CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Description
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85
CVEs mapped to this weakness (46,610)
page 2090 of 2,331| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-24708 | Med | 0.00 | 5.4 | 0.01 | Oct 28, 2020 | Cross Site Scripting (XSS) vulnerability in Gophish before 0.11.0 via the Host field on the send profile form. | ||
| CVE-2020-24303 | Med | 0.00 | 6.1 | 0.02 | Oct 28, 2020 | Grafana before 7.1.0-beta 1 allows XSS via a query alias for the ElasticSearch datasource. | ||
| CVE-2020-15274 | Med | 0.00 | 5.8 | 0.01 | Oct 26, 2020 | In Wiki.js before version 2.5.162, an XSS payload can be injected in a page title and executed via the search results. While the title is properly escaped in both the navigation links and the actual page title, it is not the case in the search results. Commit… | ||
| CVE-2020-27666 | Med | 0.00 | 5.4 | 0.01 | Oct 22, 2020 | Strapi before 3.2.5 has stored XSS in the wysiwyg editor's preview feature. | ||
| CVE-2020-27642 | Med | 0.00 | 6.1 | 0.01 | Oct 22, 2020 | A cross-site scripting (XSS) vulnerability exists in the 'merge account' functionality in admins.js in BigBlueButton Greenlight 2.7.6. | ||
| CVE-2020-26891 | Med | 0.00 | 6.1 | 0.02 | Oct 19, 2020 | AuthRestServlet in Matrix Synapse before 1.21.0 is vulnerable to XSS due to unsafe interpolation of the session GET parameter. This allows a remote attacker to execute an XSS attack on the domain Synapse is hosted on, by supplying the victim user with a malicious URL to the… | ||
| CVE-2020-27163 | Med | 0.00 | 6.1 | 0.01 | Oct 16, 2020 | phpRedisAdmin before 1.13.2 allows XSS via the login.php username parameter. | ||
| CVE-2020-15253 | Hig | 0.00 | 7.3 | 0.01 | Oct 14, 2020 | Versions of Grocy <= 2.7.1 are vulnerable to Cross-Site Scripting via the Create Shopping List module, that is rendered upon deleting that Shopping List. The issue was also found in users, batteries, chores, equipment, locations, quantity units, shopping locations, tasks,… | ||
| CVE-2020-15217 | Med | 0.00 | 5.3 | 0.01 | Oct 7, 2020 | In GLPI before version 9.5.2, there is a leakage of user information through the public FAQ. The issue was introduced in version 9.5.0 and patched in 9.5.2. As a workaround, disable public access to the FAQ. | ||
| CVE-2020-15177 | Hig | 0.00 | 8.0 | 0.01 | Oct 7, 2020 | In GLPI before version 9.5.2, the `install/install.php` endpoint insecurely stores user input into the database as `url_base` and `url_base_api`. These settings are referenced throughout the application and allow for vulnerabilities like Cross-Site Scripting and Insecure… | ||
| CVE-2020-15231 | Cri | 0.00 | 9.3 | 0.01 | Oct 2, 2020 | In mapfish-print before version 3.24, a user can use the JSONP support to do a Cross-site scripting. | ||
| CVE-2020-26135 | Med | 0.00 | 6.1 | 0.01 | Oct 2, 2020 | Live Helper Chat before 3.44v allows reflected XSS via the setsettingajax PATH_INFO. | ||
| CVE-2020-26134 | Med | 0.00 | 6.1 | 0.01 | Oct 2, 2020 | Live Helper Chat before 3.44v allows stored XSS in chat messages with an operator via BBCode. | ||
| CVE-2020-15162 | Med | 0.00 | 5.4 | 0.01 | Sep 24, 2020 | In PrestaShop from version 1.5.0.0 and before version 1.7.6.8, users are allowed to send compromised files. These attachments allowed people to input malicious JavaScript which triggered an XSS payload. The problem is fixed in version 1.7.6.8. | ||
| CVE-2020-15161 | Med | 0.00 | 5.4 | 0.01 | Sep 24, 2020 | In PrestaShop from version 1.6.0.4 and before version 1.7.6.8 an attacker is able to inject javascript while using the contact form. The problem is fixed in 1.7.6.8 | ||
| CVE-2020-15183 | Hig | 0.00 | 8.4 | 0.02 | Sep 17, 2020 | SoyCMS 3.0.2 and earlier is affected by Reflected Cross-Site Scripting (XSS) which leads to Remote Code Execution (RCE) from a known vulnerability. This allows remote attackers to force the administrator to edit files once the adminsitrator loads a specially crafted webpage. | ||
| CVE-2020-25729 | Med | 0.00 | 6.1 | 0.01 | Sep 17, 2020 | ZoneMinder before 1.34.21 has XSS via the connkey parameter to download.php or export.php. | ||
| CVE-2020-15179 | Hig | 0.00 | 8.0 | 0.01 | Sep 15, 2020 | The ScratchSig extension for MediaWiki before version 1.0.1 allows stored Cross-Site Scripting. Using tag inside tag, attackers with edit permission can execute scripts on visitors' browser. With MediaWiki JavaScript API, this can potentially lead to… | ||
| CVE-2020-12058 | Med | 0.00 | 6.1 | 0.01 | Sep 3, 2020 | Several XSS vulnerabilities in osCommerce CE Phoenix before 1.0.6.0 allow an attacker to inject and execute arbitrary JavaScript code. The malicious code can be injected as follows: the page parameter to catalog/admin/order_status.php, catalog/admin/tax_rates.php,… | ||
| CVE-2020-25093 | Med | 0.00 | 6.1 | 0.01 | Sep 3, 2020 | Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in blog.php. within application/views/templates/clothesshop, application/views/templates/onepage, and application/views/templates/redlabel. |
- risk 0.00cvss 5.4epss 0.01
Cross Site Scripting (XSS) vulnerability in Gophish before 0.11.0 via the Host field on the send profile form.
