CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Description
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85
CVEs mapped to this weakness (46,610)
page 2094 of 2,331| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-1933 | Med | 0.00 | 6.1 | 0.03 | Jan 28, 2020 | A XSS vulnerability was found in Apache NiFi 1.0.0 to 1.10.0. Malicious scripts could be injected to the UI through action by an unaware authenticated user in Firefox. Did not appear to occur in other browsers. | ||
| CVE-2019-19858 | Med | 0.00 | 4.8 | 0.01 | Jan 15, 2020 | An issue was discovered in Serpico (aka SimplE RePort wrIting and CollaboratiOn tool) 1.3.0. admin/add_user/UID allows stored XSS via the author parameter. | ||
| CVE-2019-19856 | Med | 0.00 | 4.8 | 0.01 | Jan 15, 2020 | An issue was discovered in Serpico (aka SimplE RePort wrIting and CollaboratiOn tool) 1.3.0. The User Type on the admin/list_user page allows stored XSS via the type parameter. | ||
| CVE-2019-19855 | Med | 0.00 | 4.8 | 0.01 | Jan 15, 2020 | An issue was discovered in Serpico (aka SimplE RePort wrIting and CollaboratiOn tool) 1.3.0. admin/list_user allows stored XSS via the auth_type parameter. | ||
| CVE-2020-6847 | Med | 0.00 | 5.4 | 0.01 | Jan 11, 2020 | OpenTrade through 0.2.0 has a DOM-based XSS vulnerability that is executed when an administrator attempts to delete a message that contains JavaScript. | ||
| CVE-2019-20374 | Cri | 0.00 | 9.6 | 0.02 | Jan 9, 2020 | A mutation cross-site scripting (XSS) issue in Typora through 0.9.9.31.2 on macOS and through 0.9.81 on Linux leads to Remote Code Execution through Mermaid code blocks. To exploit this vulnerability, one must open a file in Typora. The XSS vulnerability is then triggered due to… | ||
| CVE-2020-6632 | Med | 0.00 | 6.1 | 0.01 | Jan 9, 2020 | In PrestaShop 1.7.6.2, XSS can occur during addition or removal of a QuickAccess link. This is related to AdminQuickAccessesController.php, themes/default/template/header.tpl, and themes/new-theme/js/header.js. | ||
| CVE-2019-20365 | Med | 0.00 | 6.1 | 0.01 | Jan 8, 2020 | An XSS issue was discovered in Ignite Realtime Openfire 4.4.4 via search to the Users/Group search page. | ||
| CVE-2019-20364 | Med | 0.00 | 6.1 | 0.01 | Jan 8, 2020 | An XSS issue was discovered in Ignite Realtime Openfire 4.4.4 via cacheName to SystemCacheDetails.jsp. | ||
| CVE-2019-20363 | Med | 0.00 | 6.1 | 0.01 | Jan 8, 2020 | An XSS issue was discovered in Ignite Realtime Openfire 4.4.4 via alias to Manage Store Contents. | ||
| CVE-2020-5497 | Med | 0.00 | 6.1 | 0.02 | Jan 4, 2020 | The OpenID Connect reference implementation for MITREid Connect through 1.3.3 allows XSS due to userInfoJson being included in the page unsanitized. This is related to header.tag. The issue can be exploited to execute arbitrary JavaScript. | ||
| CVE-2019-20042 | Med | 0.00 | 6.1 | 0.03 | Dec 27, 2019 | In wp-includes/formatting.php in WordPress 3.7 to 5.3.0, the function wp_targeted_link_rel() can be used in a particular way to result in a stored cross-site scripting (XSS) vulnerability. This has been patched in WordPress 5.3.1, along with all the previous WordPress versions… | ||
| CVE-2019-19388 | Med | 0.00 | 6.1 | 0.01 | Nov 29, 2019 | A cross-site scripting (XSS) vulnerability in app/dialplans/dialplan_detail_edit.php in FusionPBX 4.4.1 allows remote attackers to inject arbitrary web script or HTML via the dialplan_uuid parameter. | ||
| CVE-2019-19387 | Med | 0.00 | 6.1 | 0.01 | Nov 29, 2019 | A cross-site scripting (XSS) vulnerability in app/fifo_list/fifo_interactive.php in FusionPBX 4.4.1 allows remote attackers to inject arbitrary web script or HTML via the c parameter. | ||
| CVE-2019-19386 | Med | 0.00 | 6.1 | 0.01 | Nov 29, 2019 | A cross-site scripting (XSS) vulnerability in app/voicemail_greetings/voicemail_greeting_edit.php in FusionPBX 4.4.1 allows remote attackers to inject arbitrary web script or HTML via the id and/or voicemail_id parameter. | ||
| CVE-2019-19385 | Med | 0.00 | 6.1 | 0.01 | Nov 29, 2019 | A cross-site scripting (XSS) vulnerability in app/dialplans/dialplans.php in FusionPBX 4.4.1 allows remote attackers to inject arbitrary web script or HTML via the app_uuid parameter. | ||
| CVE-2019-19384 | Med | 0.00 | 6.1 | 0.01 | Nov 29, 2019 | A cross-site scripting (XSS) vulnerability in app/fax/fax_log_view.php in FusionPBX 4.4.1 allows remote attackers to inject arbitrary web script or HTML via the fax_uuid parameter. | ||
| CVE-2019-19367 | Med | 0.00 | 6.1 | 0.01 | Nov 27, 2019 | A cross-site scripting (XSS) vulnerability in app/fax/fax_files.php in FusionPBX 4.4.1 allows remote attackers to inject arbitrary web script or HTML via the id parameter. | ||
| CVE-2019-19366 | Med | 0.00 | 6.1 | 0.01 | Nov 27, 2019 | A cross-site scripting (XSS) vulnerability in app/xml_cdr/xml_cdr_search.php in FusionPBX 4.4.1 allows remote attackers to inject arbitrary web script or HTML via the redirect parameter. | ||
| CVE-2019-19040 | Med | 0.00 | 6.1 | 0.01 | Nov 17, 2019 | KairosDB through 1.2.2 has XSS in view.html because of showErrorMessage in js/graph.js, as demonstrated by view.html?q= with a '"sampling":{"value":"' substring. |
- risk 0.00cvss 6.1epss 0.03
A XSS vulnerability was found in Apache NiFi 1.0.0 to 1.10.0. Malicious scripts could be injected to the UI through action by an unaware authenticated user in Firefox. Did not appear to occur in other browsers.
