CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Description
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85
CVEs mapped to this weakness (46,610)
page 2100 of 2,331| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2018-12099 | Med | 0.00 | 6.1 | 0.02 | Jun 11, 2018 | Grafana before 5.2.0-beta1 has XSS vulnerabilities in dashboard links. | ||
| CVE-2018-12043 | Med | 0.00 | 6.1 | 0.01 | Jun 7, 2018 | content/content.blueprintspages.php in Symphony 2.7.6 has XSS via the pages content page. | ||
| CVE-2017-18286 | Med | 0.00 | 5.4 | 0.01 | Jun 5, 2018 | nZEDb v0.7.3.3 has XSS in the 404 error page. | ||
| CVE-2017-16022 | Med | 0.00 | 6.1 | 0.01 | Jun 4, 2018 | Morris.js creates an svg graph, with labels that appear when hovering over a point. The hovering label names are not escaped in versions 0.5.0 and earlier. If control over the labels is obtained, script can be injected. The script will run on the client side whenever that… | ||
| CVE-2017-16017 | Med | 0.00 | 6.1 | 0.01 | Jun 4, 2018 | sanitize-html is a library for scrubbing html input for malicious values Versions 1.2.2 and below have a cross site scripting vulnerability. | ||
| CVE-2017-16008 | — | Med | 0.00 | 6.1 | 0.01 | Jun 4, 2018 | i18next is a language translation framework. Because of how the interpolation is implemented, making replacements from the dictionary one at a time, untrusted user input can use the name of one of the dictionary keys to inject script into the browser. This affects i18next… | |
| CVE-2018-10382 | Med | 0.00 | 5.4 | 0.01 | Jun 1, 2018 | MODX Revolution 2.6.3 has XSS. | ||
| CVE-2018-11651 | Med | 0.00 | 6.1 | 0.01 | Jun 1, 2018 | Graylog before v2.4.4 has an XSS security issue with unescaped text in dashboard names, related to components/dashboard/Dashboard.jsx, components/dashboard/EditDashboardModal.jsx, and pages/ShowDashboardPage.jsx. | ||
| CVE-2018-11650 | Med | 0.00 | 6.1 | 0.01 | Jun 1, 2018 | Graylog before v2.4.4 has an XSS security issue with unescaped text in notifications, related to toastr and util/UserNotification.js. | ||
| CVE-2017-16010 | — | Med | 0.00 | 6.1 | 0.01 | May 29, 2018 | i18next is a language translation framework. When using the .init method, passing interpolation options without passing an escapeValue will default to undefined rather than the assumed true. This can result in a cross-site scripting vulnerability because user input is assumed to… | |
| CVE-2018-11330 | Med | 0.00 | 4.8 | 0.01 | May 21, 2018 | An issue was discovered in Pluck before 4.7.6. There is authenticated stored XSS because the character set for filenames is not properly restricted. | ||
| CVE-2018-11245 | Med | 0.00 | 6.1 | 0.01 | May 18, 2018 | app/webroot/js/misp.js in MISP 2.4.91 has a DOM based XSS with cortex type attributes. | ||
| CVE-2018-10307 | Med | 0.00 | 6.1 | 0.01 | May 18, 2018 | error.php in ILIAS 5.2.x through 5.3.x before 5.3.4 allows XSS via the text of a PDO exception. | ||
| CVE-2018-10306 | Med | 0.00 | 6.1 | 0.01 | May 18, 2018 | Services/Form/classes/class.ilDateDurationInputGUI.php and Services/Form/classes/class.ilDateTimeInputGUI.php in ILIAS 5.1.x through 5.3.x before 5.3.4 allow XSS via an invalid date. | ||
| CVE-2018-11120 | Med | 0.00 | 6.1 | 0.01 | May 17, 2018 | Services/COPage/classes/class.ilPCSourceCode.php in ILIAS 5.1.x, 5.2.x, and 5.3.x before 5.3.5 has XSS. | ||
| CVE-2018-11118 | Med | 0.00 | 6.1 | 0.01 | May 17, 2018 | The RSS subsystem in ILIAS 5.1.x, 5.2.x, and 5.3.x before 5.3.5 has XSS via a URI to Services/Feeds/classes/class.ilExternalFeedItem.php. | ||
| CVE-2018-11117 | Med | 0.00 | 6.1 | 0.01 | May 17, 2018 | Services/Feeds/classes/class.ilExternalFeedItem.php in ILIAS 5.1.x, 5.2.x, and 5.3.x before 5.3.5 has XSS via a link attribute. | ||
| CVE-2018-10994 | Med | 0.00 | 6.1 | 0.01 | May 14, 2018 | js/views/message_view.js in Open Whisper Signal (aka Signal-Desktop) before 1.10.1 allows XSS via a URL. | ||
| CVE-2018-10665 | Med | 0.00 | 6.1 | 0.01 | May 2, 2018 | ILIAS 5.3.4 has XSS through unsanitized output of PHP_SELF, related to shib_logout.php and third-party demo files. | ||
| CVE-2018-10364 | Med | 0.00 | 5.4 | 0.01 | Apr 30, 2018 | BigTree before 4.2.22 has XSS in the Users management page via the name or company field. |
- risk 0.00cvss 6.1epss 0.02
Grafana before 5.2.0-beta1 has XSS vulnerabilities in dashboard links.