- risk 0.00cvss 6.1epss 0.02
Grafana before 7.1.0-beta 1 allows XSS via a query alias for the ElasticSearch datasource.
- risk 0.00cvss 5.8epss 0.01
In Wiki.js before version 2.5.162, an XSS payload can be injected in a page title and executed via the search results. While the title is properly escaped in both the navigation links and the actual page title, it is not the case in the search results. Commit…
- risk 0.00cvss 5.4epss 0.01
Strapi before 3.2.5 has stored XSS in the wysiwyg editor's preview feature.
- risk 0.00cvss 6.1epss 0.01
A cross-site scripting (XSS) vulnerability exists in the 'merge account' functionality in admins.js in BigBlueButton Greenlight 2.7.6.
- risk 0.00cvss 6.1epss 0.02
AuthRestServlet in Matrix Synapse before 1.21.0 is vulnerable to XSS due to unsafe interpolation of the session GET parameter. This allows a remote attacker to execute an XSS attack on the domain Synapse is hosted on, by supplying the victim user with a malicious URL to the…
- risk 0.00cvss 6.1epss 0.01
phpRedisAdmin before 1.13.2 allows XSS via the login.php username parameter.
- risk 0.00cvss 7.3epss 0.01
Versions of Grocy <= 2.7.1 are vulnerable to Cross-Site Scripting via the Create Shopping List module, that is rendered upon deleting that Shopping List. The issue was also found in users, batteries, chores, equipment, locations, quantity units, shopping locations, tasks,…
- risk 0.00cvss 5.3epss 0.01
In GLPI before version 9.5.2, there is a leakage of user information through the public FAQ. The issue was introduced in version 9.5.0 and patched in 9.5.2. As a workaround, disable public access to the FAQ.
- risk 0.00cvss 8.0epss 0.01
In GLPI before version 9.5.2, the `install/install.php` endpoint insecurely stores user input into the database as `url_base` and `url_base_api`. These settings are referenced throughout the application and allow for vulnerabilities like Cross-Site Scripting and Insecure…
- risk 0.00cvss 9.3epss 0.01
In mapfish-print before version 3.24, a user can use the JSONP support to do a Cross-site scripting.
- risk 0.00cvss 6.1epss 0.01
Live Helper Chat before 3.44v allows reflected XSS via the setsettingajax PATH_INFO.
- risk 0.00cvss 6.1epss 0.01
Live Helper Chat before 3.44v allows stored XSS in chat messages with an operator via BBCode.
- risk 0.00cvss 5.4epss 0.01
In PrestaShop from version 1.5.0.0 and before version 1.7.6.8, users are allowed to send compromised files. These attachments allowed people to input malicious JavaScript which triggered an XSS payload. The problem is fixed in version 1.7.6.8.
- risk 0.00cvss 5.4epss 0.01
In PrestaShop from version 1.6.0.4 and before version 1.7.6.8 an attacker is able to inject javascript while using the contact form. The problem is fixed in 1.7.6.8
- risk 0.00cvss 8.4epss 0.02
SoyCMS 3.0.2 and earlier is affected by Reflected Cross-Site Scripting (XSS) which leads to Remote Code Execution (RCE) from a known vulnerability. This allows remote attackers to force the administrator to edit files once the adminsitrator loads a specially crafted webpage.
- risk 0.00cvss 6.1epss 0.01
ZoneMinder before 1.34.21 has XSS via the connkey parameter to download.php or export.php.
- risk 0.00cvss 8.0epss 0.01
The ScratchSig extension for MediaWiki before version 1.0.1 allows stored Cross-Site Scripting. Using tag inside tag, attackers with edit permission can execute scripts on visitors' browser. With MediaWiki JavaScript API, this can potentially lead to…
- risk 0.00cvss 6.1epss 0.01
Several XSS vulnerabilities in osCommerce CE Phoenix before 1.0.6.0 allow an attacker to inject and execute arbitrary JavaScript code. The malicious code can be injected as follows: the page parameter to catalog/admin/order_status.php, catalog/admin/tax_rates.php,…
- risk 0.00cvss 6.1epss 0.01
Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in blog.php. within application/views/templates/clothesshop, application/views/templates/onepage, and application/views/templates/redlabel.