CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Description
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85
CVEs mapped to this weakness (46,610)
page 2088 of 2,331| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-21383 | Hig | 0.00 | 7.6 | 0.01 | Mar 18, 2021 | Wiki.js an open-source wiki app built on Node.js. Wiki.js before version 2.5.191 is vulnerable to stored cross-site scripting through mustache expressions in code blocks. This vulnerability exists due to mustache expressions being parsed by Vue during content injection even… | ||
| CVE-2021-28115 | Med | 0.00 | 6.1 | 0.01 | Mar 9, 2021 | The OUGC Feedback plugin before 1.8.23 for MyBB allows XSS via the comment field of feedback during an edit operation. | ||
| CVE-2021-22878 | Med | 0.00 | 4.8 | 0.01 | Mar 3, 2021 | Nextcloud Server prior to 20.0.6 is vulnerable to reflected cross-site scripting (XSS) due to lack of sanitization in `OC.Notification.show`. | ||
| CVE-2021-23347 | Med | 0.00 | 4.7 | 0.01 | Mar 3, 2021 | The package github.com/argoproj/argo-cd/cmd before 1.7.13, from 1.8.0 and before 1.8.6 are vulnerable to Cross-site Scripting (XSS) the SSO provider connected to Argo CD would have to send back a malicious error message containing JavaScript to the user. | ||
| CVE-2021-21258 | Med | 0.00 | 6.8 | 0.01 | Mar 2, 2021 | GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. In GLPI from version 9.5.0 and before version 9.5.4, there is a cross-site scripting injection vulnerability when using… | ||
| CVE-2020-1936 | Med | 0.00 | 6.1 | 0.03 | Mar 2, 2021 | A cross-site scripting issue was found in Apache Ambari Views. This was addressed in Apache Ambari 2.7.4. | ||
| CVE-2020-27224 | Cri | 0.00 | 9.6 | 0.02 | Feb 24, 2021 | In Eclipse Theia versions up to and including 1.2.0, the Markdown Preview (@theia/preview), can be exploited to execute arbitrary code. | ||
| CVE-2021-27279 | Med | 0.00 | 5.4 | 0.01 | Feb 22, 2021 | MyBB before 1.8.25 allows stored XSS via nested [email] tags with MyCode (aka BBCode). | ||
| CVE-2021-27559 | Med | 0.00 | 5.4 | 0.01 | Feb 22, 2021 | The Contact page in Monica 2.19.1 allows stored XSS via the Nickname field. | ||
| CVE-2021-27371 | Med | 0.00 | 5.4 | 0.01 | Feb 22, 2021 | The Contact page in Monica 2.19.1 allows stored XSS via the Description field. | ||
| CVE-2021-27369 | Med | 0.00 | 5.4 | 0.01 | Feb 22, 2021 | The Contact page in Monica 2.19.1 allows stored XSS via the Middle Name field. | ||
| CVE-2021-27368 | Med | 0.00 | 5.4 | 0.01 | Feb 22, 2021 | The Contact page in Monica 2.19.1 allows stored XSS via the First Name field. | ||
| CVE-2021-26746 | Med | 0.00 | 6.1 | 0.01 | Feb 19, 2021 | Chamilo 1.11.14 allows XSS via a main/calendar/agenda_list.php?type= URI. | ||
| CVE-2020-29171 | Med | 0.00 | 6.1 | 0.01 | Feb 10, 2021 | Cross-site scripting (XSS) vulnerability in admin/wp-security-blacklist-menu.php in the Tips and Tricks HQ All In One WP Security & Firewall (all-in-one-wp-security-and-firewall) plugin before 4.4.6 for WordPress. | ||
| CVE-2021-26925 | Med | 0.00 | 5.4 | 0.01 | Feb 9, 2021 | Roundcube before 1.4.11 allows XSS via crafted Cascading Style Sheets (CSS) token sequences during HTML email rendering. | ||
| CVE-2021-3258 | Med | 0.00 | 5.4 | 0.02 | Feb 5, 2021 | Question2Answer Q2A Ultimate SEO Version 1.3 is affected by cross-site scripting (XSS), which may lead to arbitrary remote code execution. | ||
| CVE-2021-3350 | Med | 0.00 | 6.1 | 0.01 | Feb 1, 2021 | deleteaccount.php in the Delete Account plugin 1.4 for MyBB allows XSS via the deletereason parameter. | ||
| CVE-2021-22872 | Med | 0.00 | 6.1 | 0.03 | Jan 26, 2021 | Revive Adserver before 5.1.0 is vulnerable to a reflected cross-site scripting (XSS) vulnerability via the publicly accessible afr.php delivery script. While this issue was previously addressed in modern browsers as CVE-2020-8115, some older browsers (e.g., IE10) that do not… | ||
| CVE-2021-22871 | Med | 0.00 | 4.8 | 0.02 | Jan 26, 2021 | Revive Adserver before 5.1.0 permits any user with a manager account to store possibly malicious content in the URL website property, which is then displayed unsanitized in the affiliate-preview.php tag generation screen, leading to a persistent cross-site scripting (XSS)… | ||
| CVE-2020-23014 | Med | 0.00 | 5.4 | 0.01 | Jan 26, 2021 | APfell 1.4 is vulnerable to authenticated reflected cross-site scripting (XSS) in /apiui/command_ through the payloadtypes_callback function, which allows an attacker to steal remote admin/user session and/or adding new users to the administration panel. |
- risk 0.00cvss 7.6epss 0.01
Wiki.js an open-source wiki app built on Node.js. Wiki.js before version 2.5.191 is vulnerable to stored cross-site scripting through mustache expressions in code blocks. This vulnerability exists due to mustache expressions being parsed by Vue during content injection even…
- risk 0.00cvss 6.1epss 0.01
The OUGC Feedback plugin before 1.8.23 for MyBB allows XSS via the comment field of feedback during an edit operation.
