VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (46,610)

page 2099 of 2,331
  • CVE-2018-19131MedNov 9, 2018
    risk 0.00cvss 6.1epss 0.03

    Squid before 4.4 has XSS via a crafted X.509 certificate during HTTP(S) error page generation for certificate errors.

  • CVE-2018-18635MedOct 24, 2018
    risk 0.00cvss 6.1epss 0.01

    www/guis/admin/application/controllers/UserController.php in the administration login interface in MailCleaner CE 2018.08 and 2018.09 allows XSS via the admin/login/user/message/ PATH_INFO.

  • CVE-2018-18478MedOct 18, 2018
    risk 0.00cvss 6.1epss 0.02

    Persistent Cross-Site Scripting (XSS) issues in LibreNMS before 1.44 allow remote attackers to inject arbitrary web script or HTML via the dashboard_name parameter in the /ajax_form.php resource, related to html/includes/forms/add-dashboard.inc.php,…

  • CVE-2018-0046HigOct 10, 2018
    risk 0.00cvss 8.8epss 0.02

    A reflected cross-site scripting vulnerability in OpenNMS included with Juniper Networks Junos Space may allow the stealing of sensitive information or session credentials from Junos Space administrators or perform administrative actions. This issue affects Juniper Networks…

  • CVE-2018-17082MedSep 16, 2018
    risk 0.00cvss 6.1epss 0.04

    The Apache2 component in PHP before 5.6.38, 7.0.x before 7.0.32, 7.1.x before 7.1.22, and 7.2.x before 7.2.10 allows XSS via the body of a "Transfer-Encoding: chunked" request, because the bucket brigade is mishandled in the php_handler function in…

  • CVE-2018-10937MedSep 11, 2018
    risk 0.00cvss 4.6epss 0.01

    A cross site scripting flaw exists in the tetonic-console component of Openshift Container Platform 3.11. An attacker with the ability to create pods can use this flaw to perform actions on the K8s API as the victim.

  • CVE-2018-1000665MedSep 6, 2018
    risk 0.00cvss 6.1epss 0.01

    Dojo Dojo Objective Harness (DOH) version prior to version 1.14 contains a Cross Site Scripting (XSS) vulnerability in unit.html and testsDOH/_base/loader/i18n-exhaustive/i18n-test/unit.html and testsDOH/_base/i18nExhaustive.js in the DOH that can result in Victim attacked…

  • CVE-2018-16316MedSep 1, 2018
    risk 0.00cvss 5.4epss 0.01

    A stored Cross-site scripting (XSS) vulnerability in Portainer through 1.19.1 allows remote authenticated users to inject arbitrary JavaScript and/or HTML via the Team Name field.

  • CVE-2018-1000640MedAug 20, 2018
    risk 0.00cvss 6.1epss 0.01

    OpenCart-Overclocked version <=1.11.1 contains a Cross Site Scripting (XSS) vulnerability in User input entered unsanitised within JS function in the template that can result in Unauthorised actions and access to data, stealing session information, denial of service. This attack…

  • CVE-2018-3773MedJul 30, 2018
    risk 0.00cvss 6.1epss 0.01

    There is a stored Cross-Site Scripting vulnerability in Open Graph meta properties read by the `metascrape` npm module <= 3.9.2.

  • CVE-2017-18343MedJul 20, 2018
    risk 0.00cvss 6.1epss 0.06

    The debug handler in Symfony before v2.7.33, 2.8.x before v2.8.26, 3.x before v3.2.13, and 3.3.x before v3.3.6 has XSS via an array key during exception pretty printing in ExceptionHandler.php, as demonstrated by a /_debugbar/open?op=get URI. NOTE: the vendor's position is that…

  • CVE-2018-14380MedJul 18, 2018
    risk 0.00cvss 6.1epss 0.01

    In Graylog before 2.4.6, XSS was possible in typeahead components, related to components/common/TypeAheadInput.jsx and components/search/QueryInput.ts.

  • CVE-2018-13878MedJul 11, 2018
    risk 0.00cvss 6.1epss 0.01

    An XSS issue was discovered in packages/rocketchat-mentions/Mentions.js in Rocket.Chat before 0.65. The real name of a username is displayed unescaped when the user is mentioned (using the @ symbol) in a channel or private chat. Consequently, it is possible to exfiltrate the…

  • CVE-2018-1000611MedJul 9, 2018
    risk 0.00cvss 6.1epss 0.01

    SURFnet OpenConext EngineBlock version 5.7.0 to 5.7.3 contains a Cross Site Scripting (XSS) vulnerability that can result in Allows an attacker to inject arbitrary web scripts or HTML into help and login pages. This attack appear to be exploitable via the victim opening a…

  • CVE-2018-13423MedJul 7, 2018
    risk 0.00cvss 6.1epss 0.01

    admin/themes/default/items/tag-form.php in Omeka before 2.6.1 allows XSS by adding or editing a tag.

  • CVE-2018-13422MedJul 7, 2018
    risk 0.00cvss 6.1epss 0.01

    TCExam before 14.1.2 has XSS via an ff_ or xl_ field.

  • CVE-2018-11588MedJun 25, 2018
    risk 0.00cvss 5.4epss 0.01

    Centreon 3.4.6 including Centreon Web 2.8.23 is vulnerable to an authenticated user injecting a payload into the username or command description, resulting in stored XSS. This is related to www/include/core/menu/menu.php and www/include/configuration/configObject/command/formArgu…

  • CVE-2018-12588MedJun 19, 2018
    risk 0.00cvss 6.1epss 0.02

    Cross-site scripting (XSS) vulnerability in templates/frontend/pages/searchResults.tpl in Public Knowledge Project (PKP) Open Monograph Press (OMP) v1.2.0 through 3.1.1-2 before 3.1.1-3 allows remote attackers to inject arbitrary web script or HTML via the catalog.noTitlesSearch…

  • CVE-2018-12030MedJun 15, 2018
    risk 0.00cvss 5.4epss 0.01

    Chevereto Free before 1.0.13 has XSS.

  • CVE-2018-10821MedJun 14, 2018
    risk 0.00cvss 4.8epss 0.01

    Cross-site scripting (XSS) vulnerability in backend/pages/modify.php in BlackCatCMS 1.3 allows remote authenticated users with the Admin role to inject arbitrary web script or HTML via the search panel.