VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (46,610)

page 2086 of 2,331
  • CVE-2021-32792LowJul 26, 2021
    risk 0.00cvss 3.1epss 0.02

    mod_auth_openidc is an authentication/authorization module for the Apache 2.x HTTP server that functions as an OpenID Connect Relying Party, authenticating users against an OpenID Connect Provider. In mod_auth_openidc before version 2.4.9, there is an XSS vulnerability in when…

  • CVE-2021-26799MedJul 23, 2021
    risk 0.00cvss 6.1epss 0.01

    Cross Site Scripting (XSS) vulnerability in admin/files/edit in Omeka Classic <=2.7 allows remote attackers to inject arbitrary web script or HTML.

  • CVE-2021-3619LowJul 22, 2021
    risk 0.00cvss 3.5epss 0.01

    Rapid7 Velociraptor 0.5.9 and prior is vulnerable to a post-authentication persistent cross-site scripting (XSS) issue, where an authenticated user could abuse MIME filetype sniffing to embed executable code on a malicious upload. This issue was fixed in version 0.6.0. Note that…

  • CVE-2021-35043MedJul 19, 2021
    risk 0.00cvss 6.1epss 0.02

    OWASP AntiSamy before 1.6.4 allows XSS via HTML attributes when using the HTML output serializer (XHTML is not affected). This was demonstrated by a javascript: URL with &#00058 as the replacement for the : character.

  • CVE-2021-34817MedJul 19, 2021
    risk 0.00cvss 6.1epss 0.01

    A Cross-Site Scripting (XSS) issue in the chat component of Etherpad 1.8.13 allows remote attackers to inject arbitrary JavaScript or HTML by importing a crafted pad.

  • CVE-2021-36755MedJul 16, 2021
    risk 0.00cvss 6.1epss 0.01

    Nightscout Web Monitor (aka cgm-remote-monitor) 14.2.2 allows XSS via a crafted X-Forwarded-For header.

  • CVE-2021-32733MedJul 12, 2021
    risk 0.00cvss 4.8epss 0.01

    Nextcloud Text is a collaborative document editing application that uses Markdown. A cross-site scripting vulnerability is present in versions prior to 19.0.13, 20.0.11, and 21.0.3. The Nextcloud Text application shipped with Nextcloud server used a `text/html` Content-Type when…

  • CVE-2021-35440MedJul 6, 2021
    risk 0.00cvss 6.1epss 0.01

    Smashing 1.3.4 is vulnerable to Cross Site Scripting (XSS). A URL for a widget can be crafted and used to execute JavaScript on the victim's computer. The JavaScript code can then steal data available in the session/cookies depending on the user environment (e.g. if re-using…

  • CVE-2020-22609MedJun 28, 2021
    risk 0.00cvss 6.1epss 0.01

    Cross Site Scripting (XSS) vulnerability in Enhancesoft osTicket before v1.12.6 via the queue-name parameter in include/class.queue.php.

  • CVE-2020-22608MedJun 28, 2021
    risk 0.00cvss 6.1epss 0.01

    Cross Site Scripting vulnerability in Enhancesoft osTicket before v1.12.6 via the queue-name parameter to include/ajax.search.php.

  • CVE-2020-22607MedJun 28, 2021
    risk 0.00cvss 6.1epss 0.01

    Cross Site Scripting vulnerabilty in LimeSurvey 4.1.11+200316 via the (1) name and (2) description parameters in application/controllers/admin/PermissiontemplatesController.php.

  • CVE-2021-32719LowJun 28, 2021
    risk 0.00cvss 3.1epss 0.01

    RabbitMQ is a multi-protocol messaging broker. In rabbitmq-server prior to version 3.8.18, when a federation link was displayed in the RabbitMQ management UI via the `rabbitmq_federation_management` plugin, its consumer tag was rendered without proper tag sanitization.…

  • CVE-2021-32718LowJun 28, 2021
    risk 0.00cvss 3.1epss 0.01

    RabbitMQ is a multi-protocol messaging broker. In rabbitmq-server prior to version 3.8.17, a new user being added via management UI could lead to the user's bane being rendered in a confirmation message without proper `` tag sanitization, potentially allowing for…

  • CVE-2021-35513MedJun 27, 2021
    risk 0.00cvss 6.1epss 0.01

    Mermaid before 8.11.0 allows XSS when the antiscript feature is used.

  • CVE-2021-32644MedJun 22, 2021
    risk 0.00cvss 6.4epss 0.01

    Ampache is an open source web based audio/video streaming application and file manager. Due to a lack of input filtering versions 4.x.y are vulnerable to code injection in random.php. The attack requires user authentication to access the random.php page unless the site is…

  • CVE-2019-25047MedJun 21, 2021
    risk 0.00cvss 6.1epss 0.01

    Greenbone Security Assistant (GSA) before 8.0.2 and Greenbone OS (GOS) before 5.0.10 allow XSS during 404 URL handling in gsad.

  • CVE-2021-32683HigJun 15, 2021
    risk 0.00cvss 8.8epss 0.01

    wire-webapp is the web version of Wire, an open-source messenger. A cross-site scripting vulnerability exists in wire-webapp prior to version 2021-06-01-production.0. If a user is instructed to open an image in a new tab (right click -> open in new tab, or copy the URL and paste…

  • CVE-2020-21316MedJun 15, 2021
    risk 0.00cvss 6.1epss 0.01

    A Cross-site scripting (XSS) vulnerability exists in the comment section in ZrLog 2.1.3, which allows remote attackers to inject arbitrary web script and stolen administrator cookies via the nickname parameter and gain access to the admin panel.

  • CVE-2020-26693MedJun 1, 2021
    risk 0.00cvss 5.4epss 0.05

    A stored cross-site scripting (XSS) vulnerability was discovered in pfSense 2.4.5-p1 which allows an authenticated attacker to execute arbitrary web scripts via exploitation of the load_balancer_monitor.php function.

  • CVE-2021-25932MedJun 1, 2021
    risk 0.00cvss 5.4epss 0.01

    In OpenNMS Horizon, versions opennms-1-0-stable through opennms-27.1.0-1; OpenNMS Meridian, versions meridian-foundation-2015.1.0-1 through meridian-foundation-2019.1.18-1; meridian-foundation-2020.1.0-1 through meridian-foundation-2020.1.6-1 are vulnerable to Stored Cross-Site…