CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Description
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85
CVEs mapped to this weakness (46,610)
page 2089 of 2,331| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-25015 | Med | 0.00 | 5.4 | 0.01 | Jan 26, 2021 | LuCI in OpenWrt 18.06.0 through 18.06.4 allows stored XSS via a crafted SSID. | ||
| CVE-2021-21259 | Hig | 0.00 | 7.4 | 0.01 | Jan 22, 2021 | HedgeDoc is open source software which lets you create real-time collaborative markdown notes. In HedgeDoc before version 1.7.2, an attacker can inject arbitrary JavaScript into a HedgeDoc note, which is executed when the note is viewed in slide mode. Depending on the… | ||
| CVE-2020-28470 | Hig | 0.00 | 7.3 | 0.01 | Jan 14, 2021 | This affects the package @scullyio/scully before 1.0.9. The transfer state is serialised with the JSON.stringify() function and then written into the HTML page. | ||
| CVE-2020-25799 | Med | 0.00 | 5.4 | 0.01 | Dec 31, 2020 | LimeSurvey 3.21.1 is affected by cross-site scripting (XSS) in the Quota component of the Survey page. When the survey quota being viewed, e.g. by an administrative user, the JavaScript code will be executed in the browser. | ||
| CVE-2020-25797 | Med | 0.00 | 5.4 | 0.01 | Dec 31, 2020 | LimeSurvey 3.21.1 is affected by cross-site scripting (XSS) in the Add Participants Function (First and last name parameters). When the survey participant being edited, e.g. by an administrative user, the JavaScript code will be executed in the browser. | ||
| CVE-2020-26296 | Hig | 0.00 | 8.7 | 0.02 | Dec 30, 2020 | Vega is a visualization grammar, a declarative format for creating, saving, and sharing interactive visualization designs. Vega in an npm package. In Vega before version 5.17.3 there is an XSS vulnerability in Vega expressions. Through a specially crafted Vega expression, an… | ||
| CVE-2020-26287 | Hig | 0.00 | 8.7 | 0.01 | Dec 29, 2020 | HedgeDoc is a collaborative platform for writing and sharing markdown. In HedgeDoc before version 1.7.1 an attacker can inject arbitrary `script` tags in HedgeDoc notes using mermaid diagrams. Our content security policy prevents loading scripts from most locations, but… | ||
| CVE-2020-35659 | Med | 0.00 | 6.1 | 0.01 | Dec 24, 2020 | The DNS query log in Pi-hole before 5.2.2 is vulnerable to stored XSS. An attacker with the ability to directly or indirectly query DNS with a malicious hostname can cause arbitrary JavaScript to execute when the Pi-hole administrator visits the Query Log or Long-term data Query… | ||
| CVE-2020-26280 | Hig | 0.00 | 8.9 | 0.01 | Dec 18, 2020 | OpenSlides is a free, Web-based presentation and assembly system for managing and projecting agenda, motions, and elections of assemblies. OpenSlides version 3.2, due to unsufficient user input validation and escaping, it is vulnerable to persistant cross-site scripting (XSS).… | ||
| CVE-2020-28457 | Hig | 0.00 | 7.2 | 0.01 | Dec 15, 2020 | This affects the package s-cart/core before 4.4. The search functionality of the admin dashboard in core/src/Admin/Controllers/AdminOrderController.phpindex is vulnerable to XSS. | ||
| CVE-2020-28456 | Hig | 0.00 | 7.3 | 0.01 | Dec 15, 2020 | The package s-cart/core before 4.4 are vulnerable to Cross-site Scripting (XSS) via the admin panel. | ||
| CVE-2020-35132 | Med | 0.00 | 5.4 | 0.01 | Dec 11, 2020 | An XSS issue has been discovered in phpLDAPadmin before 1.2.6.2 that allows users to store malicious values that may be executed by other users at a later time via get_request in lib/function.php. | ||
| CVE-2020-27409 | Med | 0.00 | 6.1 | 0.01 | Dec 4, 2020 | OpenSIS Community Edition before 7.5 is affected by a cross-site scripting (XSS) vulnerability in SideForStudent.php via the modname parameter. | ||
| CVE-2020-26239 | Hig | 0.00 | 7.6 | 0.01 | Nov 23, 2020 | Scratch Addons is a WebExtension that supports both Chrome and Firefox. Scratch Addons before version 1.3.2 is vulnerable to DOM-based XSS. If the victim visited a specific website, the More Links addon of the Scratch Addons extension used incorrect regular expression which… | ||
| CVE-2020-25798 | Med | 0.00 | 5.4 | 0.01 | Nov 17, 2020 | A stored cross-site scripting (XSS) vulnerability in LimeSurvey before and including 3.21.1 allows authenticated users with correct permissions to inject arbitrary web script or HTML via parameter ParticipantAttributeNamesDropdown of the Attributes on the central participant… | ||
| CVE-2020-7773 | Med | 0.00 | 6.5 | 0.01 | Nov 16, 2020 | This affects the package markdown-it-highlightjs before 3.3.1. It is possible insert malicious JavaScript as a value of lang in the markdown-it-highlightjs Inline code highlighting feature. const markdownItHighlightjs = require("markdown-it-highlightjs"); const md =… | ||
| CVE-2020-25706 | Med | 0.00 | 5.4 | 0.03 | Nov 12, 2020 | A cross-site scripting (XSS) vulnerability exists in templates_import.php (Cacti 1.2.13) due to Improper escaping of error message during template import preview in the xml_path field | ||
| CVE-2020-26210 | Hig | 0.00 | 7.7 | 0.01 | Nov 3, 2020 | In BookStack before version 0.30.4, a user with permissions to edit a page could add an attached link which would execute untrusted JavaScript code when clicked by a viewer of the page. Dangerous content may remain in the database after this update. If you think this could have… | ||
| CVE-2020-26205 | Hig | 0.00 | 7.6 | 0.01 | Oct 29, 2020 | Sal is a multi-tenanted reporting dashboard for Munki with the ability to display information from Facter. In Sal through version 4.1.6 there is an XSS vulnerability on the machine_list view. | ||
| CVE-2020-24712 | Med | 0.00 | 5.4 | 0.01 | Oct 28, 2020 | Cross Site Scripting (XSS) vulnerability in Gophish before 0.11.0 via the IMAP Host field on the account settings page. |
- risk 0.00cvss 5.4epss 0.01
LuCI in OpenWrt 18.06.0 through 18.06.4 allows stored XSS via a crafted SSID.
