CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Description
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85
CVEs mapped to this weakness (46,610)
page 2096 of 2,331| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-14967 | Med | 0.00 | 6.1 | 0.01 | Aug 12, 2019 | An issue was discovered in Frappe Framework 10, 11 before 11.1.46, and 12. There exists an XSS vulnerability. | ||
| CVE-2018-20858 | Med | 0.00 | 6.1 | 0.01 | Aug 9, 2019 | Recommender before 2018-07-18 allows XSS. | ||
| CVE-2019-14672 | Med | 0.00 | 5.4 | 0.01 | Aug 5, 2019 | Firefly III 4.7.17.5 is vulnerable to stored XSS due to the lack of filtration of user-supplied data in the liability name field. The JavaScript code is executed upon an error condition during a visit to the account show page. | ||
| CVE-2019-14670 | Med | 0.00 | 5.4 | 0.01 | Aug 5, 2019 | Firefly III 4.7.17.3 is vulnerable to stored XSS due to the lack of filtration of user-supplied data in the bill name field. The JavaScript code is executed during rule-from-bill creation. | ||
| CVE-2019-14669 | Med | 0.00 | 5.4 | 0.01 | Aug 5, 2019 | Firefly III 4.7.17.3 is vulnerable to stored XSS due to the lack of filtration of user-supplied data in the asset account name. The JavaScript code is executed during a visit to the audit account statistics page. | ||
| CVE-2019-14668 | Med | 0.00 | 5.4 | 0.01 | Aug 5, 2019 | Firefly III 4.7.17.3 is vulnerable to stored XSS due to the lack of filtration of user-supplied data in the transaction description field. The JavaScript code is executed during deletion of a transaction link. | ||
| CVE-2019-14667 | Med | 0.00 | 6.1 | 0.01 | Aug 5, 2019 | Firefly III 4.7.17.4 is vulnerable to multiple stored XSS issues due to the lack of filtration of user-supplied data in the transaction description field and the asset account name. The JavaScript code is executed during a convert transaction action. | ||
| CVE-2019-14550 | Med | 0.00 | 5.4 | 0.01 | Aug 5, 2019 | An issue was discovered in EspoCRM before 5.6.9. Stored XSS was executed when a victim clicks on the Edit Dashboard feature present on the Homepage. An attacker can load malicious JavaScript inside the add tab list feature, which would fire when a user clicks on the Edit… | ||
| CVE-2019-14549 | Med | 0.00 | 5.4 | 0.01 | Aug 5, 2019 | An issue was discovered in EspoCRM before 5.6.9. Stored XSS was executed inside the title and breadcrumb of a newly formed entity available to all the users. A malicious user can inject JavaScript in these values of an entity, thus stealing user cookies when someone visits the… | ||
| CVE-2019-14548 | Med | 0.00 | 5.4 | 0.01 | Aug 5, 2019 | An issue was discovered in EspoCRM before 5.6.9. Stored XSS in the body of an Article was executed when a victim opens articles received through mail. This Article can be formed by an attacker using the Knowledge Base feature in the tab list. The attacker could inject malicious… | ||
| CVE-2019-14547 | Med | 0.00 | 5.4 | 0.01 | Aug 5, 2019 | An issue was discovered in EspoCRM before 5.6.9. Stored XSS was executed when a attacker sends an attachment to admin with malicious JavaScript in the filename. This JavaScript executed when an admin selects the particular file from the list of all attachments. The attacker… | ||
| CVE-2019-14546 | Med | 0.00 | 5.4 | 0.01 | Aug 5, 2019 | An issue was discovered in EspoCRM before 5.6.9. Stored XSS was executed on the Preference page as well as while sending an email when a malicious payload was inserted inside the Email Signature in the Preference page. The attacker could insert malicious JavaScript inside his… | ||
| CVE-2018-20859 | Med | 0.00 | 6.1 | 0.01 | Jul 30, 2019 | edx-platform before 2018-07-18 allows XSS via a response to a Chemical Equation advanced problem. | ||
| CVE-2019-14331 | Med | 0.00 | 6.1 | 0.01 | Jul 28, 2019 | An issue was discovered in EspoCRM before 5.6.6. Stored XSS exists due to lack of filtration of user-supplied data in Create User. A malicious attacker can modify the firstName and lastName to contain JavaScript code. | ||
| CVE-2019-14330 | Med | 0.00 | 6.1 | 0.01 | Jul 28, 2019 | An issue was discovered in EspoCRM before 5.6.6. Stored XSS exists due to lack of filtration of user-supplied data in Create Case. A malicious attacker can modify the firstName and lastName to contain JavaScript code. | ||
| CVE-2019-14329 | Med | 0.00 | 6.1 | 0.01 | Jul 28, 2019 | An issue was discovered in EspoCRM before 5.6.6. There is stored XSS due to lack of filtration of user-supplied data in Create Task. A malicious attacker can modify the parameter name to contain JavaScript code. | ||
| CVE-2018-18676 | Med | 0.00 | 6.1 | 0.02 | Jul 23, 2019 | GNUBOARD5 5.3.1.9 has XSS that allows remote attackers to inject arbitrary web script or HTML via the "mobile board tail contents" parameter, aka the adm/board_form_update.php bo_mobile_content_tail parameter. | ||
| CVE-2018-18675 | Med | 0.00 | 6.1 | 0.02 | Jul 23, 2019 | GNUBOARD5 5.3.1.9 has XSS that allows remote attackers to inject arbitrary web script or HTML via the "mobile board title contents" parameter, aka the adm/board_form_update.php bo_mobile_subject parameter. | ||
| CVE-2018-18672 | Med | 0.00 | 6.1 | 0.02 | Jul 23, 2019 | GNUBOARD5 5.3.1.9 has XSS that allows remote attackers to inject arbitrary web script or HTML via the "board head contents" parameter, aka the adm/board_form_update.php bo_content_head parameter. | ||
| CVE-2018-18670 | Med | 0.00 | 6.1 | 0.02 | Jul 23, 2019 | GNUBOARD5 5.3.1.9 has XSS that allows remote attackers to inject arbitrary web script or HTML via the "Extra Contents" parameter, aka the adm/config_form_update.php cf_1~10 parameter. |
- risk 0.00cvss 6.1epss 0.01
An issue was discovered in Frappe Framework 10, 11 before 11.1.46, and 12. There exists an XSS vulnerability.
