CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Description
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85
CVEs mapped to this weakness (46,610)
page 2097 of 2,331| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2018-18673 | Med | 0.00 | 6.1 | 0.02 | Jul 23, 2019 | GNUBOARD5 5.3.1.9 has XSS that allows remote attackers to inject arbitrary web script or HTML via the "Menu Link" parameter, aka the adm/menu_list_update.php me_link parameter. | ||
| CVE-2018-18671 | Med | 0.00 | 6.1 | 0.02 | Jul 23, 2019 | GNUBOARD5 5.3.1.9 has XSS that allows remote attackers to inject arbitrary web script or HTML via the "mobile board head contents" parameter, aka the adm/board_form_update.php bo_mobile_content_head parameter. | ||
| CVE-2018-18669 | Med | 0.00 | 6.1 | 0.02 | Jul 23, 2019 | GNUBOARD5 5.3.1.9 has XSS that allows remote attackers to inject arbitrary web script or HTML via the "board title contents" parameter, aka the adm/board_form_update.php bo_subject parameter. | ||
| CVE-2019-1010237 | Med | 0.00 | 6.1 | 0.02 | Jul 22, 2019 | Ilias 5.3 before 5.3.12; 5.2 before 5.2.21 is affected by: Cross Site Scripting (XSS) - CWE-79 Type 2: Stored XSS (or Persistent). The impact is: Execute code in the victim's browser. The component is: Assessment / TestQuestionPool. The attack vector is: Cloze Test Text gap… | ||
| CVE-2019-1010247 | Med | 0.00 | 6.1 | 0.01 | Jul 19, 2019 | ZmartZone IAM mod_auth_openidc 2.3.10.1 and earlier is affected by: Cross Site Scripting (XSS). The impact is: Redirecting the user to a phishing page or interacting with the application on behalf of the user. The component is: File: src/mod_auth_openidc.c, Line: 3109. The fixed… | ||
| CVE-2019-1010261 | Med | 0.00 | 6.1 | 0.01 | Jul 18, 2019 | Gitea 1.7.0 and earlier is affected by: Cross Site Scripting (XSS). The impact is: Attacker is able to have victim execute arbitrary JS in browser. The component is: go-get URL generation - PR to fix: https://github.com/go-gitea/gitea/pull/5905. The attack vector is: victim must… | ||
| CVE-2019-12724 | Med | 0.00 | 6.1 | 0.01 | Jul 10, 2019 | An issue was discovered in the Teclib News plugin through 1.5.2 for GLPI. It allows a stored XSS attack via the $_POST['name'] parameter. | ||
| CVE-2019-13239 | Med | 0.00 | 6.1 | 0.01 | Jul 4, 2019 | inc/user.class.php in GLPI before 9.4.3 allows XSS via a user picture. | ||
| CVE-2019-12584 | Med | 0.00 | 6.1 | 0.03 | Jun 3, 2019 | Apcupsd 0.3.91_5, as used in pfSense through 2.4.4-RELEASE-p3 and other products, has an XSS issue in apcupsd_status.php. | ||
| CVE-2019-12566 | Med | 0.00 | 5.4 | 0.01 | Jun 3, 2019 | The WP Statistics plugin through 12.6.5 for Wordpress has stored XSS in includes/class-wp-statistics-pages.php. This is related to an account with the Editor role creating a post with a title that contains JavaScript, to attack an admin user. | ||
| CVE-2019-10325 | Med | 0.00 | 5.4 | 0.01 | May 31, 2019 | A cross-site scripting vulnerability in Jenkins Warnings NG Plugin 5.0.0 and earlier allowed attacker with Job/Configure permission to inject arbitrary JavaScript in build overview pages. | ||
| CVE-2018-20837 | Med | 0.00 | 4.8 | 0.01 | May 9, 2019 | include/admin/Menu/Ajax.php in Typesetter 5.1 has index.php/Admin/Menu/Ajax?cmd=AddHidden title XSS. | ||
| CVE-2019-10864 | Med | 0.00 | 6.1 | 0.01 | Apr 23, 2019 | The WP Statistics plugin through 12.6.2 for WordPress has XSS, allowing a remote attacker to inject arbitrary web script or HTML via the Referer header of a GET request. | ||
| CVE-2019-9841 | Med | 0.00 | 6.1 | 0.01 | Apr 19, 2019 | Vesta Control Panel 0.9.8-23 allows XSS via a crafted URL. | ||
| CVE-2019-9844 | Med | 0.00 | 6.1 | 0.01 | Apr 9, 2019 | simple-markdown.js in Khan Academy simple-markdown before 0.4.4 allows XSS via a data: or vbscript: URI. | ||
| CVE-2019-11003 | Med | 0.00 | 6.1 | 0.01 | Apr 8, 2019 | In Materialize through 1.0.0, XSS is possible via the Autocomplete feature. | ||
| CVE-2019-11002 | Med | 0.00 | 6.1 | 0.01 | Apr 8, 2019 | In Materialize through 1.0.0, XSS is possible via the Tooltip feature. | ||
| CVE-2018-20816 | Med | 0.00 | 6.1 | 0.01 | Apr 5, 2019 | An XSS combined with CSRF vulnerability discovered in SalesAgility SuiteCRM 7.x before 7.8.24 and 7.10.x before 7.10.11 leads to cookie stealing, aka session hijacking. This issue affects the "add dashboard pages" feature where users can receive a malicious attack through a… | ||
| CVE-2019-10118 | Med | 0.00 | 6.1 | 0.01 | Mar 27, 2019 | Snipe-IT before 4.6.14 has XSS, as demonstrated by log_meta values and the user's last name in the API. | ||
| CVE-2018-20737 | Med | 0.00 | 5.4 | 0.01 | Mar 21, 2019 | An issue was discovered in WSO2 API Manager 2.1.0 and 2.6.0. Reflected XSS exists in the carbon part of the product. |
- risk 0.00cvss 6.1epss 0.02
GNUBOARD5 5.3.1.9 has XSS that allows remote attackers to inject arbitrary web script or HTML via the "Menu Link" parameter, aka the adm/menu_list_update.php me_link parameter.
