VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (46,610)

page 2100 of 2,331
  • CVE-2018-12099MedJun 11, 2018
    risk 0.00cvss 6.1epss 0.02

    Grafana before 5.2.0-beta1 has XSS vulnerabilities in dashboard links.

  • CVE-2018-12043MedJun 7, 2018
    risk 0.00cvss 6.1epss 0.01

    content/content.blueprintspages.php in Symphony 2.7.6 has XSS via the pages content page.

  • CVE-2017-18286MedJun 5, 2018
    risk 0.00cvss 5.4epss 0.01

    nZEDb v0.7.3.3 has XSS in the 404 error page.

  • CVE-2017-16022MedJun 4, 2018
    risk 0.00cvss 6.1epss 0.01

    Morris.js creates an svg graph, with labels that appear when hovering over a point. The hovering label names are not escaped in versions 0.5.0 and earlier. If control over the labels is obtained, script can be injected. The script will run on the client side whenever that…

  • CVE-2017-16017MedJun 4, 2018
    risk 0.00cvss 6.1epss 0.01

    sanitize-html is a library for scrubbing html input for malicious values Versions 1.2.2 and below have a cross site scripting vulnerability.

  • CVE-2017-16008MedJun 4, 2018
    risk 0.00cvss 6.1epss 0.01

    i18next is a language translation framework. Because of how the interpolation is implemented, making replacements from the dictionary one at a time, untrusted user input can use the name of one of the dictionary keys to inject script into the browser. This affects i18next…

  • CVE-2018-10382MedJun 1, 2018
    risk 0.00cvss 5.4epss 0.01

    MODX Revolution 2.6.3 has XSS.

  • CVE-2018-11651MedJun 1, 2018
    risk 0.00cvss 6.1epss 0.01

    Graylog before v2.4.4 has an XSS security issue with unescaped text in dashboard names, related to components/dashboard/Dashboard.jsx, components/dashboard/EditDashboardModal.jsx, and pages/ShowDashboardPage.jsx.

  • CVE-2018-11650MedJun 1, 2018
    risk 0.00cvss 6.1epss 0.01

    Graylog before v2.4.4 has an XSS security issue with unescaped text in notifications, related to toastr and util/UserNotification.js.

  • CVE-2017-16010MedMay 29, 2018
    risk 0.00cvss 6.1epss 0.01

    i18next is a language translation framework. When using the .init method, passing interpolation options without passing an escapeValue will default to undefined rather than the assumed true. This can result in a cross-site scripting vulnerability because user input is assumed to…

  • CVE-2018-11330MedMay 21, 2018
    risk 0.00cvss 4.8epss 0.01

    An issue was discovered in Pluck before 4.7.6. There is authenticated stored XSS because the character set for filenames is not properly restricted.

  • CVE-2018-11245MedMay 18, 2018
    risk 0.00cvss 6.1epss 0.01

    app/webroot/js/misp.js in MISP 2.4.91 has a DOM based XSS with cortex type attributes.

  • CVE-2018-10307MedMay 18, 2018
    risk 0.00cvss 6.1epss 0.01

    error.php in ILIAS 5.2.x through 5.3.x before 5.3.4 allows XSS via the text of a PDO exception.

  • CVE-2018-10306MedMay 18, 2018
    risk 0.00cvss 6.1epss 0.01

    Services/Form/classes/class.ilDateDurationInputGUI.php and Services/Form/classes/class.ilDateTimeInputGUI.php in ILIAS 5.1.x through 5.3.x before 5.3.4 allow XSS via an invalid date.

  • CVE-2018-11120MedMay 17, 2018
    risk 0.00cvss 6.1epss 0.01

    Services/COPage/classes/class.ilPCSourceCode.php in ILIAS 5.1.x, 5.2.x, and 5.3.x before 5.3.5 has XSS.

  • CVE-2018-11118MedMay 17, 2018
    risk 0.00cvss 6.1epss 0.01

    The RSS subsystem in ILIAS 5.1.x, 5.2.x, and 5.3.x before 5.3.5 has XSS via a URI to Services/Feeds/classes/class.ilExternalFeedItem.php.

  • CVE-2018-11117MedMay 17, 2018
    risk 0.00cvss 6.1epss 0.01

    Services/Feeds/classes/class.ilExternalFeedItem.php in ILIAS 5.1.x, 5.2.x, and 5.3.x before 5.3.5 has XSS via a link attribute.

  • CVE-2018-10994MedMay 14, 2018
    risk 0.00cvss 6.1epss 0.01

    js/views/message_view.js in Open Whisper Signal (aka Signal-Desktop) before 1.10.1 allows XSS via a URL.

  • CVE-2018-10665MedMay 2, 2018
    risk 0.00cvss 6.1epss 0.01

    ILIAS 5.3.4 has XSS through unsanitized output of PHP_SELF, related to shib_logout.php and third-party demo files.

  • CVE-2018-10364MedApr 30, 2018
    risk 0.00cvss 5.4epss 0.01

    BigTree before 4.2.22 has XSS in the Users management page via the name or company field.