Generic in GitHub repository bigbluebutton/bigbluebutton prior to 2.4.0.

  • CVE-2022-0243MedJan 19, 2022
    risk 0.00cvss 5.4epss 0.01

    Cross-site Scripting (XSS) - Stored in NuGet OrchardCore.Application.Cms.Targets prior to 1.2.2.

  • CVE-2021-3857MedJan 17, 2022
    risk 0.00cvss 5.4epss 0.01

    chaskiq is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

  • CVE-2021-3853MedJan 17, 2022
    risk 0.00cvss 6.1epss 0.01

    chaskiq is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')