VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (46,610)

page 2082 of 2,331
  • CVE-2020-28919MedJan 15, 2022
    risk 0.00cvss 5.4epss 0.01

    A stored cross site scripting (XSS) vulnerability in Checkmk 1.6.0x prior to 1.6.0p19 allows an authenticated remote attacker to inject arbitrary JavaScript via a javascript: URL in a view title.

  • CVE-2021-23824MedJan 13, 2022
    risk 0.00cvss 6.5epss 0.01

    This affects the package Crow before 0.3+4. When using attributes without quotes in the template, an attacker can manipulate the input to introduce additional attributes, potentially executing code. This may lead to a Cross-site Scripting (XSS) vulnerability, assuming an…

  • CVE-2022-22117MedJan 10, 2022
    risk 0.00cvss 5.4epss 0.01

    In Directus, versions 9.0.0-alpha.4 through 9.4.1 allow unrestricted file upload of .html files in the media upload functionality, which leads to Cross-Site Scripting vulnerability. A low privileged attacker can upload a crafted HTML file as a profile avatar, and when an admin…

  • CVE-2022-22116MedJan 10, 2022
    risk 0.00cvss 5.4epss 0.01

    In Directus, versions 9.0.0-alpha.4 through 9.4.1 are vulnerable to stored Cross-Site Scripting (XSS) vulnerability via SVG file upload in media upload functionality. A low privileged attacker can inject arbitrary javascript code which will be executed in a victim’s browser…

  • CVE-2022-22115CriJan 10, 2022
    risk 0.00cvss 9.0epss 0.01

    In Teedy, versions v1.5 through v1.9 are vulnerable to Stored Cross-Site Scripting (XSS) in the name of a created Tag. Since the Tag name is not being sanitized properly in the edit tag page, a low privileged attacker can store malicious scripts in the name of the Tag. In the…

  • CVE-2022-22114CriJan 10, 2022
    risk 0.00cvss 9.6epss 0.01

    In Teedy, versions v1.5 through v1.9 are vulnerable to Reflected Cross-Site Scripting (XSS). The “search term" search functionality is not sufficiently sanitized while displaying the results of the search, which can be leveraged to inject arbitrary scripts. These scripts are…

  • CVE-2022-0157MedJan 10, 2022
    risk 0.00cvss 5.4epss 0.01

    phoronix-test-suite is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

  • CVE-2021-44584MedJan 6, 2022
    risk 0.00cvss 6.1epss 0.01

    Cross-site scripting (XSS) vulnerability in index.php in emlog version <= pro-1.0.7 allows remote attackers to inject arbitrary web script or HTML via the s parameter.

  • CVE-2021-46144MedJan 6, 2022
    risk 0.00cvss 6.1epss 0.01

    Roundcube before 1.4.13 and 1.5.x before 1.5.2 allows XSS via an HTML e-mail message with crafted Cascading Style Sheets (CSS) token sequences.

  • CVE-2022-0121HigJan 6, 2022
    risk 0.00cvss 8.0epss 0.01

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in hoppscotch hoppscotch/hoppscotch.This issue affects hoppscotch/hoppscotch before 2.1.1.

  • CVE-2020-23986MedJan 6, 2022
    risk 0.00cvss 6.1epss 0.01

    Github Read Me Stats commit 3c7220e4f7144f6cb068fd433c774f6db47ccb95 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the function renderError.

  • CVE-2022-21650HigJan 4, 2022
    risk 0.00cvss 7.6epss 0.01

    Convos is an open source multi-user chat that runs in a web browser. You can't use SVG extension in Convos' chat window, but you can upload a file with an .html extension. By uploading an SVG file with an html extension the upload filter can be bypassed. This causes Stored XSS.…

  • CVE-2022-21649HigJan 4, 2022
    risk 0.00cvss 7.6epss 0.01

    Convos is an open source multi-user chat that runs in a web browser. Characters starting with "https://" in the chat window create an tag. Stored XSS vulnerability using onfocus and autofocus occurs because escaping exists for "<" or ">" but escaping for double quotes does…

  • CVE-2021-44896MedJan 1, 2022
    risk 0.00cvss 6.1epss 0.01

    DMP Roadmap before 3.0.4 allows XSS.

  • CVE-2021-25993MedDec 29, 2021
    risk 0.00cvss 5.4epss 0.01

    In Requarks wiki.js, versions 2.0.0-beta.147 to 2.5.255 are affected by Stored XSS vulnerability, where a low privileged (editor) user can upload a SVG file that contains malicious JavaScript while uploading assets in the page. That will send the JWT tokens to the attacker’s…

  • CVE-2021-4176MedDec 29, 2021
    risk 0.00cvss 6.1epss 0.01

    livehelperchat is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

  • CVE-2021-4175MedDec 29, 2021
    risk 0.00cvss 5.4epss 0.01

    livehelperchat is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

  • CVE-2021-25990MedDec 29, 2021
    risk 0.00cvss 5.4epss 0.01

    In “ifme”, versions v7.22.0 to v7.31.4 are vulnerable against self-stored XSS in the contacts field as it allows loading XSS payloads fetched via an iframe.

  • CVE-2021-25989MedDec 29, 2021
    risk 0.00cvss 5.4epss 0.01

    In “ifme”, versions 1.0.0 to v7.31.4 are vulnerable against stored XSS vulnerability in the markdown editor. It can be exploited by making a victim a Leader of a group which triggers the payload for them.

  • CVE-2021-25988MedDec 29, 2021
    risk 0.00cvss 5.4epss 0.01

    In “ifme”, versions 1.0.0 to v7.31.4 are vulnerable against stored XSS vulnerability (notifications section) which can be directly triggered by sending an ally request to the admin.