VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (46,610)

page 2091 of 2,331
  • CVE-2020-25092MedSep 3, 2020
    risk 0.00cvss 6.1epss 0.01

    Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in _parts/header.php, within application/views/templates/clothesshop, application/views/templates/greenlabel, and application/views/templates/redlabel.

  • CVE-2020-25091MedSep 3, 2020
    risk 0.00cvss 6.1epss 0.01

    Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in application/modules/vendor/views/add_product.php.

  • CVE-2020-25090MedSep 3, 2020
    risk 0.00cvss 6.1epss 0.01

    Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in application/modules/admin/views/ecommerce/publish.php.

  • CVE-2020-25089MedSep 3, 2020
    risk 0.00cvss 6.1epss 0.01

    Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in application/modules/admin/views/ecommerce/discounts.php.

  • CVE-2020-25088MedSep 3, 2020
    risk 0.00cvss 6.1epss 0.01

    Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in application/modules/admin/views/blog/blogpublish.php.

  • CVE-2020-25087MedSep 3, 2020
    risk 0.00cvss 6.1epss 0.01

    Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in application/modules/admin/views/advanced_settings/languages.php.

  • CVE-2020-25086MedSep 3, 2020
    risk 0.00cvss 6.1epss 0.01

    Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in application/modules/admin/views/advanced_settings/adminUsers.php.

  • CVE-2020-24390MedAug 27, 2020
    risk 0.00cvss 6.1epss 0.01

    eonweb in EyesOfNetwork before 5.3-7 does not properly escape the username on the /module/admin_logs page, which might allow pre-authentication stored XSS during login/logout logs recording.

  • CVE-2020-15926MedAug 18, 2020
    risk 0.00cvss 6.1epss 0.03

    Rocket.Chat through 3.4.2 allows XSS where an attacker can send a specially crafted message to a channel or in a direct message to the client which results in remote code execution on the client side.

  • CVE-2019-7410MedAug 14, 2020
    risk 0.00cvss 6.1epss 0.01

    There is stored cross site scripting (XSS) in Galileo CMS v0.042. Remote authenticated users could inject arbitrary web script or HTML via $page_title in /lib/Galileo/files/templates/page/show.html.ep (aka the PAGE TITLE Field).

  • CVE-2020-13278MedAug 12, 2020
    risk 0.00cvss 6.1epss 0.01

    Reflected Cross-Site Scripting vulnerability in Modules.php in RosarioSIS Student Information System < 6.5.1 allows remote attackers to execute arbitrary web script via embedding javascript or HTML tags in a GET request.

  • CVE-2020-16145MedAug 12, 2020
    risk 0.00cvss 6.1epss 0.02

    Roundcube Webmail before 1.3.15 and 1.4.8 allows stored XSS in HTML messages during message display via a crafted SVG document. This issue has been fixed in 1.4.8 and 1.3.15.

  • CVE-2020-15139HigAug 10, 2020
    risk 0.00cvss 8.8epss 0.01

    In MyBB before version 1.8.24, the custom MyCode (BBCode) for the visual editor doesn't escape input properly when rendering HTML, resulting in a DOM-based XSS vulnerability. The weakness can be exploited by pointing a victim to a page where the visual editor is active (e.g. as…

  • CVE-2020-17476MedAug 10, 2020
    risk 0.00cvss 6.1epss 0.01

    Mibew Messenger before 3.2.7 allows XSS via a crafted user name.

  • CVE-2020-15138HigAug 7, 2020
    risk 0.00cvss 7.1epss 0.02

    Prism is vulnerable to Cross-Site Scripting. The easing preview of the Previewers plugin has an XSS vulnerability that allows attackers to execute arbitrary code in Safari and Internet Explorer. This impacts all Safari and Internet Explorer users of Prism >=v1.1.0 that use the…

  • CVE-2020-16192MedAug 5, 2020
    risk 0.00cvss 6.1epss 0.01

    LimeSurvey 4.3.2 allows reflected XSS because application/controllers/LSBaseController.php lacks code to validate parameters.

  • CVE-2020-16131MedAug 3, 2020
    risk 0.00cvss 6.1epss 0.01

    Tiki before 21.2 allows XSS because [\s\/"\'] is not properly considered in lib/core/TikiFilter/PreventXss.php.

  • CVE-2020-6506MedJul 22, 2020
    risk 0.00cvss 6.5epss 0.04

    Insufficient policy enforcement in WebView in Google Chrome on Android prior to 83.0.4103.106 allowed a remote attacker to bypass site isolation via a crafted HTML page.

  • CVE-2020-15717MedJul 15, 2020
    risk 0.00cvss 6.1epss 0.02

    RosarioSIS 6.7.2 is vulnerable to XSS, caused by improper validation of user-supplied input by the Search.inc.php script. A remote attacker could exploit this vulnerability using the advanced parameter in a crafted URL.

  • CVE-2020-15721MedJul 14, 2020
    risk 0.00cvss 6.1epss 0.01

    RosarioSIS through 6.8-beta allows modules/Custom/NotifyParents.php XSS because of the href attributes for AddStudents.php and User.php.