- risk 0.00cvss 4.8epss 0.01
Nextcloud Server prior to 20.0.6 is vulnerable to reflected cross-site scripting (XSS) due to lack of sanitization in `OC.Notification.show`.
- risk 0.00cvss 4.7epss 0.01
The package github.com/argoproj/argo-cd/cmd before 1.7.13, from 1.8.0 and before 1.8.6 are vulnerable to Cross-site Scripting (XSS) the SSO provider connected to Argo CD would have to send back a malicious error message containing JavaScript to the user.
- risk 0.00cvss 6.8epss 0.01
GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. In GLPI from version 9.5.0 and before version 9.5.4, there is a cross-site scripting injection vulnerability when using…
- risk 0.00cvss 6.1epss 0.03
A cross-site scripting issue was found in Apache Ambari Views. This was addressed in Apache Ambari 2.7.4.
- risk 0.00cvss 9.6epss 0.02
In Eclipse Theia versions up to and including 1.2.0, the Markdown Preview (@theia/preview), can be exploited to execute arbitrary code.
- risk 0.00cvss 5.4epss 0.01
MyBB before 1.8.25 allows stored XSS via nested [email] tags with MyCode (aka BBCode).
- risk 0.00cvss 5.4epss 0.01
The Contact page in Monica 2.19.1 allows stored XSS via the Nickname field.
- risk 0.00cvss 5.4epss 0.01
The Contact page in Monica 2.19.1 allows stored XSS via the Description field.
- risk 0.00cvss 5.4epss 0.01
The Contact page in Monica 2.19.1 allows stored XSS via the Middle Name field.
- risk 0.00cvss 5.4epss 0.01
The Contact page in Monica 2.19.1 allows stored XSS via the First Name field.
- risk 0.00cvss 6.1epss 0.01
Chamilo 1.11.14 allows XSS via a main/calendar/agenda_list.php?type= URI.
- risk 0.00cvss 6.1epss 0.01
Cross-site scripting (XSS) vulnerability in admin/wp-security-blacklist-menu.php in the Tips and Tricks HQ All In One WP Security & Firewall (all-in-one-wp-security-and-firewall) plugin before 4.4.6 for WordPress.
- risk 0.00cvss 5.4epss 0.01
Roundcube before 1.4.11 allows XSS via crafted Cascading Style Sheets (CSS) token sequences during HTML email rendering.
- risk 0.00cvss 5.4epss 0.02
Question2Answer Q2A Ultimate SEO Version 1.3 is affected by cross-site scripting (XSS), which may lead to arbitrary remote code execution.
- risk 0.00cvss 6.1epss 0.01
deleteaccount.php in the Delete Account plugin 1.4 for MyBB allows XSS via the deletereason parameter.
- risk 0.00cvss 6.1epss 0.03
Revive Adserver before 5.1.0 is vulnerable to a reflected cross-site scripting (XSS) vulnerability via the publicly accessible afr.php delivery script. While this issue was previously addressed in modern browsers as CVE-2020-8115, some older browsers (e.g., IE10) that do not…
- risk 0.00cvss 4.8epss 0.02
Revive Adserver before 5.1.0 permits any user with a manager account to store possibly malicious content in the URL website property, which is then displayed unsanitized in the affiliate-preview.php tag generation screen, leading to a persistent cross-site scripting (XSS)…
- risk 0.00cvss 5.4epss 0.01
APfell 1.4 is vulnerable to authenticated reflected cross-site scripting (XSS) in /apiui/command_ through the payloadtypes_callback function, which allows an attacker to steal remote admin/user session and/or adding new users to the administration panel.