- risk 0.00cvss 4.8epss 0.01
An issue was discovered in Serpico (aka SimplE RePort wrIting and CollaboratiOn tool) 1.3.0. admin/add_user/UID allows stored XSS via the author parameter.
- risk 0.00cvss 4.8epss 0.01
An issue was discovered in Serpico (aka SimplE RePort wrIting and CollaboratiOn tool) 1.3.0. The User Type on the admin/list_user page allows stored XSS via the type parameter.
- risk 0.00cvss 4.8epss 0.01
An issue was discovered in Serpico (aka SimplE RePort wrIting and CollaboratiOn tool) 1.3.0. admin/list_user allows stored XSS via the auth_type parameter.
- risk 0.00cvss 5.4epss 0.01
OpenTrade through 0.2.0 has a DOM-based XSS vulnerability that is executed when an administrator attempts to delete a message that contains JavaScript.
- risk 0.00cvss 9.6epss 0.02
A mutation cross-site scripting (XSS) issue in Typora through 0.9.9.31.2 on macOS and through 0.9.81 on Linux leads to Remote Code Execution through Mermaid code blocks. To exploit this vulnerability, one must open a file in Typora. The XSS vulnerability is then triggered due to…
- risk 0.00cvss 6.1epss 0.01
In PrestaShop 1.7.6.2, XSS can occur during addition or removal of a QuickAccess link. This is related to AdminQuickAccessesController.php, themes/default/template/header.tpl, and themes/new-theme/js/header.js.
- risk 0.00cvss 6.1epss 0.01
An XSS issue was discovered in Ignite Realtime Openfire 4.4.4 via search to the Users/Group search page.
- risk 0.00cvss 6.1epss 0.01
An XSS issue was discovered in Ignite Realtime Openfire 4.4.4 via cacheName to SystemCacheDetails.jsp.
- risk 0.00cvss 6.1epss 0.01
An XSS issue was discovered in Ignite Realtime Openfire 4.4.4 via alias to Manage Store Contents.
- risk 0.00cvss 6.1epss 0.02
The OpenID Connect reference implementation for MITREid Connect through 1.3.3 allows XSS due to userInfoJson being included in the page unsanitized. This is related to header.tag. The issue can be exploited to execute arbitrary JavaScript.
- risk 0.00cvss 6.1epss 0.03
In wp-includes/formatting.php in WordPress 3.7 to 5.3.0, the function wp_targeted_link_rel() can be used in a particular way to result in a stored cross-site scripting (XSS) vulnerability. This has been patched in WordPress 5.3.1, along with all the previous WordPress versions…
- risk 0.00cvss 6.1epss 0.01
A cross-site scripting (XSS) vulnerability in app/dialplans/dialplan_detail_edit.php in FusionPBX 4.4.1 allows remote attackers to inject arbitrary web script or HTML via the dialplan_uuid parameter.
- risk 0.00cvss 6.1epss 0.01
A cross-site scripting (XSS) vulnerability in app/fifo_list/fifo_interactive.php in FusionPBX 4.4.1 allows remote attackers to inject arbitrary web script or HTML via the c parameter.
- risk 0.00cvss 6.1epss 0.01
A cross-site scripting (XSS) vulnerability in app/voicemail_greetings/voicemail_greeting_edit.php in FusionPBX 4.4.1 allows remote attackers to inject arbitrary web script or HTML via the id and/or voicemail_id parameter.
- risk 0.00cvss 6.1epss 0.01
A cross-site scripting (XSS) vulnerability in app/dialplans/dialplans.php in FusionPBX 4.4.1 allows remote attackers to inject arbitrary web script or HTML via the app_uuid parameter.
- risk 0.00cvss 6.1epss 0.01
A cross-site scripting (XSS) vulnerability in app/fax/fax_log_view.php in FusionPBX 4.4.1 allows remote attackers to inject arbitrary web script or HTML via the fax_uuid parameter.
- risk 0.00cvss 6.1epss 0.01
A cross-site scripting (XSS) vulnerability in app/fax/fax_files.php in FusionPBX 4.4.1 allows remote attackers to inject arbitrary web script or HTML via the id parameter.
- risk 0.00cvss 6.1epss 0.01
A cross-site scripting (XSS) vulnerability in app/xml_cdr/xml_cdr_search.php in FusionPBX 4.4.1 allows remote attackers to inject arbitrary web script or HTML via the redirect parameter.
- risk 0.00cvss 6.1epss 0.01
KairosDB through 1.2.2 has XSS in view.html because of showErrorMessage in js/graph.js, as demonstrated by view.html?q= with a '"sampling":{"value":"' substring.