VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (46,610)

page 2098 of 2,331
  • CVE-2018-20736MedMar 21, 2019
    risk 0.00cvss 5.4epss 0.01

    An issue was discovered in WSO2 API Manager 2.1.0 and 2.6.0. A DOM-based XSS exists in the store part of the product.

  • CVE-2018-20140MedMar 21, 2019
    risk 0.00cvss 6.1epss 0.02

    Zenphoto 1.4.14 has multiple cross-site scripting (XSS) vulnerabilities via different URL parameters.

  • CVE-2019-1000015MedFeb 4, 2019
    risk 0.00cvss 6.1epss 0.01

    Chamilo Chamilo-lms version 1.11.8 and earlier contains a Cross Site Scripting (XSS) vulnerability in main/messages/new_message.php, main/social/personal_data.php, main/inc/lib/TicketManager.php, main/ticket/ticket_details.php that can result in a message being sent to the…

  • CVE-2019-1000010MedFeb 4, 2019
    risk 0.00cvss 6.1epss 0.01

    phpIPAM version 1.3.2 and earlier contains a Cross Site Scripting (XSS) vulnerability in subnet-scan-telnet.php that can result in executing code in victims browser. This attack appears to be exploitable via victim visits link crafted by an attacker. This vulnerability appears…

  • CVE-2018-20726MedJan 16, 2019
    risk 0.00cvss 5.4epss 0.01

    A cross-site scripting (XSS) vulnerability exists in host.php (via tree.php) in Cacti before 1.2.0 due to lack of escaping of unintended characters in the Website Hostname field for Devices.

  • CVE-2018-20725MedJan 16, 2019
    risk 0.00cvss 4.8epss 0.01

    A cross-site scripting (XSS) vulnerability exists in graph_templates.php in Cacti before 1.2.0 due to lack of escaping of unintended characters in the Graph Vertical Label.

  • CVE-2018-20724MedJan 16, 2019
    risk 0.00cvss 4.8epss 0.01

    A cross-site scripting (XSS) vulnerability exists in pollers.php in Cacti before 1.2.0 due to lack of escaping of unintended characters in the Website Hostname for Data Collectors.

  • CVE-2018-20723MedJan 16, 2019
    risk 0.00cvss 4.8epss 0.01

    A cross-site scripting (XSS) vulnerability exists in color_templates.php in Cacti before 1.2.0 due to lack of escaping of unintended characters in the Name field for a Color.

  • CVE-2017-18358MedJan 15, 2019
    risk 0.00cvss 6.1epss 0.01

    LimeSurvey before 2.72.4 has Stored XSS by using the Continue Later (aka Resume later) feature to enter an email address, which is mishandled in the admin panel.

  • CVE-2018-20590MedDec 30, 2018
    risk 0.00cvss 4.8epss 0.01

    Ivan Cordoba Generic Content Management System (CMS) through 2018-04-28 has XSS via the Administrator/users.php user ID.

  • CVE-2018-20589MedDec 30, 2018
    risk 0.00cvss 4.8epss 0.01

    Ivan Cordoba Generic Content Management System (CMS) through 2018-04-28 has XSS via the Administrator/add_pictures.php article ID.

  • CVE-2018-20322MedDec 21, 2018
    risk 0.00cvss 6.1epss 0.01

    LimeSurvey version 3.15.5 contains a Cross-site scripting (XSS) vulnerability in Survey Resource zip upload, resulting in Javascript code execution against LimeSurvey administrators. Fixed in version 3.15.6.

  • CVE-2018-20328MedDec 21, 2018
    risk 0.00cvss 5.4epss 0.01

    Chamilo LMS version 1.11.8 contains XSS in main/social/group_view.php in the social groups tool, allowing authenticated users to affect other users, under specific conditions of permissions granted by administrators. This is considered "low risk" due to the nature of the feature…

  • CVE-2018-20327MedDec 21, 2018
    risk 0.00cvss 5.4epss 0.01

    Chamilo LMS version 1.11.8 contains XSS in main/template/default/admin/gradebook_list.tpl in the gradebook dependencies tool, allowing authenticated users to affect other users, under specific conditions of permissions granted by administrators. This is considered "low risk" due…

  • CVE-2018-1000870MedDec 20, 2018
    risk 0.00cvss 5.4epss 0.01

    PHPipam version 1.3.2 and earlier contains a CWE-79 vulnerability in /app/admin/users/print-user.php that can result in Execute code in the victims browser. This attack appear to be exploitable via Attacker change theme parameter in user settings. Admin(Victim) views user in…

  • CVE-2018-1000868MedDec 20, 2018
    risk 0.00cvss 6.1epss 0.02

    WeBid version up to current version 1.2.2 contains a Cross Site Scripting (XSS) vulnerability in user_login.php, register.php that can result in Javascript execution in the user's browser, injection of malicious markup into the page. This attack appear to be exploitable via The…

  • CVE-2018-1000855MedDec 20, 2018
    risk 0.00cvss 6.1epss 0.01

    easymon version 1.4 and earlier contains a Cross Site Scripting (XSS) vulnerability in Endpoint where monitoring is mounted that can result in Reflected XSS that affects Firefox. Can be used to steal cookies, depending on the cookie settings.. This attack appear to be…

  • CVE-2018-1000847MedDec 20, 2018
    risk 0.00cvss 5.4epss 0.01

    FreshDNS version 1.0.3 and prior contains a Cross Site Scripting (XSS) vulnerability in Account data form; Zone editor that can result in Execution of attacker's JavaScript code in victim's session. This attack appear to be exploitable via The attacker stores a specially crafted…

  • CVE-2018-19311MedNov 16, 2018
    risk 0.00cvss 5.4epss 0.01

    Centreon 3.4.x (fixed in Centreon 18.10.0) allows XSS via the Service field to the main.php?p=20201 URI, as demonstrated by the "Monitoring > Status Details > Services" screen.

  • CVE-2018-19280MedNov 14, 2018
    risk 0.00cvss 6.1epss 0.01

    Centreon 3.4.x (fixed in Centreon 18.10.0) has XSS via the resource name or macro expression of a poller macro.