VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (46,610)

page 2083 of 2,331
  • CVE-2021-4179MedDec 28, 2021
    risk 0.00cvss 5.4epss 0.00

    livehelperchat is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

  • CVE-2021-43856HigDec 27, 2021
    risk 0.00cvss 8.2epss 0.01

    Wiki.js is a wiki app built on Node.js. Wiki.js 2.5.263 and earlier is vulnerable to stored cross-site scripting through non-image file uploads for file types that can be viewed directly inline in the browser. By creating a malicious file which can execute inline JS when viewed…

  • CVE-2021-43855HigDec 27, 2021
    risk 0.00cvss 8.2epss 0.01

    Wiki.js is a wiki app built on node.js. Wiki.js 2.5.263 and earlier is vulnerable to stored cross-site scripting through a SVG file upload made via a custom request with a fake MIME type. By creating a crafted SVG file, a malicious Wiki.js user may stage a stored cross-site…

  • CVE-2021-4169MedDec 26, 2021
    risk 0.00cvss 6.1epss 0.01

    livehelperchat is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

  • CVE-2021-43842MedDec 20, 2021
    risk 0.00cvss 5.4epss 0.01

    Wiki.js is a wiki app built on Node.js. Wiki.js versions 2.5.257 and earlier are vulnerable to stored cross-site scripting through a SVG file upload. By creating a crafted SVG file, a malicious Wiki.js user may stage a stored cross-site scripting attack. This allows the attacker…

  • CVE-2021-42584MedDec 17, 2021
    risk 0.00cvss 5.4epss 0.01

    A Stored Cross Site Scripting (XSS) issue exists in Convos-Chat before 6.32.

  • CVE-2021-41261HigDec 16, 2021
    risk 0.00cvss 8.1epss 0.01

    Galette is a membership management web application built for non profit organizations and released under GPLv3. Versions prior to 0.9.6 are subject to stored cross site scripting attacks via the preferences footer. The preference footer can only be altered by a site admin. This…

  • CVE-2021-4124MedDec 16, 2021
    risk 0.00cvss 6.1epss 0.01

    janus-gateway is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

  • CVE-2021-3831MedDec 14, 2021
    risk 0.00cvss 6.1epss 0.02

    gnuboard5 is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

  • CVE-2021-43810HigDec 7, 2021
    risk 0.00cvss 8.8epss 0.05

    Admidio is a free open source user management system for websites of organizations and groups. A cross-site scripting vulnerability is present in Admidio prior to version 4.0.12. The Reflected XSS vulnerability occurs because redirect.php does not properly validate the value of…

  • CVE-2021-35415MedDec 3, 2021
    risk 0.00cvss 4.8epss 0.01

    A stored cross-site scripting (XSS) vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the course "Title" and "Content" fields.

  • CVE-2021-44279MedDec 1, 2021
    risk 0.00cvss 6.1epss 0.01

    Librenms 21.11.0 is affected by a Cross Site Scripting (XSS) vulnerability in includes/html/forms/poller-groups.inc.php.

  • CVE-2021-44277MedDec 1, 2021
    risk 0.00cvss 6.1epss 0.01

    Librenms 21.11.0 is affected by a Cross Site Scripting (XSS) vulnerability in includes/html/common/alert-log.inc.php.

  • CVE-2021-4020MedNov 27, 2021
    risk 0.00cvss 5.4epss 0.01

    janus-gateway is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

  • CVE-2021-3920MedNov 19, 2021
    risk 0.00cvss 5.4epss 0.01

    grav-plugin-admin is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

  • CVE-2021-44025MedNov 19, 2021
    risk 0.00cvss 6.1epss 0.01

    Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to XSS in handling an attachment's filename extension when displaying a MIME type warning message.

  • CVE-2021-41258HigNov 16, 2021
    risk 0.00cvss 7.3epss 0.01

    Kirby is an open source file structured CMS. In affected versions Kirby's blocks field stores structured data for each block. This data is then used in block snippets to convert the blocks to HTML for use in your templates. We recommend to escape HTML special characters to…

  • CVE-2020-14424MedNov 14, 2021
    risk 0.00cvss 6.1epss 0.02

    Cacti before 1.2.18 allows remote attackers to trigger XSS via template import for the midwinter theme.

  • CVE-2021-43523CriNov 10, 2021
    risk 0.00cvss 9.6epss 0.03

    In uClibc and uClibc-ng before 1.0.39, incorrect handling of special characters in domain names returned by DNS servers via gethostbyname, getaddrinfo, gethostbyaddr, and getnameinfo can lead to output of wrong hostnames (leading to domain hijacking) or injection into…

  • CVE-2021-33611MedNov 2, 2021
    risk 0.00cvss 6.1epss 0.01

    Missing output sanitization in test sources in org.webjars.bowergithub.vaadin:vaadin-menu-bar versions 1.0.0 through 1.2.0 (Vaadin 14.0.0 through 14.4.4) allows remote attackers to execute malicious JavaScript in browser by opening crafted URL