VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (46,610)

page 2087 of 2,331
  • CVE-2021-3509MedMay 27, 2021
    risk 0.00cvss 6.1epss 0.02

    A flaw was found in Red Hat Ceph Storage 4, in the Dashboard component. In response to CVE-2020-27839, the JWT token was moved from localStorage to an httpOnly cookie. However, token cookies are used in the body of the HTTP response for the documentation, which again makes it…

  • CVE-2021-25935MedMay 25, 2021
    risk 0.00cvss 5.4epss 0.01

    In OpenNMS Horizon, versions opennms-17.0.0-1 through opennms-27.1.0-1; OpenNMS Meridian, versions meridian-foundation-2015.1.0-1 through meridian-foundation-2019.1.18-1; meridian-foundation-2020.1.0-1 through meridian-foundation-2020.1.7-1 are vulnerable to Stored Cross-Site…

  • CVE-2021-25938MedMay 24, 2021
    risk 0.00cvss 6.1epss 0.01

    In ArangoDB, versions v2.2.6.2 through v3.7.10 are vulnerable to Cross-Site Scripting (XSS), since there is no validation of the .zip file name and filtering of potential abusive characters which zip files can be named to. There is no X-Frame-Options Header set, which makes it…

  • CVE-2020-21054MedMay 20, 2021
    risk 0.00cvss 6.1epss 0.01

    Cross Site Scripting (XSS) vulnerability in FusionPBX 4.5.7 allows remote malicious users to inject arbitrary web script or HTML via an unsanitized "f" variable in app\vars\vars_textarea.php.

  • CVE-2020-21053MedMay 20, 2021
    risk 0.00cvss 6.1epss 0.01

    Cross Site Scriptiong (XSS) vulnerability exists in FusionPBX 4.5.7 allows remote malicious users to inject arbitrary web script or HTML via an unsanitized "query_string" variable in app\devices\device_imports.php.

  • CVE-2021-29503HigMay 19, 2021
    risk 0.00cvss 8.1epss 0.01

    HedgeDoc is a platform to write and share markdown. HedgeDoc before version 1.8.2 is vulnerable to a cross-site scripting attack using the YAML-metadata of a note. An attacker with write access to a note can embed HTML tags in the Open Graph metadata section of the note,…

  • CVE-2021-31930MedMay 19, 2021
    risk 0.00cvss 6.1epss 0.01

    Persistent cross-site scripting (XSS) in the web interface of Concerto through 2.3.6 allows an unauthenticated remote attacker to introduce arbitrary JavaScript by injecting an XSS payload into the First Name or Last Name parameter upon registration. When a privileged user…

  • CVE-2020-23263MedMay 6, 2021
    risk 0.00cvss 6.1epss 0.01

    Persistent Cross-site scripting vulnerability on Fork CMS version 5.8.2 allows remote attackers to inject arbitrary Javascript code via the "navigation_title" parameter and the "title" parameter in /private/en/pages/add.

  • CVE-2020-22808MedApr 29, 2021
    risk 0.00cvss 6.1epss 0.01

    An issue was found in yii2_fecshop 2.x. There is a reflected XSS vulnerability in the check cart page.

  • CVE-2021-28280MedApr 29, 2021
    risk 0.00cvss 6.1epss 0.01

    CSRF + Cross-site scripting (XSS) vulnerability in search.php in PHPFusion 9.03.110 allows remote attackers to inject arbitrary web script or HTML

  • CVE-2019-25028MedApr 23, 2021
    risk 0.00cvss 5.4epss 0.01

    Missing variable sanitization in Grid component in com.vaadin:vaadin-server versions 7.4.0 through 7.7.19 (Vaadin 7.4.0 through 7.7.19), and 8.0.0 through 8.8.4 (Vaadin 8.0.0 through 8.8.4) allows attacker to inject malicious JavaScript via unspecified vector

  • CVE-2019-25027MedApr 23, 2021
    risk 0.00cvss 6.1epss 0.01

    Missing output sanitization in default RouteNotFoundError view in com.vaadin:flow-server versions 1.0.0 through 1.0.10 (Vaadin 10.0.0 through 10.0.13), and 1.1.0 through 1.4.2 (Vaadin 11.0.0 through 13.0.5) allows attacker to execute malicious JavaScript via crafted URL

  • CVE-2021-22540MedApr 22, 2021
    risk 0.00cvss 6.1epss 0.01

    Bad validation logic in the Dart SDK versions prior to 2.12.3 allow an attacker to use an XSS attack via DOM clobbering. The validation logic in dart:html for creating DOM nodes from text did not sanitize properly when it came across template tags.

  • CVE-2020-35660MedApr 14, 2021
    risk 0.00cvss 5.4epss 0.01

    Cross Site Scripting (XSS) in Monica before 2.19.1 via the journal page.

  • CVE-2020-28124MedApr 14, 2021
    risk 0.00cvss 5.4epss 0.01

    Cross Site Scripting (XSS) in LavaLite 5.8.0 via the Address field.

  • CVE-2021-21398MedMar 30, 2021
    risk 0.00cvss 5.4epss 0.01

    PrestaShop is a fully scalable open source e-commerce solution. In PrestaShop before version 1.7.7.3, an attacker can inject HTML when the Grid Column Type DataColumn is badly used. The problem is fixed in 1.7.7.3

  • CVE-2021-22886MedMar 26, 2021
    risk 0.00cvss 6.1epss 0.02

    Rocket.Chat before 3.11, 3.10.5, 3.9.7, 3.8.8 is vulnerable to persistent cross-site scripting (XSS) using nested markdown tags allowing a remote attacker to inject arbitrary JavaScript in a message. This flaw leads to arbitrary file read and RCE on Rocket.Chat desktop app.

  • CVE-2021-25922MedMar 22, 2021
    risk 0.00cvss 6.1epss 0.01

    In OpenEMR, versions 4.2.0 to 6.0.0 are vulnerable to Reflected Cross-Site-Scripting (XSS) due to user input not being validated properly. An attacker could trick a user to click on a malicious url and execute malicious code.

  • CVE-2021-25918MedMar 22, 2021
    risk 0.00cvss 4.8epss 0.01

    In OpenEMR, versions 5.0.2 to 6.0.0 are vulnerable to Stored Cross-Site-Scripting (XSS) due to user input not being validated properly and rendered in the TOTP Authentication method page. A highly privileged attacker could inject arbitrary code into input fields when creating a…

  • CVE-2021-25917MedMar 22, 2021
    risk 0.00cvss 4.8epss 0.01

    In OpenEMR, versions 5.0.2 to 6.0.0 are vulnerable to Stored Cross-Site-Scripting (XSS) due to user input not being validated properly and rendered in the U2F USB Device authentication method page. A highly privileged attacker could inject arbitrary code into input fields when…