VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (46,607)

page 21 of 2,331
  • CVE-2020-9740CriSep 10, 2020
    risk 0.59cvss 9.0epss 0.02

    AEM versions 6.5.5.0 (and below), 6.4.8.1 (and below), 6.3.3.8 (and below) and 6.2 SP1-CFP20 (and below) are affected by a stored XSS vulnerability that allows users with 'Author' privileges to store malicious scripts in fields associated with the Design Importer. These scripts…

  • CVE-2020-9734CriSep 10, 2020
    risk 0.59cvss 9.0epss 0.02

    The AEM Forms add-on for versions 6.5.5.0 (and below) and 6.4.8.1 (and below) is affected by a stored XSS vulnerability that allows users with 'Author' privileges to store malicious scripts in fields associated with the Forms component. These scripts may be executed in a…

  • CVE-2020-9732CriSep 10, 2020
    risk 0.59cvss 9.0epss 0.03

    The AEM Forms add-on for versions 6.5.5.0 (and below) and 6.4.8.2 (and below) are affected by a stored XSS vulnerability that allows users with 'Author' privileges to store malicious scripts in fields associated with the Sites component. These scripts may be executed in a…

  • CVE-2020-2036HigSep 9, 2020
    risk 0.59cvss 8.8epss 0.24

    A reflected cross-site scripting (XSS) vulnerability exists in the PAN-OS management web interface. A remote attacker able to convince an administrator with an active authenticated session on the firewall management interface to click on a crafted link to that management web…

  • CVE-2020-16210CriSep 1, 2020
    risk 0.59cvss 9.0epss 0.03

    The affected product is vulnerable to reflected cross-site scripting, which may allow an attacker to remotely execute arbitrary code and perform actions in the context of an attacked user on the N-Tron 702-W / 702M12-W (all versions).

  • CVE-2020-16206CriSep 1, 2020
    risk 0.59cvss 9.0epss 0.03

    The affected product is vulnerable to stored cross-site scripting, which may allow an attacker to remotely execute arbitrary code to gain access to sensitive data on the N-Tron 702-W / 702M12-W (all versions).

  • CVE-2020-6284CriAug 12, 2020
    risk 0.59cvss 9.0epss 0.02

    SAP NetWeaver (Knowledge Management), versions - 7.30, 7.31, 7.40, 7.50, allows the automatic execution of script content in a stored file due to inadequate filtering with the accessing user's privileges. If the accessing user has administrative privileges, then the execution of…

  • CVE-2020-11436CriJul 15, 2020
    risk 0.59cvss 9.0epss 0.01

    LibreHealth EMR v2.0.0 is vulnerable to XSS that results in the ability to force arbitrary actions on behalf of other users including administrators.

  • CVE-2020-12021CriJun 23, 2020
    risk 0.59cvss 9.0epss 0.02

    In OSIsoft PI Web API 2019 Patch 1 (1.12.0.6346) and all previous versions, the affected product is vulnerable to a cross-site scripting attack, which may allow an attacker to remotely execute arbitrary code.

  • CVE-2019-18578CriMar 13, 2020
    risk 0.59cvss 9.0epss 0.01

    Dell EMC XtremIO XMS versions prior to 6.3.0 contain a stored cross-site scripting vulnerability. A low-privileged malicious remote user of XtremIO may exploit this vulnerability to store malicious HTML or JavaScript code in application fields. When victim users access the…

  • CVE-2020-8612CriFeb 14, 2020
    risk 0.59cvss 9.0epss 0.02

    In Progress MOVEit Transfer 2019.1 before 2019.1.4 and 2019.2 before 2019.2.1, a REST API endpoint failed to adequately sanitize malicious input, which could allow an authenticated attacker to execute arbitrary code in a victim's browser, aka XSS.

  • CVE-2019-17634CriJan 17, 2020
    risk 0.59cvss 9.0epss 0.02

    Eclipse Memory Analyzer version 1.9.1 and earlier is subject to a cross site scripting (XSS) vulnerability when generating an HTML report from a malicious heap dump. The user must chose todownload, open the malicious heap dump and generate an HTML report for the problem to…

  • CVE-2019-18839CriNov 13, 2019
    risk 0.59cvss 9.0epss 0.05

    FUDForum 3.0.9 is vulnerable to Stored XSS via the nlogin parameter. This may result in remote code execution. An attacker can use a user account to fully compromise the system using a POST request. When the admin visits the user information, the payload will execute. This will…

  • CVE-2019-17625CriOct 16, 2019
    risk 0.59cvss 9.0epss 0.03

    There is a stored XSS in Rambox 0.6.9 that can lead to code execution. The XSS is in the name field while adding/editing a service. The problem occurs due to incorrect sanitization of the name field when being processed and stored. This allows a user to craft a payload for…

  • CVE-2019-7551CriApr 10, 2019
    risk 0.59cvss 9.0epss 0.02

    Cantemo Portal before 3.2.13, 3.3.x before 3.3.8, and 3.4.x before 3.4.9 has XSS. Leveraging this vulnerability would enable performing actions as users, including administrative users. This could enable account creation and deletion as well as deletion of information contained…

  • CVE-2018-13359HigNov 27, 2018
    risk 0.59cvss 8.8epss 0.14

    Cross-site scripting in usertable.php in TerraMaster TOS version 3.1.03 allows attackers to execute JavaScript via the "modgroup" parameter.

  • CVE-2016-9470CriMar 28, 2017
    risk 0.59cvss 9.0epss 0.02

    Revive Adserver before 3.2.5 and 4.0.0 suffers from Reflected File Download. `www/delivery/asyncspc.php` was vulnerable to the fairly new Reflected File Download (RFD) web attack vector that enables attackers to gain complete control over a victim's machine by virtually…

  • CVE-2026-18099HigAug 12, 2026
    risk 0.58cvss 8.9epss 0.00

    IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary script code due to improper neutralization of user-controlled input.

  • CVE-2026-57858HigAug 12, 2026
    risk 0.58cvss 8.9epss 0.00

    Cal.com Cal.diy versions 2.1.1 through 6.2.0 contain a stored cross-site scripting vulnerability in the BookingPageTagManager component that allows authenticated event owners to inject arbitrary JavaScript by supplying a malicious analytics tracking ID without sanitization.…

  • CVE-2026-71386HigAug 11, 2026
    risk 0.58cvss 8.8epss 0.07

    is affected by a Cross-site Scripting (XSS) vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. The vulnerable component is restricted to an administrative network…