- risk 0.00cvss 6.1epss 0.01
Recommender before 2018-07-18 allows XSS.
- risk 0.00cvss 5.4epss 0.01
Firefly III 4.7.17.5 is vulnerable to stored XSS due to the lack of filtration of user-supplied data in the liability name field. The JavaScript code is executed upon an error condition during a visit to the account show page.
- risk 0.00cvss 5.4epss 0.01
Firefly III 4.7.17.3 is vulnerable to stored XSS due to the lack of filtration of user-supplied data in the bill name field. The JavaScript code is executed during rule-from-bill creation.
- risk 0.00cvss 5.4epss 0.01
Firefly III 4.7.17.3 is vulnerable to stored XSS due to the lack of filtration of user-supplied data in the asset account name. The JavaScript code is executed during a visit to the audit account statistics page.
- risk 0.00cvss 5.4epss 0.01
Firefly III 4.7.17.3 is vulnerable to stored XSS due to the lack of filtration of user-supplied data in the transaction description field. The JavaScript code is executed during deletion of a transaction link.
- risk 0.00cvss 6.1epss 0.01
Firefly III 4.7.17.4 is vulnerable to multiple stored XSS issues due to the lack of filtration of user-supplied data in the transaction description field and the asset account name. The JavaScript code is executed during a convert transaction action.
- risk 0.00cvss 5.4epss 0.01
An issue was discovered in EspoCRM before 5.6.9. Stored XSS was executed when a victim clicks on the Edit Dashboard feature present on the Homepage. An attacker can load malicious JavaScript inside the add tab list feature, which would fire when a user clicks on the Edit…
- risk 0.00cvss 5.4epss 0.01
An issue was discovered in EspoCRM before 5.6.9. Stored XSS was executed inside the title and breadcrumb of a newly formed entity available to all the users. A malicious user can inject JavaScript in these values of an entity, thus stealing user cookies when someone visits the…
- risk 0.00cvss 5.4epss 0.01
An issue was discovered in EspoCRM before 5.6.9. Stored XSS in the body of an Article was executed when a victim opens articles received through mail. This Article can be formed by an attacker using the Knowledge Base feature in the tab list. The attacker could inject malicious…
- risk 0.00cvss 5.4epss 0.01
An issue was discovered in EspoCRM before 5.6.9. Stored XSS was executed when a attacker sends an attachment to admin with malicious JavaScript in the filename. This JavaScript executed when an admin selects the particular file from the list of all attachments. The attacker…
- risk 0.00cvss 5.4epss 0.01
An issue was discovered in EspoCRM before 5.6.9. Stored XSS was executed on the Preference page as well as while sending an email when a malicious payload was inserted inside the Email Signature in the Preference page. The attacker could insert malicious JavaScript inside his…
- risk 0.00cvss 6.1epss 0.01
edx-platform before 2018-07-18 allows XSS via a response to a Chemical Equation advanced problem.
- risk 0.00cvss 6.1epss 0.01
An issue was discovered in EspoCRM before 5.6.6. Stored XSS exists due to lack of filtration of user-supplied data in Create User. A malicious attacker can modify the firstName and lastName to contain JavaScript code.
- risk 0.00cvss 6.1epss 0.01
An issue was discovered in EspoCRM before 5.6.6. Stored XSS exists due to lack of filtration of user-supplied data in Create Case. A malicious attacker can modify the firstName and lastName to contain JavaScript code.
- risk 0.00cvss 6.1epss 0.01
An issue was discovered in EspoCRM before 5.6.6. There is stored XSS due to lack of filtration of user-supplied data in Create Task. A malicious attacker can modify the parameter name to contain JavaScript code.
- risk 0.00cvss 6.1epss 0.02
GNUBOARD5 5.3.1.9 has XSS that allows remote attackers to inject arbitrary web script or HTML via the "mobile board tail contents" parameter, aka the adm/board_form_update.php bo_mobile_content_tail parameter.
- risk 0.00cvss 6.1epss 0.02
GNUBOARD5 5.3.1.9 has XSS that allows remote attackers to inject arbitrary web script or HTML via the "mobile board title contents" parameter, aka the adm/board_form_update.php bo_mobile_subject parameter.
- risk 0.00cvss 6.1epss 0.02
GNUBOARD5 5.3.1.9 has XSS that allows remote attackers to inject arbitrary web script or HTML via the "board head contents" parameter, aka the adm/board_form_update.php bo_content_head parameter.
- risk 0.00cvss 6.1epss 0.02
GNUBOARD5 5.3.1.9 has XSS that allows remote attackers to inject arbitrary web script or HTML via the "Extra Contents" parameter, aka the adm/config_form_update.php cf_1~10 parameter.