VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (46,610)

page 2090 of 2,331
  • CVE-2020-24708MedOct 28, 2020
    risk 0.00cvss 5.4epss 0.01

    Cross Site Scripting (XSS) vulnerability in Gophish before 0.11.0 via the Host field on the send profile form.

  • CVE-2020-24303MedOct 28, 2020
    risk 0.00cvss 6.1epss 0.02

    Grafana before 7.1.0-beta 1 allows XSS via a query alias for the ElasticSearch datasource.

  • CVE-2020-15274MedOct 26, 2020
    risk 0.00cvss 5.8epss 0.01

    In Wiki.js before version 2.5.162, an XSS payload can be injected in a page title and executed via the search results. While the title is properly escaped in both the navigation links and the actual page title, it is not the case in the search results. Commit…

  • CVE-2020-27666MedOct 22, 2020
    risk 0.00cvss 5.4epss 0.01

    Strapi before 3.2.5 has stored XSS in the wysiwyg editor's preview feature.

  • CVE-2020-27642MedOct 22, 2020
    risk 0.00cvss 6.1epss 0.01

    A cross-site scripting (XSS) vulnerability exists in the 'merge account' functionality in admins.js in BigBlueButton Greenlight 2.7.6.

  • CVE-2020-26891MedOct 19, 2020
    risk 0.00cvss 6.1epss 0.02

    AuthRestServlet in Matrix Synapse before 1.21.0 is vulnerable to XSS due to unsafe interpolation of the session GET parameter. This allows a remote attacker to execute an XSS attack on the domain Synapse is hosted on, by supplying the victim user with a malicious URL to the…

  • CVE-2020-27163MedOct 16, 2020
    risk 0.00cvss 6.1epss 0.01

    phpRedisAdmin before 1.13.2 allows XSS via the login.php username parameter.

  • CVE-2020-15253HigOct 14, 2020
    risk 0.00cvss 7.3epss 0.01

    Versions of Grocy <= 2.7.1 are vulnerable to Cross-Site Scripting via the Create Shopping List module, that is rendered upon deleting that Shopping List. The issue was also found in users, batteries, chores, equipment, locations, quantity units, shopping locations, tasks,…

  • CVE-2020-15217MedOct 7, 2020
    risk 0.00cvss 5.3epss 0.01

    In GLPI before version 9.5.2, there is a leakage of user information through the public FAQ. The issue was introduced in version 9.5.0 and patched in 9.5.2. As a workaround, disable public access to the FAQ.

  • CVE-2020-15177HigOct 7, 2020
    risk 0.00cvss 8.0epss 0.01

    In GLPI before version 9.5.2, the `install/install.php` endpoint insecurely stores user input into the database as `url_base` and `url_base_api`. These settings are referenced throughout the application and allow for vulnerabilities like Cross-Site Scripting and Insecure…

  • CVE-2020-15231CriOct 2, 2020
    risk 0.00cvss 9.3epss 0.01

    In mapfish-print before version 3.24, a user can use the JSONP support to do a Cross-site scripting.

  • CVE-2020-26135MedOct 2, 2020
    risk 0.00cvss 6.1epss 0.01

    Live Helper Chat before 3.44v allows reflected XSS via the setsettingajax PATH_INFO.

  • CVE-2020-26134MedOct 2, 2020
    risk 0.00cvss 6.1epss 0.01

    Live Helper Chat before 3.44v allows stored XSS in chat messages with an operator via BBCode.

  • CVE-2020-15162MedSep 24, 2020
    risk 0.00cvss 5.4epss 0.01

    In PrestaShop from version 1.5.0.0 and before version 1.7.6.8, users are allowed to send compromised files. These attachments allowed people to input malicious JavaScript which triggered an XSS payload. The problem is fixed in version 1.7.6.8.

  • CVE-2020-15161MedSep 24, 2020
    risk 0.00cvss 5.4epss 0.01

    In PrestaShop from version 1.6.0.4 and before version 1.7.6.8 an attacker is able to inject javascript while using the contact form. The problem is fixed in 1.7.6.8

  • CVE-2020-15183HigSep 17, 2020
    risk 0.00cvss 8.4epss 0.02

    SoyCMS 3.0.2 and earlier is affected by Reflected Cross-Site Scripting (XSS) which leads to Remote Code Execution (RCE) from a known vulnerability. This allows remote attackers to force the administrator to edit files once the adminsitrator loads a specially crafted webpage.

  • CVE-2020-25729MedSep 17, 2020
    risk 0.00cvss 6.1epss 0.01

    ZoneMinder before 1.34.21 has XSS via the connkey parameter to download.php or export.php.

  • CVE-2020-15179HigSep 15, 2020
    risk 0.00cvss 8.0epss 0.01

    The ScratchSig extension for MediaWiki before version 1.0.1 allows stored Cross-Site Scripting. Using tag inside tag, attackers with edit permission can execute scripts on visitors' browser. With MediaWiki JavaScript API, this can potentially lead to…

  • CVE-2020-12058MedSep 3, 2020
    risk 0.00cvss 6.1epss 0.01

    Several XSS vulnerabilities in osCommerce CE Phoenix before 1.0.6.0 allow an attacker to inject and execute arbitrary JavaScript code. The malicious code can be injected as follows: the page parameter to catalog/admin/order_status.php, catalog/admin/tax_rates.php,…

  • CVE-2020-25093MedSep 3, 2020
    risk 0.00cvss 6.1epss 0.01

    Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in blog.php. within application/views/templates/clothesshop, application/views/templates/onepage, and application/views/templates/redlabel.