VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (46,610)

page 2097 of 2,331
  • CVE-2018-18673MedJul 23, 2019
    risk 0.00cvss 6.1epss 0.02

    GNUBOARD5 5.3.1.9 has XSS that allows remote attackers to inject arbitrary web script or HTML via the "Menu Link" parameter, aka the adm/menu_list_update.php me_link parameter.

  • CVE-2018-18671MedJul 23, 2019
    risk 0.00cvss 6.1epss 0.02

    GNUBOARD5 5.3.1.9 has XSS that allows remote attackers to inject arbitrary web script or HTML via the "mobile board head contents" parameter, aka the adm/board_form_update.php bo_mobile_content_head parameter.

  • CVE-2018-18669MedJul 23, 2019
    risk 0.00cvss 6.1epss 0.02

    GNUBOARD5 5.3.1.9 has XSS that allows remote attackers to inject arbitrary web script or HTML via the "board title contents" parameter, aka the adm/board_form_update.php bo_subject parameter.

  • CVE-2019-1010237MedJul 22, 2019
    risk 0.00cvss 6.1epss 0.02

    Ilias 5.3 before 5.3.12; 5.2 before 5.2.21 is affected by: Cross Site Scripting (XSS) - CWE-79 Type 2: Stored XSS (or Persistent). The impact is: Execute code in the victim's browser. The component is: Assessment / TestQuestionPool. The attack vector is: Cloze Test Text gap…

  • CVE-2019-1010247MedJul 19, 2019
    risk 0.00cvss 6.1epss 0.01

    ZmartZone IAM mod_auth_openidc 2.3.10.1 and earlier is affected by: Cross Site Scripting (XSS). The impact is: Redirecting the user to a phishing page or interacting with the application on behalf of the user. The component is: File: src/mod_auth_openidc.c, Line: 3109. The fixed…

  • CVE-2019-1010261MedJul 18, 2019
    risk 0.00cvss 6.1epss 0.01

    Gitea 1.7.0 and earlier is affected by: Cross Site Scripting (XSS). The impact is: Attacker is able to have victim execute arbitrary JS in browser. The component is: go-get URL generation - PR to fix: https://github.com/go-gitea/gitea/pull/5905. The attack vector is: victim must…

  • CVE-2019-12724MedJul 10, 2019
    risk 0.00cvss 6.1epss 0.01

    An issue was discovered in the Teclib News plugin through 1.5.2 for GLPI. It allows a stored XSS attack via the $_POST['name'] parameter.

  • CVE-2019-13239MedJul 4, 2019
    risk 0.00cvss 6.1epss 0.01

    inc/user.class.php in GLPI before 9.4.3 allows XSS via a user picture.

  • CVE-2019-12584MedJun 3, 2019
    risk 0.00cvss 6.1epss 0.03

    Apcupsd 0.3.91_5, as used in pfSense through 2.4.4-RELEASE-p3 and other products, has an XSS issue in apcupsd_status.php.

  • CVE-2019-12566MedJun 3, 2019
    risk 0.00cvss 5.4epss 0.01

    The WP Statistics plugin through 12.6.5 for Wordpress has stored XSS in includes/class-wp-statistics-pages.php. This is related to an account with the Editor role creating a post with a title that contains JavaScript, to attack an admin user.

  • CVE-2019-10325MedMay 31, 2019
    risk 0.00cvss 5.4epss 0.01

    A cross-site scripting vulnerability in Jenkins Warnings NG Plugin 5.0.0 and earlier allowed attacker with Job/Configure permission to inject arbitrary JavaScript in build overview pages.

  • CVE-2018-20837MedMay 9, 2019
    risk 0.00cvss 4.8epss 0.01

    include/admin/Menu/Ajax.php in Typesetter 5.1 has index.php/Admin/Menu/Ajax?cmd=AddHidden title XSS.

  • CVE-2019-10864MedApr 23, 2019
    risk 0.00cvss 6.1epss 0.01

    The WP Statistics plugin through 12.6.2 for WordPress has XSS, allowing a remote attacker to inject arbitrary web script or HTML via the Referer header of a GET request.

  • CVE-2019-9841MedApr 19, 2019
    risk 0.00cvss 6.1epss 0.01

    Vesta Control Panel 0.9.8-23 allows XSS via a crafted URL.

  • CVE-2019-9844MedApr 9, 2019
    risk 0.00cvss 6.1epss 0.01

    simple-markdown.js in Khan Academy simple-markdown before 0.4.4 allows XSS via a data: or vbscript: URI.

  • CVE-2019-11003MedApr 8, 2019
    risk 0.00cvss 6.1epss 0.01

    In Materialize through 1.0.0, XSS is possible via the Autocomplete feature.

  • CVE-2019-11002MedApr 8, 2019
    risk 0.00cvss 6.1epss 0.01

    In Materialize through 1.0.0, XSS is possible via the Tooltip feature.

  • CVE-2018-20816MedApr 5, 2019
    risk 0.00cvss 6.1epss 0.01

    An XSS combined with CSRF vulnerability discovered in SalesAgility SuiteCRM 7.x before 7.8.24 and 7.10.x before 7.10.11 leads to cookie stealing, aka session hijacking. This issue affects the "add dashboard pages" feature where users can receive a malicious attack through a…

  • CVE-2019-10118MedMar 27, 2019
    risk 0.00cvss 6.1epss 0.01

    Snipe-IT before 4.6.14 has XSS, as demonstrated by log_meta values and the user's last name in the API.

  • CVE-2018-20737MedMar 21, 2019
    risk 0.00cvss 5.4epss 0.01

    An issue was discovered in WSO2 API Manager 2.1.0 and 2.6.0. Reflected XSS exists in the carbon part of the product.