VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (46,610)

page 2101 of 2,331
  • CVE-2018-10571MedApr 30, 2018
    risk 0.00cvss 6.1epss 0.02

    Multiple reflected cross-site scripting (XSS) vulnerabilities in OpenEMR before 5.0.1 allow remote attackers to inject arbitrary web script or HTML via the (1) patient parameter to interface/main/finder/finder_navigation.php; (2) key parameter to…

  • CVE-2018-1000162MedApr 18, 2018
    risk 0.00cvss 6.1epss 0.01

    Parsedown version prior to 1.7.0 contains a Cross Site Scripting (XSS) vulnerability in `setMarkupEscaped` for escaping HTML that can result in JavaScript code execution. This attack appears to be exploitable via specially crafted markdown that allows it to side step HTML…

  • CVE-2018-1081MedApr 4, 2018
    risk 0.00cvss 5.3epss 0.01

    A flaw was found in Moodle 3.4 to 3.4.1, 3.3 to 3.3.4, 3.2 to 3.2.7, 3.1 to 3.1.10 and earlier unsupported versions. Unauthenticated users can trigger custom messages to admin via paypal enrol script. Paypal IPN callback script should only send error emails to admin after…

  • CVE-2018-8948MedMar 23, 2018
    risk 0.00cvss 6.1epss 0.01

    In MISP before 2.4.89, app/View/Events/resolved_attributes.ctp has multiple XSS issues via a malicious MISP module.

  • CVE-2018-8899MedMar 22, 2018
    risk 0.00cvss 6.1epss 0.01

    IdentityServer IdentityServer4 1.x before 1.5.3 and 2.x before 2.1.3 does not encode the redirect URI on the authorization response page, which might lead to XSS in some configurations.

  • CVE-2018-8728MedMar 15, 2018
    risk 0.00cvss 6.1epss 0.01

    server/app/views/static/code.html in Kontena before 1.5.0 allows XSS in "kontena master login --remote" code display, as demonstrated by /code#code= in a URI.

  • CVE-2018-7563MedMar 12, 2018
    risk 0.00cvss 6.1epss 0.01

    An issue was discovered in GLPI through 9.2.1. The application is affected by XSS in the query string to front/preference.php. An attacker is able to create a malicious URL that, if opened by an authenticated user with debug privilege, will execute JavaScript code supplied by…

  • CVE-2017-2661MedMar 12, 2018
    risk 0.00cvss 6.1epss 0.01

    ClusterLabs pcs before version 0.9.157 is vulnerable to a cross-site scripting vulnerability due to improper validation of Node name field when creating new cluster or adding existing cluster.

  • CVE-2017-18217MedMar 5, 2018
    risk 0.00cvss 6.1epss 0.01

    An issue was discovered in InvoicePlane before 1.5.5. It was observed that the Email address and Web address parameters are vulnerable to Cross Site Scripting, related to application/modules/clients/views/view.php, application/modules/invoices/views/view.php, and…

  • CVE-2018-7663MedMar 5, 2018
    risk 0.00cvss 6.1epss 0.01

    An issue was discovered in resources/views/layouts/app.blade.php in Voten.co before 2017-08-25. An unescaped template literal in the bio field of a user profile (resources/views/layouts/app.blade.php) allows for server-side template injection of arbitrary JavaScript.

  • CVE-2018-7652MedMar 4, 2018
    risk 0.00cvss 6.1epss 0.01

    lib/Zonemaster/GUI/Dancer/Export.pm in Zonemaster Web GUI before 1.0.11 has XSS.

  • CVE-2017-1000508MedFeb 9, 2018
    risk 0.00cvss 6.1epss 0.01

    Invoice Plane version 1.5.4 and earlier contains a Cross Site Scripting (XSS) vulnerability in Client's details that can result in execution of javascript code . This vulnerability appears to have been fixed in 1.5.5 and later.

  • CVE-2018-6834MedFeb 8, 2018
    risk 0.00cvss 6.1epss 0.01

    static/js/pad_utils.js in Etherpad Lite before v1.6.3 has XSS via window.location.href.

  • CVE-2018-6550MedFeb 2, 2018
    risk 0.00cvss 5.4epss 0.01

    Monstra CMS through 3.0.4 has XSS in the title function in plugins/box/pages/pages.plugin.php via a page title to admin/index.php.

  • CVE-2018-6354MedJan 27, 2018
    risk 0.00cvss 6.1epss 0.01

    templates/forms/thanks.html in Formspree before 2018-01-23 allows XSS related to the _next parameter.

  • CVE-2018-5249MedJan 5, 2018
    risk 0.00cvss 6.1epss 0.01

    Cross-site scripting (XSS) vulnerability in Shaarli before 0.8.5 and 0.9.x before 0.9.3 allows remote attackers to inject arbitrary code via the login form's username field (aka the login parameter to the ban_canLogin function in index.php).

  • CVE-2018-5213MedJan 4, 2018
    risk 0.00cvss 5.4epss 0.01

    The Simple Download Monitor plugin before 3.5.4 for WordPress has XSS via the sdm_upload (aka Downloadable File) parameter in an edit action to wp-admin/post.php.

  • CVE-2018-5212MedJan 4, 2018
    risk 0.00cvss 5.4epss 0.01

    The Simple Download Monitor plugin before 3.5.4 for WordPress has XSS via the sdm_upload_thumbnail (aka File Thumbnail) parameter in an edit action to wp-admin/post.php.

  • CVE-2017-1000492MedJan 3, 2018
    risk 0.00cvss 6.1epss 0.01

    Leanote-desktop version v2.5 is vulnerable to a XSS which leads to code execution due to enabled node integration

  • CVE-2017-1000457MedJan 2, 2018
    risk 0.00cvss 4.8epss 0.01

    Cross-site scripting (XSS) vulnerability in Help.aspx in mojoPortal version 2.5.0.0 allows remote attackers to inject arbitrary web script or HTML via the helpkey parameter. Exploitation requires authenticated reflected cross-site scripting for user accounts assigned either the…