CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Description
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85
CVEs mapped to this weakness (46,610)
page 2081 of 2,331| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-23053 | Med | 0.00 | 6.1 | 0.01 | Feb 20, 2022 | Openmct versions 1.3.0 to 1.7.7 are vulnerable against stored XSS via the “Condition Widget” element, that allows the injection of malicious JavaScript into the ‘URL’ field. This issue affects: nasa openmct 1.7.7 version and prior versions; 1.3.0 version and later… | ||
| CVE-2022-22126 | Med | 0.00 | 6.1 | 0.01 | Feb 20, 2022 | Openmct versions 1.3.0 to 1.7.7 are vulnerable against stored XSS via the “Web Page” element, that allows the injection of malicious JavaScript into the ‘URL’ field. This issue affects: nasa openmct 1.7.7 version and prior versions; 1.3.0 version and later versions. | ||
| CVE-2022-25321 | Med | 0.00 | 6.1 | 0.01 | Feb 18, 2022 | An issue was discovered in Cerebrate through 1.4. XSS could occur in the bookmarks component. | ||
| CVE-2022-25317 | Med | 0.00 | 6.1 | 0.01 | Feb 18, 2022 | An issue was discovered in Cerebrate through 1.4. genericForm allows reflected XSS in form descriptions via a user-controlled description. | ||
| CVE-2021-46251 | Med | 0.00 | 6.1 | 0.01 | Feb 15, 2022 | A reflected cross-site scripting (XSS) in ScratchOAuth2 before commit 1603f04e44ef67dde6ccffe866d2dca16defb293 allows attackers to execute arbitrary web scripts or HTML via a crafted POST request. | ||
| CVE-2022-23637 | Med | 0.00 | 6.1 | 0.00 | Feb 14, 2022 | K-Box is a web-based application to manage documents, images, videos and geodata. Prior to version 0.33.1, a stored Cross-Site-Scripting (XSS) vulnerability is present in the markdown editor used by the document abstract and markdown file preview. A specifically crafted anchor… | ||
| CVE-2022-0571 | Med | 0.00 | 6.1 | 0.01 | Feb 14, 2022 | Cross-site Scripting (XSS) - Reflected in GitHub repository phoronix-test-suite/phoronix-test-suite prior to 10.8.2. | ||
| CVE-2022-0527 | Med | 0.00 | 6.1 | 0.01 | Feb 9, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository chatwoot/chatwoot prior to 2.2.0. | ||
| CVE-2022-0526 | Med | 0.00 | 6.1 | 0.01 | Feb 9, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository chatwoot/chatwoot prior to 2.2.0. | ||
| CVE-2021-45329 | Med | 0.00 | 6.1 | 0.01 | Feb 8, 2022 | Cross Site Scripting (XSS) vulnerability exists in Gitea before 1.5.1 via the repository settings inside the external wiki/issue tracker URL field. | ||
| CVE-2022-24123 | Cri | 0.00 | 9.0 | 0.02 | Jan 29, 2022 | MarkText through 0.16.3 does not sanitize the input of a mermaid block before rendering. This could lead to Remote Code Execution via a .md file containing a mutation Cross-Site Scripting (XSS) payload. | ||
| CVE-2022-21719 | Med | 0.00 | 6.1 | 0.01 | Jan 28, 2022 | GLPI is a free asset and IT management software package. All GLPI versions prior to 9.5.7 are vulnerable to reflected cross-site scripting. Version 9.5.7 contains a patch for this issue. There are no known workarounds. | ||
| CVE-2022-23993 | Med | 0.00 | 6.1 | 0.02 | Jan 26, 2022 | /usr/local/www/pkg.php in pfSense CE before 2.6.0 and pfSense Plus before 22.01 uses $_REQUEST['pkg_filter'] in a PHP echo call, causing XSS. | ||
| CVE-2022-22851 | Med | 0.00 | 5.4 | 0.01 | Jan 26, 2022 | A Stored Cross Site Scripting (XSS) vulnerability exists in Sourcecodtester Hospital's Patient Records Management System 1.0 via the specialization parameter in doctors.php | ||
| CVE-2022-21710 | Med | 0.00 | 4.7 | 0.01 | Jan 24, 2022 | ShortDescription is a MediaWiki extension that provides local short description support. A cross-site scripting (XSS) vulnerability exists in versions prior to 2.3.4. On a wiki that has the ShortDescription enabled, XSS can be triggered on any page or the page with the… | ||
| CVE-2021-3866 | Med | 0.00 | 5.4 | 0.01 | Jan 20, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository zulip/zulip more than and including 44f935695d452cc3fb16845a0c6af710438b153d and prior to 3eb2791c3e9695f7d37ffe84e0c2184fae665cb6. | ||
| CVE-2021-4143 | Med | 0.00 | 6.1 | 0.01 | Jan 19, 2022 | Cross-site Scripting (XSS) - Generic in GitHub repository bigbluebutton/bigbluebutton prior to 2.4.0. | ||
| CVE-2022-0243 | Med | 0.00 | 5.4 | 0.01 | Jan 19, 2022 | Cross-site Scripting (XSS) - Stored in NuGet OrchardCore.Application.Cms.Targets prior to 1.2.2. | ||
| CVE-2021-3857 | Med | 0.00 | 5.4 | 0.01 | Jan 17, 2022 | chaskiq is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | ||
| CVE-2021-3853 | Med | 0.00 | 6.1 | 0.01 | Jan 17, 2022 | chaskiq is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
- risk 0.00cvss 6.1epss 0.01
Openmct versions 1.3.0 to 1.7.7 are vulnerable against stored XSS via the “Condition Widget” element, that allows the injection of malicious JavaScript into the ‘URL’ field. This issue affects: nasa openmct 1.7.7 version and prior versions; 1.3.0 version and later…
- risk 0.00cvss 6.1epss 0.01
Openmct versions 1.3.0 to 1.7.7 are vulnerable against stored XSS via the “Web Page” element, that allows the injection of malicious JavaScript into the ‘URL’ field. This issue affects: nasa openmct 1.7.7 version and prior versions; 1.3.0 version and later versions.
