VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (46,610)

page 2084 of 2,331
  • CVE-2020-22864MedOct 26, 2021
    risk 0.00cvss 6.1epss 0.01

    A cross site scripting (XSS) vulnerability in the Insert Video function of Froala WYSIWYG Editor 3.1.0 allows attackers to execute arbitrary web scripts or HTML.

  • CVE-2021-41175HigOct 26, 2021
    risk 0.00cvss 7.3epss 0.01

    Pi-hole's Web interface (based on AdminLTE) provides a central location to manage one's Pi-hole and review the statistics generated by FTLDNS. Prior to version 5.8, cross-site scripting is possible when adding a client via the groups-clients management page. This issue was…

  • CVE-2021-39221MedOct 25, 2021
    risk 0.00cvss 6.4epss 0.01

    Nextcloud is an open-source, self-hosted productivity platform. The Nextcloud Contacts application prior to version 4.0.3 was vulnerable to a stored Cross-Site Scripting (XSS) vulnerability. For exploitation, a user would need to right-click on a malicious file and open the file…

  • CVE-2021-21319MedOct 25, 2021
    risk 0.00cvss 6.8epss 0.01

    Galette is a membership management web application geared towards non profit organizations. In versions prior to 0.9.5, malicious javascript code can be stored to be displayed later on self subscription page. The self subscription feature can be disabled as a workaround (this is…

  • CVE-2021-24884CriOct 25, 2021
    risk 0.00cvss 9.6epss 0.03

    The Formidable Form Builder WordPress plugin before 4.09.05 allows to inject certain HTML Tags like ,,, and.This could allow an unauthenticated, remote attacker to exploit a HTML-injection byinjecting a malicous link. The HTML-injection may trick…

  • CVE-2021-32664HigOct 19, 2021
    risk 0.00cvss 8.1epss 0.01

    Combodo iTop is an open source web based IT Service Management tool. In affected versions there is a XSS vulnerability on "run query" page when logged as administrator. This has been resolved in versions 2.6.5 and 2.7.5.

  • CVE-2021-25968MedOct 19, 2021
    risk 0.00cvss 5.4epss 0.01

    In “OpenCMS”, versions 10.5.0 to 11.0.2 are affected by a stored XSS vulnerability that allows low privileged application users to store malicious scripts in the Sitemap functionality. These scripts are executed in a victim’s browser when they open the page containing the…

  • CVE-2021-42650MedOct 18, 2021
    risk 0.00cvss 6.1epss 0.01

    Cross Site Scripting (XSS vulnerability exists in Portainer before 2.9.1 via the node input box in Custom Templates.

  • CVE-2020-8291MedOct 18, 2021
    risk 0.00cvss 6.1epss 0.01

    A link preview rendering issue in Rocket.Chat versions before 3.9 could lead to potential XSS attacks.

  • CVE-2021-41139HigOct 13, 2021
    risk 0.00cvss 8.1epss 0.01

    Anuko Time Tracker is an open source, web-based time tracking application written in PHP. When a logged on user selects a date in Time Tracker, it is being passed on via the date parameter in URI. Because of not checking this parameter for sanity in versions prior to…

  • CVE-2021-25964MedOct 4, 2021
    risk 0.00cvss 5.4epss 0.01

    In “Calibre-web” application, v0.6.0 to v0.6.12, are vulnerable to Stored XSS in “Metadata”. An attacker that has access to edit the metadata information, can inject JavaScript payload in the description field. When a victim tries to open the file, XSS will be triggered.

  • CVE-2021-40926MedOct 1, 2021
    risk 0.00cvss 6.1epss 0.01

    Cross-site scripting (XSS) vulnerability in demos/demo.mysqli.php in getID3 1.X and v2.0.0-beta allows remote attackers to inject arbitrary web script or HTML via the showtagfiles parameter.

  • CVE-2021-41095MedSep 27, 2021
    risk 0.00cvss 4.2epss 0.01

    Discourse is an open source discussion platform. There is a cross-site scripting (XSS) vulnerability in versions 2.7.7 and earlier of the `stable` branch, versions 2.8.0.beta6 and earlier of the `beta` branch, and versions 2.8.0.beta6 and earlier of the `tests-passed` branch.…

  • CVE-2021-3830MedSep 26, 2021
    risk 0.00cvss 5.4epss 0.01

    btcpayserver is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

  • CVE-2016-6556HigSep 24, 2021
    risk 0.00cvss 7.1epss 0.01

    OpenNMS version 18.0.1 and prior are vulnerable to a stored XSS issue due to insufficient filtering of SNMP agent supplied data. By creating a malicious SNMP 'sysName' or 'sysContact' response, an attacker can store an XSS payload which will trigger when a user of the web UI…

  • CVE-2016-6555HigSep 24, 2021
    risk 0.00cvss 7.1epss 0.01

    OpenNMS version 18.0.1 and prior are vulnerable to a stored XSS issue due to insufficient filtering of SNMP trap supplied data. By creating a malicious SNMP trap, an attacker can store an XSS payload which will trigger when a user of the web UI views the events list page. This…

  • CVE-2021-3812MedSep 17, 2021
    risk 0.00cvss 6.1epss 0.01

    adminlte is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

  • CVE-2021-3811MedSep 17, 2021
    risk 0.00cvss 6.1epss 0.01

    adminlte is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

  • CVE-2021-27340MedSep 16, 2021
    risk 0.00cvss 6.1epss 0.01

    OpenSIS Community Edition version <= 7.6 is affected by a reflected XSS vulnerability in EmailCheck.php via the "opt" parameter.

  • CVE-2021-39205MedSep 15, 2021
    risk 0.00cvss 6.8epss 0.01

    Jitsi Meet is an open source video conferencing application. Versions prior to 2.0.6173 are vulnerable to client-side cross-site scripting via injecting properties into JSON objects that were not properly escaped. There are no known incidents related to this vulnerability being…