- risk 0.00cvss 7.4epss 0.01
HedgeDoc is open source software which lets you create real-time collaborative markdown notes. In HedgeDoc before version 1.7.2, an attacker can inject arbitrary JavaScript into a HedgeDoc note, which is executed when the note is viewed in slide mode. Depending on the…
- risk 0.00cvss 7.3epss 0.01
This affects the package @scullyio/scully before 1.0.9. The transfer state is serialised with the JSON.stringify() function and then written into the HTML page.
- risk 0.00cvss 5.4epss 0.01
LimeSurvey 3.21.1 is affected by cross-site scripting (XSS) in the Quota component of the Survey page. When the survey quota being viewed, e.g. by an administrative user, the JavaScript code will be executed in the browser.
- risk 0.00cvss 5.4epss 0.01
LimeSurvey 3.21.1 is affected by cross-site scripting (XSS) in the Add Participants Function (First and last name parameters). When the survey participant being edited, e.g. by an administrative user, the JavaScript code will be executed in the browser.
- risk 0.00cvss 8.7epss 0.02
Vega is a visualization grammar, a declarative format for creating, saving, and sharing interactive visualization designs. Vega in an npm package. In Vega before version 5.17.3 there is an XSS vulnerability in Vega expressions. Through a specially crafted Vega expression, an…
- risk 0.00cvss 8.7epss 0.01
HedgeDoc is a collaborative platform for writing and sharing markdown. In HedgeDoc before version 1.7.1 an attacker can inject arbitrary `script` tags in HedgeDoc notes using mermaid diagrams. Our content security policy prevents loading scripts from most locations, but…
- risk 0.00cvss 6.1epss 0.01
The DNS query log in Pi-hole before 5.2.2 is vulnerable to stored XSS. An attacker with the ability to directly or indirectly query DNS with a malicious hostname can cause arbitrary JavaScript to execute when the Pi-hole administrator visits the Query Log or Long-term data Query…
- risk 0.00cvss 8.9epss 0.01
OpenSlides is a free, Web-based presentation and assembly system for managing and projecting agenda, motions, and elections of assemblies. OpenSlides version 3.2, due to unsufficient user input validation and escaping, it is vulnerable to persistant cross-site scripting (XSS).…
- risk 0.00cvss 7.2epss 0.01
This affects the package s-cart/core before 4.4. The search functionality of the admin dashboard in core/src/Admin/Controllers/AdminOrderController.phpindex is vulnerable to XSS.
- risk 0.00cvss 7.3epss 0.01
The package s-cart/core before 4.4 are vulnerable to Cross-site Scripting (XSS) via the admin panel.
- risk 0.00cvss 5.4epss 0.01
An XSS issue has been discovered in phpLDAPadmin before 1.2.6.2 that allows users to store malicious values that may be executed by other users at a later time via get_request in lib/function.php.
- risk 0.00cvss 6.1epss 0.01
OpenSIS Community Edition before 7.5 is affected by a cross-site scripting (XSS) vulnerability in SideForStudent.php via the modname parameter.
- risk 0.00cvss 7.6epss 0.01
Scratch Addons is a WebExtension that supports both Chrome and Firefox. Scratch Addons before version 1.3.2 is vulnerable to DOM-based XSS. If the victim visited a specific website, the More Links addon of the Scratch Addons extension used incorrect regular expression which…
- risk 0.00cvss 5.4epss 0.01
A stored cross-site scripting (XSS) vulnerability in LimeSurvey before and including 3.21.1 allows authenticated users with correct permissions to inject arbitrary web script or HTML via parameter ParticipantAttributeNamesDropdown of the Attributes on the central participant…
- risk 0.00cvss 6.5epss 0.01
This affects the package markdown-it-highlightjs before 3.3.1. It is possible insert malicious JavaScript as a value of lang in the markdown-it-highlightjs Inline code highlighting feature. const markdownItHighlightjs = require("markdown-it-highlightjs"); const md =…
- risk 0.00cvss 5.4epss 0.03
A cross-site scripting (XSS) vulnerability exists in templates_import.php (Cacti 1.2.13) due to Improper escaping of error message during template import preview in the xml_path field
- risk 0.00cvss 7.7epss 0.01
In BookStack before version 0.30.4, a user with permissions to edit a page could add an attached link which would execute untrusted JavaScript code when clicked by a viewer of the page. Dangerous content may remain in the database after this update. If you think this could have…
- risk 0.00cvss 7.6epss 0.01
Sal is a multi-tenanted reporting dashboard for Munki with the ability to display information from Facter. In Sal through version 4.1.6 there is an XSS vulnerability on the machine_list view.
- risk 0.00cvss 5.4epss 0.01
Cross Site Scripting (XSS) vulnerability in Gophish before 0.11.0 via the IMAP Host field on the account settings page.