- risk 0.00cvss 6.1epss 0.01
An issue was discovered in Cerebrate through 1.4. XSS could occur in the bookmarks component.
- risk 0.00cvss 6.1epss 0.01
An issue was discovered in Cerebrate through 1.4. genericForm allows reflected XSS in form descriptions via a user-controlled description.
- risk 0.00cvss 6.1epss 0.01
A reflected cross-site scripting (XSS) in ScratchOAuth2 before commit 1603f04e44ef67dde6ccffe866d2dca16defb293 allows attackers to execute arbitrary web scripts or HTML via a crafted POST request.
- risk 0.00cvss 6.1epss 0.00
K-Box is a web-based application to manage documents, images, videos and geodata. Prior to version 0.33.1, a stored Cross-Site-Scripting (XSS) vulnerability is present in the markdown editor used by the document abstract and markdown file preview. A specifically crafted anchor…
- risk 0.00cvss 6.1epss 0.01
Cross-site Scripting (XSS) - Reflected in GitHub repository phoronix-test-suite/phoronix-test-suite prior to 10.8.2.
- risk 0.00cvss 6.1epss 0.01
Cross-site Scripting (XSS) - Stored in GitHub repository chatwoot/chatwoot prior to 2.2.0.
- risk 0.00cvss 6.1epss 0.01
Cross-site Scripting (XSS) - Stored in GitHub repository chatwoot/chatwoot prior to 2.2.0.
- risk 0.00cvss 6.1epss 0.01
Cross Site Scripting (XSS) vulnerability exists in Gitea before 1.5.1 via the repository settings inside the external wiki/issue tracker URL field.
- risk 0.00cvss 9.0epss 0.02
MarkText through 0.16.3 does not sanitize the input of a mermaid block before rendering. This could lead to Remote Code Execution via a .md file containing a mutation Cross-Site Scripting (XSS) payload.
- risk 0.00cvss 6.1epss 0.01
GLPI is a free asset and IT management software package. All GLPI versions prior to 9.5.7 are vulnerable to reflected cross-site scripting. Version 9.5.7 contains a patch for this issue. There are no known workarounds.
- risk 0.00cvss 6.1epss 0.02
/usr/local/www/pkg.php in pfSense CE before 2.6.0 and pfSense Plus before 22.01 uses $_REQUEST['pkg_filter'] in a PHP echo call, causing XSS.
- risk 0.00cvss 5.4epss 0.01
A Stored Cross Site Scripting (XSS) vulnerability exists in Sourcecodtester Hospital's Patient Records Management System 1.0 via the specialization parameter in doctors.php
- risk 0.00cvss 4.7epss 0.01
ShortDescription is a MediaWiki extension that provides local short description support. A cross-site scripting (XSS) vulnerability exists in versions prior to 2.3.4. On a wiki that has the ShortDescription enabled, XSS can be triggered on any page or the page with the…
- risk 0.00cvss 5.4epss 0.01
Cross-site Scripting (XSS) - Stored in GitHub repository zulip/zulip more than and including 44f935695d452cc3fb16845a0c6af710438b153d and prior to 3eb2791c3e9695f7d37ffe84e0c2184fae665cb6.
- risk 0.00cvss 6.1epss 0.01
Cross-site Scripting (XSS) - Generic in GitHub repository bigbluebutton/bigbluebutton prior to 2.4.0.
- risk 0.00cvss 5.4epss 0.01
Cross-site Scripting (XSS) - Stored in NuGet OrchardCore.Application.Cms.Targets prior to 1.2.2.
- risk 0.00cvss 5.4epss 0.01
chaskiq is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- risk 0.00cvss 6.1epss 0.01
chaskiq is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')