VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (46,610)

page 2085 of 2,331
  • CVE-2021-3646MedSep 10, 2021
    risk 0.00cvss 6.1epss 0.01

    btcpayserver is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

  • CVE-2021-31274MedSep 8, 2021
    risk 0.00cvss 5.4epss 0.01

    In LibreNMS < 21.3.0, a stored XSS vulnerability was identified in the API Access page due to insufficient sanitization of the $api->description variable. As a result, arbitrary Javascript code can get executed.

  • CVE-2021-32782MedSep 7, 2021
    risk 0.00cvss 5.8epss 0.01

    Nextcloud Circles is an open source social network built for the nextcloud ecosystem. In affected versions the Nextcloud Circles application is vulnerable to a stored Cross-Site Scripting (XSS) vulnerability. Due the strict Content-Security-Policy shipped with Nextcloud, this…

  • CVE-2021-3768MedSep 6, 2021
    risk 0.00cvss 5.4epss 0.01

    bookstack is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

  • CVE-2021-3767MedSep 6, 2021
    risk 0.00cvss 5.4epss 0.01

    bookstack is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

  • CVE-2021-23439MedSep 5, 2021
    risk 0.00cvss 4.2epss 0.01

    This affects the package file-upload-with-preview before 4.2.0. A file containing malicious JavaScript code in the name can be uploaded (a user needs to be tricked into uploading such a file).

  • CVE-2021-39170HigSep 1, 2021
    risk 0.00cvss 8.0epss 0.01

    Pimcore is an open source data & experience management platform. Prior to version 10.1.2, an authenticated user could add XSS code as a value of custom metadata on assets. There is a patch for this issue in Pimcore version 10.1.2. As a workaround, users may apply the patch…

  • CVE-2021-39166HigSep 1, 2021
    risk 0.00cvss 8.0epss 0.01

    Pimcore is an open source data & experience management platform. Prior to version 10.1.2, text-values were not properly escaped before printed in the version preview. This allowed XSS by authenticated users with access to the resources. This issue is patched in Pimcore version…

  • CVE-2021-37794MedAug 31, 2021
    risk 0.00cvss 5.4epss 0.01

    A stored cross-site scripting (XSS) vulnerability exists in FileBrowser < v2.16.0 that allows an authenticated user authorized to upload a malicious .svg file which acts as a stored XSS payload. If this stored XSS payload is triggered by an administrator it will trigger…

  • CVE-2021-39175HigAug 30, 2021
    risk 0.00cvss 8.1epss 0.01

    HedgeDoc is a platform to write and share markdown. In versions prior to 1.9.0, an unauthenticated attacker can inject arbitrary JavaScript into the speaker-notes of the slide-mode feature by embedding an iframe hosting the malicious code into the slides or by embedding the…

  • CVE-2021-39169HigAug 27, 2021
    risk 0.00cvss 8.0epss 0.01

    Misskey is a decentralized microblogging platform. In versions of Misskey prior to 12.51.0, malicious actors can use the web client built-in dialog to display a malicious string, leading to cross-site scripting (XSS). XSS could compromise the API request token. This issue has…

  • CVE-2020-14161MedAug 26, 2021
    risk 0.00cvss 6.1epss 0.01

    It is possible to inject HTML and/or JavaScript in the HTML to PDF conversion in Gotenberg through 6.2.1 via the /convert/html endpoint.

  • CVE-2021-3694HigAug 23, 2021
    risk 0.00cvss 8.2epss 0.03

    LedgerSMB does not sufficiently HTML-encode error messages sent to the browser. By sending a specially crafted URL to an authenticated user, this flaw can be abused for remote code execution and information disclosure.

  • CVE-2021-37390MedAug 10, 2021
    risk 0.00cvss 6.1epss 0.01

    A Chamilo LMS 1.11.14 reflected XSS vulnerability exists in main/social/search.php=q URI (social network search feature).

  • CVE-2021-37389MedAug 10, 2021
    risk 0.00cvss 6.1epss 0.01

    Chamilo 1.11.14 allows stored XSS via main/install/index.php and main/install/ajax.php through the port parameter.

  • CVE-2021-37633HigAug 9, 2021
    risk 0.00cvss 7.4epss 0.01

    Discourse is an open source discussion platform. In versions prior to 2.7.8 rendering of d-popover tooltips can be susceptible to XSS attacks. This vulnerability only affects sites which have modified or disabled Discourse's default Content Security Policy. This issue is patched…

  • CVE-2021-38193MedAug 8, 2021
    risk 0.00cvss 6.1epss 0.01

    An issue was discovered in the ammonia crate before 3.1.0 for Rust. XSS can occur because the parsing differences for HTML, SVG, and MathML are mishandled, a similar issue to CVE-2020-26870.

  • CVE-2021-35265MedAug 3, 2021
    risk 0.00cvss 6.1epss 0.03

    A reflected cross-site scripting (XSS) vulnerability in MaxSite CMS before V106 via product/page/* allows remote attackers to inject arbitrary web script to a page.

  • CVE-2021-32812MedAug 2, 2021
    risk 0.00cvss 4.6epss 0.01

    Monkshu is an enterprise application server for mobile apps (iOS and Android), responsive HTML 5 apps, and JSON API services. In version 2.90 and earlier, there is a reflected cross-site scripting vulnerability in frontend HTTP server. The attacker can send in a carefully…

  • CVE-2021-37596MedJul 30, 2021
    risk 0.00cvss 6.1epss 0.01

    Telegram Web K Alpha 0.6.1 allows XSS via a document name.