- risk 0.00cvss 6.1epss 0.01
content/content.blueprintspages.php in Symphony 2.7.6 has XSS via the pages content page.
- risk 0.00cvss 5.4epss 0.01
nZEDb v0.7.3.3 has XSS in the 404 error page.
- risk 0.00cvss 6.1epss 0.01
Morris.js creates an svg graph, with labels that appear when hovering over a point. The hovering label names are not escaped in versions 0.5.0 and earlier. If control over the labels is obtained, script can be injected. The script will run on the client side whenever that…
- risk 0.00cvss 6.1epss 0.01
sanitize-html is a library for scrubbing html input for malicious values Versions 1.2.2 and below have a cross site scripting vulnerability.
- risk 0.00cvss 6.1epss 0.01
i18next is a language translation framework. Because of how the interpolation is implemented, making replacements from the dictionary one at a time, untrusted user input can use the name of one of the dictionary keys to inject script into the browser. This affects i18next…
- risk 0.00cvss 5.4epss 0.01
MODX Revolution 2.6.3 has XSS.
- risk 0.00cvss 6.1epss 0.01
Graylog before v2.4.4 has an XSS security issue with unescaped text in dashboard names, related to components/dashboard/Dashboard.jsx, components/dashboard/EditDashboardModal.jsx, and pages/ShowDashboardPage.jsx.
- risk 0.00cvss 6.1epss 0.01
Graylog before v2.4.4 has an XSS security issue with unescaped text in notifications, related to toastr and util/UserNotification.js.
- risk 0.00cvss 6.1epss 0.01
i18next is a language translation framework. When using the .init method, passing interpolation options without passing an escapeValue will default to undefined rather than the assumed true. This can result in a cross-site scripting vulnerability because user input is assumed to…
- risk 0.00cvss 4.8epss 0.01
An issue was discovered in Pluck before 4.7.6. There is authenticated stored XSS because the character set for filenames is not properly restricted.
- risk 0.00cvss 6.1epss 0.01
app/webroot/js/misp.js in MISP 2.4.91 has a DOM based XSS with cortex type attributes.
- risk 0.00cvss 6.1epss 0.01
error.php in ILIAS 5.2.x through 5.3.x before 5.3.4 allows XSS via the text of a PDO exception.
- risk 0.00cvss 6.1epss 0.01
Services/Form/classes/class.ilDateDurationInputGUI.php and Services/Form/classes/class.ilDateTimeInputGUI.php in ILIAS 5.1.x through 5.3.x before 5.3.4 allow XSS via an invalid date.
- risk 0.00cvss 6.1epss 0.01
Services/COPage/classes/class.ilPCSourceCode.php in ILIAS 5.1.x, 5.2.x, and 5.3.x before 5.3.5 has XSS.
- risk 0.00cvss 6.1epss 0.01
The RSS subsystem in ILIAS 5.1.x, 5.2.x, and 5.3.x before 5.3.5 has XSS via a URI to Services/Feeds/classes/class.ilExternalFeedItem.php.
- risk 0.00cvss 6.1epss 0.01
Services/Feeds/classes/class.ilExternalFeedItem.php in ILIAS 5.1.x, 5.2.x, and 5.3.x before 5.3.5 has XSS via a link attribute.
- risk 0.00cvss 6.1epss 0.01
js/views/message_view.js in Open Whisper Signal (aka Signal-Desktop) before 1.10.1 allows XSS via a URL.
- risk 0.00cvss 6.1epss 0.01
ILIAS 5.3.4 has XSS through unsanitized output of PHP_SELF, related to shib_logout.php and third-party demo files.
- risk 0.00cvss 5.4epss 0.01
BigTree before 4.2.22 has XSS in the Users management page via the name or company field.