VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (46,610)

page 2089 of 2,331
  • CVE-2019-25015MedJan 26, 2021
    risk 0.00cvss 5.4epss 0.01

    LuCI in OpenWrt 18.06.0 through 18.06.4 allows stored XSS via a crafted SSID.

  • CVE-2021-21259HigJan 22, 2021
    risk 0.00cvss 7.4epss 0.01

    HedgeDoc is open source software which lets you create real-time collaborative markdown notes. In HedgeDoc before version 1.7.2, an attacker can inject arbitrary JavaScript into a HedgeDoc note, which is executed when the note is viewed in slide mode. Depending on the…

  • CVE-2020-28470HigJan 14, 2021
    risk 0.00cvss 7.3epss 0.01

    This affects the package @scullyio/scully before 1.0.9. The transfer state is serialised with the JSON.stringify() function and then written into the HTML page.

  • CVE-2020-25799MedDec 31, 2020
    risk 0.00cvss 5.4epss 0.01

    LimeSurvey 3.21.1 is affected by cross-site scripting (XSS) in the Quota component of the Survey page. When the survey quota being viewed, e.g. by an administrative user, the JavaScript code will be executed in the browser.

  • CVE-2020-25797MedDec 31, 2020
    risk 0.00cvss 5.4epss 0.01

    LimeSurvey 3.21.1 is affected by cross-site scripting (XSS) in the Add Participants Function (First and last name parameters). When the survey participant being edited, e.g. by an administrative user, the JavaScript code will be executed in the browser.

  • CVE-2020-26296HigDec 30, 2020
    risk 0.00cvss 8.7epss 0.02

    Vega is a visualization grammar, a declarative format for creating, saving, and sharing interactive visualization designs. Vega in an npm package. In Vega before version 5.17.3 there is an XSS vulnerability in Vega expressions. Through a specially crafted Vega expression, an…

  • CVE-2020-26287HigDec 29, 2020
    risk 0.00cvss 8.7epss 0.01

    HedgeDoc is a collaborative platform for writing and sharing markdown. In HedgeDoc before version 1.7.1 an attacker can inject arbitrary `script` tags in HedgeDoc notes using mermaid diagrams. Our content security policy prevents loading scripts from most locations, but…

  • CVE-2020-35659MedDec 24, 2020
    risk 0.00cvss 6.1epss 0.01

    The DNS query log in Pi-hole before 5.2.2 is vulnerable to stored XSS. An attacker with the ability to directly or indirectly query DNS with a malicious hostname can cause arbitrary JavaScript to execute when the Pi-hole administrator visits the Query Log or Long-term data Query…

  • CVE-2020-26280HigDec 18, 2020
    risk 0.00cvss 8.9epss 0.01

    OpenSlides is a free, Web-based presentation and assembly system for managing and projecting agenda, motions, and elections of assemblies. OpenSlides version 3.2, due to unsufficient user input validation and escaping, it is vulnerable to persistant cross-site scripting (XSS).…

  • CVE-2020-28457HigDec 15, 2020
    risk 0.00cvss 7.2epss 0.01

    This affects the package s-cart/core before 4.4. The search functionality of the admin dashboard in core/src/Admin/Controllers/AdminOrderController.phpindex is vulnerable to XSS.

  • CVE-2020-28456HigDec 15, 2020
    risk 0.00cvss 7.3epss 0.01

    The package s-cart/core before 4.4 are vulnerable to Cross-site Scripting (XSS) via the admin panel.

  • CVE-2020-35132MedDec 11, 2020
    risk 0.00cvss 5.4epss 0.01

    An XSS issue has been discovered in phpLDAPadmin before 1.2.6.2 that allows users to store malicious values that may be executed by other users at a later time via get_request in lib/function.php.

  • CVE-2020-27409MedDec 4, 2020
    risk 0.00cvss 6.1epss 0.01

    OpenSIS Community Edition before 7.5 is affected by a cross-site scripting (XSS) vulnerability in SideForStudent.php via the modname parameter.

  • CVE-2020-26239HigNov 23, 2020
    risk 0.00cvss 7.6epss 0.01

    Scratch Addons is a WebExtension that supports both Chrome and Firefox. Scratch Addons before version 1.3.2 is vulnerable to DOM-based XSS. If the victim visited a specific website, the More Links addon of the Scratch Addons extension used incorrect regular expression which…

  • CVE-2020-25798MedNov 17, 2020
    risk 0.00cvss 5.4epss 0.01

    A stored cross-site scripting (XSS) vulnerability in LimeSurvey before and including 3.21.1 allows authenticated users with correct permissions to inject arbitrary web script or HTML via parameter ParticipantAttributeNamesDropdown of the Attributes on the central participant…

  • CVE-2020-7773MedNov 16, 2020
    risk 0.00cvss 6.5epss 0.01

    This affects the package markdown-it-highlightjs before 3.3.1. It is possible insert malicious JavaScript as a value of lang in the markdown-it-highlightjs Inline code highlighting feature. const markdownItHighlightjs = require("markdown-it-highlightjs"); const md =…

  • CVE-2020-25706MedNov 12, 2020
    risk 0.00cvss 5.4epss 0.03

    A cross-site scripting (XSS) vulnerability exists in templates_import.php (Cacti 1.2.13) due to Improper escaping of error message during template import preview in the xml_path field

  • CVE-2020-26210HigNov 3, 2020
    risk 0.00cvss 7.7epss 0.01

    In BookStack before version 0.30.4, a user with permissions to edit a page could add an attached link which would execute untrusted JavaScript code when clicked by a viewer of the page. Dangerous content may remain in the database after this update. If you think this could have…

  • CVE-2020-26205HigOct 29, 2020
    risk 0.00cvss 7.6epss 0.01

    Sal is a multi-tenanted reporting dashboard for Munki with the ability to display information from Facter. In Sal through version 4.1.6 there is an XSS vulnerability on the machine_list view.

  • CVE-2020-24712MedOct 28, 2020
    risk 0.00cvss 5.4epss 0.01

    Cross Site Scripting (XSS) vulnerability in Gophish before 0.11.0 via the IMAP Host field on the account settings page.