VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (46,610)

page 2088 of 2,331
  • CVE-2021-21383HigMar 18, 2021
    risk 0.00cvss 7.6epss 0.01

    Wiki.js an open-source wiki app built on Node.js. Wiki.js before version 2.5.191 is vulnerable to stored cross-site scripting through mustache expressions in code blocks. This vulnerability exists due to mustache expressions being parsed by Vue during content injection even…

  • CVE-2021-28115MedMar 9, 2021
    risk 0.00cvss 6.1epss 0.01

    The OUGC Feedback plugin before 1.8.23 for MyBB allows XSS via the comment field of feedback during an edit operation.

  • CVE-2021-22878MedMar 3, 2021
    risk 0.00cvss 4.8epss 0.01

    Nextcloud Server prior to 20.0.6 is vulnerable to reflected cross-site scripting (XSS) due to lack of sanitization in `OC.Notification.show`.

  • CVE-2021-23347MedMar 3, 2021
    risk 0.00cvss 4.7epss 0.01

    The package github.com/argoproj/argo-cd/cmd before 1.7.13, from 1.8.0 and before 1.8.6 are vulnerable to Cross-site Scripting (XSS) the SSO provider connected to Argo CD would have to send back a malicious error message containing JavaScript to the user.

  • CVE-2021-21258MedMar 2, 2021
    risk 0.00cvss 6.8epss 0.01

    GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. In GLPI from version 9.5.0 and before version 9.5.4, there is a cross-site scripting injection vulnerability when using…

  • CVE-2020-1936MedMar 2, 2021
    risk 0.00cvss 6.1epss 0.03

    A cross-site scripting issue was found in Apache Ambari Views. This was addressed in Apache Ambari 2.7.4.

  • CVE-2020-27224CriFeb 24, 2021
    risk 0.00cvss 9.6epss 0.02

    In Eclipse Theia versions up to and including 1.2.0, the Markdown Preview (@theia/preview), can be exploited to execute arbitrary code.

  • CVE-2021-27279MedFeb 22, 2021
    risk 0.00cvss 5.4epss 0.01

    MyBB before 1.8.25 allows stored XSS via nested [email] tags with MyCode (aka BBCode).

  • CVE-2021-27559MedFeb 22, 2021
    risk 0.00cvss 5.4epss 0.01

    The Contact page in Monica 2.19.1 allows stored XSS via the Nickname field.

  • CVE-2021-27371MedFeb 22, 2021
    risk 0.00cvss 5.4epss 0.01

    The Contact page in Monica 2.19.1 allows stored XSS via the Description field.

  • CVE-2021-27369MedFeb 22, 2021
    risk 0.00cvss 5.4epss 0.01

    The Contact page in Monica 2.19.1 allows stored XSS via the Middle Name field.

  • CVE-2021-27368MedFeb 22, 2021
    risk 0.00cvss 5.4epss 0.01

    The Contact page in Monica 2.19.1 allows stored XSS via the First Name field.

  • CVE-2021-26746MedFeb 19, 2021
    risk 0.00cvss 6.1epss 0.01

    Chamilo 1.11.14 allows XSS via a main/calendar/agenda_list.php?type= URI.

  • CVE-2020-29171MedFeb 10, 2021
    risk 0.00cvss 6.1epss 0.01

    Cross-site scripting (XSS) vulnerability in admin/wp-security-blacklist-menu.php in the Tips and Tricks HQ All In One WP Security & Firewall (all-in-one-wp-security-and-firewall) plugin before 4.4.6 for WordPress.

  • CVE-2021-26925MedFeb 9, 2021
    risk 0.00cvss 5.4epss 0.01

    Roundcube before 1.4.11 allows XSS via crafted Cascading Style Sheets (CSS) token sequences during HTML email rendering.

  • CVE-2021-3258MedFeb 5, 2021
    risk 0.00cvss 5.4epss 0.02

    Question2Answer Q2A Ultimate SEO Version 1.3 is affected by cross-site scripting (XSS), which may lead to arbitrary remote code execution.

  • CVE-2021-3350MedFeb 1, 2021
    risk 0.00cvss 6.1epss 0.01

    deleteaccount.php in the Delete Account plugin 1.4 for MyBB allows XSS via the deletereason parameter.

  • CVE-2021-22872MedJan 26, 2021
    risk 0.00cvss 6.1epss 0.03

    Revive Adserver before 5.1.0 is vulnerable to a reflected cross-site scripting (XSS) vulnerability via the publicly accessible afr.php delivery script. While this issue was previously addressed in modern browsers as CVE-2020-8115, some older browsers (e.g., IE10) that do not…

  • CVE-2021-22871MedJan 26, 2021
    risk 0.00cvss 4.8epss 0.02

    Revive Adserver before 5.1.0 permits any user with a manager account to store possibly malicious content in the URL website property, which is then displayed unsanitized in the affiliate-preview.php tag generation screen, leading to a persistent cross-site scripting (XSS)…

  • CVE-2020-23014MedJan 26, 2021
    risk 0.00cvss 5.4epss 0.01

    APfell 1.4 is vulnerable to authenticated reflected cross-site scripting (XSS) in /apiui/command_ through the payloadtypes_callback function, which allows an attacker to steal remote admin/user session and/or adding new users to the administration panel.