- risk 0.00cvss 6.1epss 0.02
GNUBOARD5 5.3.1.9 has XSS that allows remote attackers to inject arbitrary web script or HTML via the "mobile board head contents" parameter, aka the adm/board_form_update.php bo_mobile_content_head parameter.
- risk 0.00cvss 6.1epss 0.02
GNUBOARD5 5.3.1.9 has XSS that allows remote attackers to inject arbitrary web script or HTML via the "board title contents" parameter, aka the adm/board_form_update.php bo_subject parameter.
- risk 0.00cvss 6.1epss 0.02
Ilias 5.3 before 5.3.12; 5.2 before 5.2.21 is affected by: Cross Site Scripting (XSS) - CWE-79 Type 2: Stored XSS (or Persistent). The impact is: Execute code in the victim's browser. The component is: Assessment / TestQuestionPool. The attack vector is: Cloze Test Text gap…
- risk 0.00cvss 6.1epss 0.01
ZmartZone IAM mod_auth_openidc 2.3.10.1 and earlier is affected by: Cross Site Scripting (XSS). The impact is: Redirecting the user to a phishing page or interacting with the application on behalf of the user. The component is: File: src/mod_auth_openidc.c, Line: 3109. The fixed…
- risk 0.00cvss 6.1epss 0.01
Gitea 1.7.0 and earlier is affected by: Cross Site Scripting (XSS). The impact is: Attacker is able to have victim execute arbitrary JS in browser. The component is: go-get URL generation - PR to fix: https://github.com/go-gitea/gitea/pull/5905. The attack vector is: victim must…
- risk 0.00cvss 6.1epss 0.01
An issue was discovered in the Teclib News plugin through 1.5.2 for GLPI. It allows a stored XSS attack via the $_POST['name'] parameter.
- risk 0.00cvss 6.1epss 0.01
inc/user.class.php in GLPI before 9.4.3 allows XSS via a user picture.
- risk 0.00cvss 6.1epss 0.03
Apcupsd 0.3.91_5, as used in pfSense through 2.4.4-RELEASE-p3 and other products, has an XSS issue in apcupsd_status.php.
- risk 0.00cvss 5.4epss 0.01
The WP Statistics plugin through 12.6.5 for Wordpress has stored XSS in includes/class-wp-statistics-pages.php. This is related to an account with the Editor role creating a post with a title that contains JavaScript, to attack an admin user.
- risk 0.00cvss 5.4epss 0.01
A cross-site scripting vulnerability in Jenkins Warnings NG Plugin 5.0.0 and earlier allowed attacker with Job/Configure permission to inject arbitrary JavaScript in build overview pages.
- risk 0.00cvss 4.8epss 0.01
include/admin/Menu/Ajax.php in Typesetter 5.1 has index.php/Admin/Menu/Ajax?cmd=AddHidden title XSS.
- risk 0.00cvss 6.1epss 0.01
The WP Statistics plugin through 12.6.2 for WordPress has XSS, allowing a remote attacker to inject arbitrary web script or HTML via the Referer header of a GET request.
- risk 0.00cvss 6.1epss 0.01
Vesta Control Panel 0.9.8-23 allows XSS via a crafted URL.
- risk 0.00cvss 6.1epss 0.01
simple-markdown.js in Khan Academy simple-markdown before 0.4.4 allows XSS via a data: or vbscript: URI.
- risk 0.00cvss 6.1epss 0.01
In Materialize through 1.0.0, XSS is possible via the Autocomplete feature.
- risk 0.00cvss 6.1epss 0.01
In Materialize through 1.0.0, XSS is possible via the Tooltip feature.
- risk 0.00cvss 6.1epss 0.01
An XSS combined with CSRF vulnerability discovered in SalesAgility SuiteCRM 7.x before 7.8.24 and 7.10.x before 7.10.11 leads to cookie stealing, aka session hijacking. This issue affects the "add dashboard pages" feature where users can receive a malicious attack through a…
- risk 0.00cvss 6.1epss 0.01
Snipe-IT before 4.6.14 has XSS, as demonstrated by log_meta values and the user's last name in the API.
- risk 0.00cvss 5.4epss 0.01
An issue was discovered in WSO2 API Manager 2.1.0 and 2.6.0. Reflected XSS exists in the carbon part of the product.