CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Description
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85
CVEs mapped to this weakness (46,610)
page 2101 of 2,331| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2018-10571 | Med | 0.00 | 6.1 | 0.02 | Apr 30, 2018 | Multiple reflected cross-site scripting (XSS) vulnerabilities in OpenEMR before 5.0.1 allow remote attackers to inject arbitrary web script or HTML via the (1) patient parameter to interface/main/finder/finder_navigation.php; (2) key parameter to… | ||
| CVE-2018-1000162 | Med | 0.00 | 6.1 | 0.01 | Apr 18, 2018 | Parsedown version prior to 1.7.0 contains a Cross Site Scripting (XSS) vulnerability in `setMarkupEscaped` for escaping HTML that can result in JavaScript code execution. This attack appears to be exploitable via specially crafted markdown that allows it to side step HTML… | ||
| CVE-2018-1081 | Med | 0.00 | 5.3 | 0.01 | Apr 4, 2018 | A flaw was found in Moodle 3.4 to 3.4.1, 3.3 to 3.3.4, 3.2 to 3.2.7, 3.1 to 3.1.10 and earlier unsupported versions. Unauthenticated users can trigger custom messages to admin via paypal enrol script. Paypal IPN callback script should only send error emails to admin after… | ||
| CVE-2018-8948 | Med | 0.00 | 6.1 | 0.01 | Mar 23, 2018 | In MISP before 2.4.89, app/View/Events/resolved_attributes.ctp has multiple XSS issues via a malicious MISP module. | ||
| CVE-2018-8899 | Med | 0.00 | 6.1 | 0.01 | Mar 22, 2018 | IdentityServer IdentityServer4 1.x before 1.5.3 and 2.x before 2.1.3 does not encode the redirect URI on the authorization response page, which might lead to XSS in some configurations. | ||
| CVE-2018-8728 | Med | 0.00 | 6.1 | 0.01 | Mar 15, 2018 | server/app/views/static/code.html in Kontena before 1.5.0 allows XSS in "kontena master login --remote" code display, as demonstrated by /code#code= in a URI. | ||
| CVE-2018-7563 | Med | 0.00 | 6.1 | 0.01 | Mar 12, 2018 | An issue was discovered in GLPI through 9.2.1. The application is affected by XSS in the query string to front/preference.php. An attacker is able to create a malicious URL that, if opened by an authenticated user with debug privilege, will execute JavaScript code supplied by… | ||
| CVE-2017-2661 | Med | 0.00 | 6.1 | 0.01 | Mar 12, 2018 | ClusterLabs pcs before version 0.9.157 is vulnerable to a cross-site scripting vulnerability due to improper validation of Node name field when creating new cluster or adding existing cluster. | ||
| CVE-2017-18217 | Med | 0.00 | 6.1 | 0.01 | Mar 5, 2018 | An issue was discovered in InvoicePlane before 1.5.5. It was observed that the Email address and Web address parameters are vulnerable to Cross Site Scripting, related to application/modules/clients/views/view.php, application/modules/invoices/views/view.php, and… | ||
| CVE-2018-7663 | Med | 0.00 | 6.1 | 0.01 | Mar 5, 2018 | An issue was discovered in resources/views/layouts/app.blade.php in Voten.co before 2017-08-25. An unescaped template literal in the bio field of a user profile (resources/views/layouts/app.blade.php) allows for server-side template injection of arbitrary JavaScript. | ||
| CVE-2018-7652 | Med | 0.00 | 6.1 | 0.01 | Mar 4, 2018 | lib/Zonemaster/GUI/Dancer/Export.pm in Zonemaster Web GUI before 1.0.11 has XSS. | ||
| CVE-2017-1000508 | Med | 0.00 | 6.1 | 0.01 | Feb 9, 2018 | Invoice Plane version 1.5.4 and earlier contains a Cross Site Scripting (XSS) vulnerability in Client's details that can result in execution of javascript code . This vulnerability appears to have been fixed in 1.5.5 and later. | ||
| CVE-2018-6834 | Med | 0.00 | 6.1 | 0.01 | Feb 8, 2018 | static/js/pad_utils.js in Etherpad Lite before v1.6.3 has XSS via window.location.href. | ||
| CVE-2018-6550 | Med | 0.00 | 5.4 | 0.01 | Feb 2, 2018 | Monstra CMS through 3.0.4 has XSS in the title function in plugins/box/pages/pages.plugin.php via a page title to admin/index.php. | ||
| CVE-2018-6354 | Med | 0.00 | 6.1 | 0.01 | Jan 27, 2018 | templates/forms/thanks.html in Formspree before 2018-01-23 allows XSS related to the _next parameter. | ||
| CVE-2018-5249 | Med | 0.00 | 6.1 | 0.01 | Jan 5, 2018 | Cross-site scripting (XSS) vulnerability in Shaarli before 0.8.5 and 0.9.x before 0.9.3 allows remote attackers to inject arbitrary code via the login form's username field (aka the login parameter to the ban_canLogin function in index.php). | ||
| CVE-2018-5213 | Med | 0.00 | 5.4 | 0.01 | Jan 4, 2018 | The Simple Download Monitor plugin before 3.5.4 for WordPress has XSS via the sdm_upload (aka Downloadable File) parameter in an edit action to wp-admin/post.php. | ||
| CVE-2018-5212 | Med | 0.00 | 5.4 | 0.01 | Jan 4, 2018 | The Simple Download Monitor plugin before 3.5.4 for WordPress has XSS via the sdm_upload_thumbnail (aka File Thumbnail) parameter in an edit action to wp-admin/post.php. | ||
