VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (46,610)

page 2092 of 2,331
  • CVE-2020-7690MedJul 6, 2020
    risk 0.00cvss 6.1epss 0.01

    All affected versions <2.0.0 of package jspdf are vulnerable to Cross-site Scripting (XSS). It is possible to inject JavaScript code via the html method.

  • CVE-2020-15562MedJul 6, 2020
    risk 0.00cvss 6.1epss 0.02

    An issue was discovered in Roundcube Webmail before 1.2.11, 1.3.x before 1.3.14, and 1.4.x before 1.4.7. It allows XSS via a crafted HTML e-mail message, as demonstrated by a JavaScript payload in the xmlns (aka XML namespace) attribute of a HEAD element when an SVG element…

  • CVE-2020-8176MedJul 2, 2020
    risk 0.00cvss 6.1epss 0.01

    A cross-site scripting vulnerability exists in koa-shopify-auth v3.1.61-v3.1.62 that allows an attacker to inject JS payloads into the `shop` parameter on the `/shopify/auth/enable_cookies` endpoint.

  • CVE-2020-15083MedJul 2, 2020
    risk 0.00cvss 4.7epss 0.01

    In PrestaShop from version 1.7.0.0 and before version 1.7.6.6, if a target sends a corrupted file, it leads to a reflected XSS. The problem is fixed in 1.7.6.6

  • CVE-2020-11074MedJul 2, 2020
    risk 0.00cvss 5.4epss 0.01

    In PrestaShop from version 1.5.3.0 and before version 1.7.6.6, there is a stored XSS when using the name of a quick access item. The problem is fixed in 1.7.6.6.

  • CVE-2020-2206MedJul 2, 2020
    risk 0.00cvss 6.1epss 0.01

    Jenkins VncRecorder Plugin 1.25 and earlier does not escape a parameter value in the checkVncServ form validation endpoint, resulting in a reflected cross-site scripting (XSS) vulnerability.

  • CVE-2020-2205MedJul 2, 2020
    risk 0.00cvss 4.8epss 0.01

    Jenkins VncRecorder Plugin 1.25 and earlier does not escape a tool path in the `checkVncServ` form validation endpoint, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by Jenkins administrators.

  • CVE-2020-4052MedJun 16, 2020
    risk 0.00cvss 6.3epss 0.01

    In Wiki.js before 2.4.107, there is a stored cross-site scripting through template injection. This vulnerability exists due to an insecure validation mechanism intended to insert v-pre tags into rendered HTML elements which contain curly-braces. By creating a crafted wiki page,…

  • CVE-2020-13973MedJun 9, 2020
    risk 0.00cvss 6.1epss 0.01

    OWASP json-sanitizer before 1.2.1 allows XSS. An attacker who controls a substring of the input JSON, and controls another substring adjacent to a SCRIPT element in which the output is embedded as JavaScript, may be able to confuse the HTML parser as to where the SCRIPT element…

  • CVE-2020-13964MedJun 9, 2020
    risk 0.00cvss 6.1epss 0.01

    An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5. include/rcmail_output_html.php allows XSS via the username template object.

  • CVE-2020-13798MedJun 3, 2020
    risk 0.00cvss 6.1epss 0.01

    An issue was discovered in Navigate CMS through 2.8.7. It allows XSS because of a lack of purify calls in lib/packages/feeds/feed.class.php.

  • CVE-2020-13797MedJun 3, 2020
    risk 0.00cvss 6.1epss 0.01

    An issue was discovered in Navigate CMS through 2.8.7. It allows XSS because of a lack of purify calls in lib/packages/websites/website.class.php.

  • CVE-2020-13796MedJun 3, 2020
    risk 0.00cvss 6.1epss 0.01

    An issue was discovered in Navigate CMS through 2.8.7. It allows XSS because of a lack of purify calls in lib/packages/structure/structure.class.php.

  • CVE-2020-2194MedJun 3, 2020
    risk 0.00cvss 5.4epss 0.01

    Jenkins ECharts API Plugin 4.7.0-3 and earlier does not escape the display name of the builds in the trend chart, resulting in a stored cross-site scripting vulnerability.

  • CVE-2020-2193MedJun 3, 2020
    risk 0.00cvss 5.4epss 0.01

    Jenkins ECharts API Plugin 4.7.0-3 and earlier does not escape the parser identifier when rendering charts, resulting in a stored cross-site scripting vulnerability.

  • CVE-2018-18625MedJun 2, 2020
    risk 0.00cvss 6.1epss 0.01

    Grafana 5.3.1 has XSS via a link on the "Dashboard > All Panels > General" screen. NOTE: this issue exists because of an incomplete fix for CVE-2018-12099.

  • CVE-2018-18623MedJun 2, 2020
    risk 0.00cvss 6.1epss 0.02

    Grafana 5.3.1 has XSS via the "Dashboard > Text Panel" screen. NOTE: this issue exists because of an incomplete fix for CVE-2018-12099.

  • CVE-2020-13430MedMay 24, 2020
    risk 0.00cvss 6.1epss 0.02

    Grafana before 7.0.0 allows tag value XSS via the OpenTSDB datasource.

  • CVE-2020-11062MedMay 12, 2020
    risk 0.00cvss 6.0epss 0.01

    In GLPI after 0.68.1 and before 9.4.6, multiple reflexive XSS occur in Dropdown endpoints due to an invalid Content-Type. This has been fixed in version 9.4.6.

  • CVE-2020-11006CriMay 8, 2020
    risk 0.00cvss 9.1epss 0.01

    In Shopizer before version 2.11.0, a script can be injected in various forms and saved in the database, then executed when information is fetched from backend. This has been patched in version 2.11.0.