CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Description
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85
CVEs mapped to this weakness (46,610)
page 2093 of 2,331| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-11051 | Med | 0.00 | 6.9 | 0.01 | May 5, 2020 | In Wiki.js before 2.3.81, there is a stored XSS in the Markdown editor. An editor with write access to a page, using the Markdown editor, could inject an XSS payload into the content. If another editor (with write access as well) load the same page into the Markdown editor, the… | ||
| CVE-2020-12629 | Med | 0.00 | 5.4 | 0.01 | May 4, 2020 | include/class.sla.php in osTicket before 1.14.2 allows XSS via the SLA Name. | ||
| CVE-2020-12625 | Med | 0.00 | 6.1 | 0.03 | May 4, 2020 | An issue was discovered in Roundcube Webmail before 1.4.4. There is a cross-site scripting (XSS) vulnerability in rcube_washtml.php because JavaScript code can occur in the CDATA of an HTML message. | ||
| CVE-2020-10797 | Med | 0.00 | 6.1 | 0.02 | Apr 29, 2020 | An XSS vulnerability resides in the hostname field of the diag_ping.php page in pfsense before 2.4.5 version. After passing inputs to the command and executing this command, the $result variable is not sanitized before it is printed. | ||
| CVE-2020-12113 | Med | 0.00 | 6.1 | 0.01 | Apr 23, 2020 | BigBlueButton before 2.2.4 allows XSS via closed captions because dangerouslySetInnerHTML in React is used. | ||
| CVE-2020-5286 | Med | 0.00 | 4.1 | 0.01 | Apr 20, 2020 | In PrestaShop between versions 1.7.4.0 and 1.7.6.5, there is a reflected XSS when uploading a wrong file. The problem is fixed in 1.7.6.5 | ||
| CVE-2020-5285 | Med | 0.00 | 4.1 | 0.01 | Apr 20, 2020 | In PrestaShop between versions 1.7.6.0 and 1.7.6.5, there is a reflected XSS with `back` parameter. The problem is fixed in 1.7.6.5 | ||
| CVE-2020-5278 | Med | 0.00 | 4.1 | 0.01 | Apr 20, 2020 | In PrestaShop between versions 1.5.4.0 and 1.7.6.5, there is a reflected XSS on Exception page The problem is fixed in 1.7.6.5 | ||
| CVE-2020-5276 | Med | 0.00 | 4.1 | 0.01 | Apr 20, 2020 | In PrestaShop between versions 1.7.1.0 and 1.7.6.5, there is a reflected XSS on AdminCarts page with `cartBox` parameter The problem is fixed in 1.7.6.5 | ||
| CVE-2020-5294 | Med | 0.00 | 4.1 | 0.01 | Apr 16, 2020 | PrestaShop module ps_facetedsearch versions before 2.1.0 has a reflected XSS with social networks fields The problem is fixed in 2.1.0 | ||
| CVE-2020-5283 | Low | 0.00 | 3.1 | 0.01 | Apr 3, 2020 | ViewVC before versions 1.1.28 and 1.2.1 has a XSS vulnerability in CVS show_subdir_lastmod support. The impact of this vulnerability is mitigated by the need for an attacker to have commit privileges to a CVS repository exposed by an otherwise trusted ViewVC instance that also… | ||
| CVE-2020-11499 | Med | 0.00 | 6.1 | 0.01 | Apr 2, 2020 | Firmware Analysis and Comparison Tool (FACT) 3 has Stored XSS when updating analysis details via a localhost web request, as demonstrated by mishandling of the tags and version fields in helperFunctions/mongo_task_conversion.py. | ||
| CVE-2020-5277 | Med | 0.00 | 4.1 | 0.01 | Mar 25, 2020 | PrestaShop module ps_facetedsearch versions before 3.5.0 has a reflected XSS with `url_name` parameter. The problem is fixed in 3.5.0 | ||
| CVE-2020-10790 | Med | 0.00 | 5.4 | 0.01 | Mar 25, 2020 | openITCOCKPIT before 3.7.3 has unnecessary files (such as Lodash files) under the web root, which leads to XSS. | ||
| CVE-2019-13389 | Med | 0.00 | 6.1 | 0.01 | Mar 20, 2020 | RainLoop Webmail before 1.13.0 lacks XSS protection mechanisms such as xlink:href validation, the X-XSS-Protection header, and the Content-Security-Policy header. | ||
| CVE-2019-14512 | Med | 0.00 | 6.1 | 0.01 | Mar 16, 2020 | LimeSurvey 3.17.7+190627 has XSS via Boxes in application/extensions/PanelBoxWidget/views/box.php or a label title in application/views/admin/labels/labelview_view.php. | ||
| CVE-2020-6804 | Hig | 0.00 | 8.8 | 0.01 | Feb 28, 2020 | A reflected XSS vulnerability exists within the gateway, allowing an attacker to craft a specialized URL which could steal the user's authentication token. When combined with CVE-2020-6803, an attacker could fully compromise the system. | ||
| CVE-2020-8981 | Med | 0.00 | 6.1 | 0.01 | Feb 13, 2020 | A cross-site scripting (XSS) vulnerability was discovered in the Source Integration plugin before 1.6.2 and 2.x before 2.3.1 for MantisBT. The repo_delete.php Delete Repository page allows execution of arbitrary code via a repo name (if CSP settings permit it). This is related… | ||
| CVE-2019-14652 | Med | 0.00 | 6.1 | 0.01 | Feb 13, 2020 | explorer.js in Amazon AWS JavaScript S3 Explorer (aka aws-js-s3-explorer) v2 alpha before 2019-08-02 allows XSS in certain circumstances. | ||
| CVE-2020-8498 | Med | 0.00 | 5.4 | 0.01 | Jan 30, 2020 | XSS exists in the shortcode functionality of the GistPress plugin before 3.0.2 for WordPress via the includes/class-gistpress.php id parameter. This allows an attacker with the WordPress Contributor role to execute arbitrary JavaScript code with the privileges of other users… |
- risk 0.00cvss 6.9epss 0.01
In Wiki.js before 2.3.81, there is a stored XSS in the Markdown editor. An editor with write access to a page, using the Markdown editor, could inject an XSS payload into the content. If another editor (with write access as well) load the same page into the Markdown editor, the…
- risk 0.00cvss 5.4epss 0.01
include/class.sla.php in osTicket before 1.14.2 allows XSS via the SLA Name.