| CVE-2017-1000492 | Med | 0.00 | 6.1 | 0.01 | Jan 3, 2018 | Leanote-desktop version v2.5 is vulnerable to a XSS which leads to code execution due to enabled node integration | ||
| CVE-2017-1000457 | Med | 0.00 | 4.8 | 0.01 | Jan 2, 2018 | Cross-site scripting (XSS) vulnerability in Help.aspx in mojoPortal version 2.5.0.0 allows remote attackers to inject arbitrary web script or HTML via the helpkey parameter. Exploitation requires authenticated reflected cross-site scripting for user accounts assigned either the… |
- risk 0.00cvss 6.1epss 0.02
Multiple reflected cross-site scripting (XSS) vulnerabilities in OpenEMR before 5.0.1 allow remote attackers to inject arbitrary web script or HTML via the (1) patient parameter to interface/main/finder/finder_navigation.php; (2) key parameter to…
- risk 0.00cvss 6.1epss 0.01
Parsedown version prior to 1.7.0 contains a Cross Site Scripting (XSS) vulnerability in `setMarkupEscaped` for escaping HTML that can result in JavaScript code execution. This attack appears to be exploitable via specially crafted markdown that allows it to side step HTML…
- risk 0.00cvss 5.3epss 0.01
A flaw was found in Moodle 3.4 to 3.4.1, 3.3 to 3.3.4, 3.2 to 3.2.7, 3.1 to 3.1.10 and earlier unsupported versions. Unauthenticated users can trigger custom messages to admin via paypal enrol script. Paypal IPN callback script should only send error emails to admin after…
- risk 0.00cvss 6.1epss 0.01
In MISP before 2.4.89, app/View/Events/resolved_attributes.ctp has multiple XSS issues via a malicious MISP module.
- risk 0.00cvss 6.1epss 0.01
IdentityServer IdentityServer4 1.x before 1.5.3 and 2.x before 2.1.3 does not encode the redirect URI on the authorization response page, which might lead to XSS in some configurations.
- risk 0.00cvss 6.1epss 0.01
server/app/views/static/code.html in Kontena before 1.5.0 allows XSS in "kontena master login --remote" code display, as demonstrated by /code#code= in a URI.
- risk 0.00cvss 6.1epss 0.01
An issue was discovered in GLPI through 9.2.1. The application is affected by XSS in the query string to front/preference.php. An attacker is able to create a malicious URL that, if opened by an authenticated user with debug privilege, will execute JavaScript code supplied by…
- risk 0.00cvss 6.1epss 0.01
ClusterLabs pcs before version 0.9.157 is vulnerable to a cross-site scripting vulnerability due to improper validation of Node name field when creating new cluster or adding existing cluster.
- risk 0.00cvss 6.1epss 0.01
An issue was discovered in InvoicePlane before 1.5.5. It was observed that the Email address and Web address parameters are vulnerable to Cross Site Scripting, related to application/modules/clients/views/view.php, application/modules/invoices/views/view.php, and…
- risk 0.00cvss 6.1epss 0.01
An issue was discovered in resources/views/layouts/app.blade.php in Voten.co before 2017-08-25. An unescaped template literal in the bio field of a user profile (resources/views/layouts/app.blade.php) allows for server-side template injection of arbitrary JavaScript.
- risk 0.00cvss 6.1epss 0.01
lib/Zonemaster/GUI/Dancer/Export.pm in Zonemaster Web GUI before 1.0.11 has XSS.
- risk 0.00cvss 6.1epss 0.01
Invoice Plane version 1.5.4 and earlier contains a Cross Site Scripting (XSS) vulnerability in Client's details that can result in execution of javascript code . This vulnerability appears to have been fixed in 1.5.5 and later.
- risk 0.00cvss 6.1epss 0.01
static/js/pad_utils.js in Etherpad Lite before v1.6.3 has XSS via window.location.href.
- risk 0.00cvss 5.4epss 0.01
Monstra CMS through 3.0.4 has XSS in the title function in plugins/box/pages/pages.plugin.php via a page title to admin/index.php.
- risk 0.00cvss 6.1epss 0.01
templates/forms/thanks.html in Formspree before 2018-01-23 allows XSS related to the _next parameter.
- risk 0.00cvss 6.1epss 0.01
Cross-site scripting (XSS) vulnerability in Shaarli before 0.8.5 and 0.9.x before 0.9.3 allows remote attackers to inject arbitrary code via the login form's username field (aka the login parameter to the ban_canLogin function in index.php).
- risk 0.00cvss 5.4epss 0.01
The Simple Download Monitor plugin before 3.5.4 for WordPress has XSS via the sdm_upload (aka Downloadable File) parameter in an edit action to wp-admin/post.php.
- risk 0.00cvss 5.4epss 0.01
The Simple Download Monitor plugin before 3.5.4 for WordPress has XSS via the sdm_upload_thumbnail (aka File Thumbnail) parameter in an edit action to wp-admin/post.php.
- risk 0.00cvss 6.1epss 0.01
Leanote-desktop version v2.5 is vulnerable to a XSS which leads to code execution due to enabled node integration
- risk 0.00cvss 4.8epss 0.01
Cross-site scripting (XSS) vulnerability in Help.aspx in mojoPortal version 2.5.0.0 allows remote attackers to inject arbitrary web script or HTML via the helpkey parameter. Exploitation requires authenticated reflected cross-site scripting for user accounts assigned either the…