- risk 0.00cvss 6.1epss 0.03
An issue was discovered in Roundcube Webmail before 1.4.4. There is a cross-site scripting (XSS) vulnerability in rcube_washtml.php because JavaScript code can occur in the CDATA of an HTML message.
- risk 0.00cvss 6.1epss 0.02
An XSS vulnerability resides in the hostname field of the diag_ping.php page in pfsense before 2.4.5 version. After passing inputs to the command and executing this command, the $result variable is not sanitized before it is printed.
- risk 0.00cvss 6.1epss 0.01
BigBlueButton before 2.2.4 allows XSS via closed captions because dangerouslySetInnerHTML in React is used.
- risk 0.00cvss 4.1epss 0.01
In PrestaShop between versions 1.7.4.0 and 1.7.6.5, there is a reflected XSS when uploading a wrong file. The problem is fixed in 1.7.6.5
- risk 0.00cvss 4.1epss 0.01
In PrestaShop between versions 1.7.6.0 and 1.7.6.5, there is a reflected XSS with `back` parameter. The problem is fixed in 1.7.6.5
- risk 0.00cvss 4.1epss 0.01
In PrestaShop between versions 1.5.4.0 and 1.7.6.5, there is a reflected XSS on Exception page The problem is fixed in 1.7.6.5
- risk 0.00cvss 4.1epss 0.01
In PrestaShop between versions 1.7.1.0 and 1.7.6.5, there is a reflected XSS on AdminCarts page with `cartBox` parameter The problem is fixed in 1.7.6.5
- risk 0.00cvss 4.1epss 0.01
PrestaShop module ps_facetedsearch versions before 2.1.0 has a reflected XSS with social networks fields The problem is fixed in 2.1.0
- risk 0.00cvss 3.1epss 0.01
ViewVC before versions 1.1.28 and 1.2.1 has a XSS vulnerability in CVS show_subdir_lastmod support. The impact of this vulnerability is mitigated by the need for an attacker to have commit privileges to a CVS repository exposed by an otherwise trusted ViewVC instance that also…
- risk 0.00cvss 6.1epss 0.01
Firmware Analysis and Comparison Tool (FACT) 3 has Stored XSS when updating analysis details via a localhost web request, as demonstrated by mishandling of the tags and version fields in helperFunctions/mongo_task_conversion.py.
- risk 0.00cvss 4.1epss 0.01
PrestaShop module ps_facetedsearch versions before 3.5.0 has a reflected XSS with `url_name` parameter. The problem is fixed in 3.5.0
- risk 0.00cvss 5.4epss 0.01
openITCOCKPIT before 3.7.3 has unnecessary files (such as Lodash files) under the web root, which leads to XSS.
- risk 0.00cvss 6.1epss 0.01
RainLoop Webmail before 1.13.0 lacks XSS protection mechanisms such as xlink:href validation, the X-XSS-Protection header, and the Content-Security-Policy header.
- risk 0.00cvss 6.1epss 0.01
LimeSurvey 3.17.7+190627 has XSS via Boxes in application/extensions/PanelBoxWidget/views/box.php or a label title in application/views/admin/labels/labelview_view.php.
- risk 0.00cvss 8.8epss 0.01
A reflected XSS vulnerability exists within the gateway, allowing an attacker to craft a specialized URL which could steal the user's authentication token. When combined with CVE-2020-6803, an attacker could fully compromise the system.
- risk 0.00cvss 6.1epss 0.01
A cross-site scripting (XSS) vulnerability was discovered in the Source Integration plugin before 1.6.2 and 2.x before 2.3.1 for MantisBT. The repo_delete.php Delete Repository page allows execution of arbitrary code via a repo name (if CSP settings permit it). This is related…
- risk 0.00cvss 6.1epss 0.01
explorer.js in Amazon AWS JavaScript S3 Explorer (aka aws-js-s3-explorer) v2 alpha before 2019-08-02 allows XSS in certain circumstances.
- risk 0.00cvss 5.4epss 0.01
XSS exists in the shortcode functionality of the GistPress plugin before 3.0.2 for WordPress via the includes/class-gistpress.php id parameter. This allows an attacker with the WordPress Contributor role to execute arbitrary JavaScript code with the privileges of other users…