VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (46,607)

page 23 of 2,331
  • CVE-2024-46278HigOct 7, 2024
    risk 0.58cvss 8.4epss 0.03

    Teedy 1.11 is vulnerable to Cross Site Scripting (XSS) via the management console.

  • CVE-2024-21897HigSep 6, 2024
    risk 0.58cvss 8.9epss 0.00

    A cross-site scripting (XSS) vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to inject malicious code via a network. We have already fixed the vulnerability in the following…

  • CVE-2024-28100HigSep 2, 2024
    risk 0.58cvss 8.9epss 0.00

    eLabFTW is an open source electronic lab notebook for research labs. By uploading specially crafted files, a regular user can create a circumstance where a visitor's browser runs arbitrary JavaScript code in the context of the eLabFTW application. This can be triggered by the…

  • CVE-2023-40000HigApr 16, 2024
    risk 0.58cvss 8.3epss 0.55

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LiteSpeed Technologies LiteSpeed Cache allows Stored XSS.This issue affects LiteSpeed Cache: from n/a through 5.7.

  • CVE-2023-45144CriOct 16, 2023
    risk 0.58cvss 10.0epss 0.01

    com.xwiki.identity-oauth:identity-oauth-ui is a package to aid in building identity and service providers based on OAuth authorizations. When a user logs in via the OAuth method, the identityOAuth parameters sent in the GET request is vulnerable to cross site scripting (XSS) and…

  • CVE-2023-30435HigAug 27, 2023
    risk 0.58cvss 8.9epss 0.00

    IBM Security Guardium 11.3, 11.4, and 11.5 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted…

  • CVE-2023-40176CriAug 23, 2023
    risk 0.58cvss 9.0epss 0.80

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any registered user can exploit a stored XSS through their user profile by setting the payload as the value of the time zone user preference. Even though the time zone is…

  • CVE-2022-4361CriJul 7, 2023
    risk 0.58cvss 10.0epss 0.01

    Keycloak, an open-source identity and access management solution, has a cross-site scripting (XSS) vulnerability in the SAML or OIDC providers. The vulnerability can allow an attacker to execute malicious scripts by setting the AssertionConsumerServiceURL value or the…

  • CVE-2023-33961HigMay 30, 2023
    risk 0.58cvss 8.9epss 0.00

    Leantime is a lean open source project management system. Starting in version 2.3.21, an authenticated user with commenting privileges can inject malicious Javascript into a comment. Once the malicious comment is loaded in the browser by a user, the malicious Javascript code…

  • CVE-2023-29508HigApr 16, 2023
    risk 0.58cvss 8.9epss 0.00

    XWiki Commons are technical libraries common to several other top level XWiki projects. A user without script rights can introduce a stored XSS by using the Live Data macro, if the last author of the content of the page has script rights. This has been patched in XWiki 14.10,…

  • CVE-2022-44724HigNov 4, 2022
    risk 0.58cvss 8.9epss 0.01

    The Handy Tip macro in Stiltsoft Handy Macros for Confluence Server/Data Center 3.x before 3.5.5 allows remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability.

  • CVE-2022-38545CriSep 19, 2022
    risk 0.58cvss 9.6epss 0.33

    Valine v1.4.18 was discovered to contain a remote code execution (RCE) vulnerability which allows attackers to execute arbitrary code via a crafted POST request.

  • CVE-2022-39824HigSep 5, 2022
    risk 0.58cvss 8.9epss 0.01

    Server-side JavaScript injection in Appsmith through 1.7.14 allows remote attackers to execute arbitrary JavaScript code from the server via the currentItem property of the list widget, e.g., to perform DoS attacks or achieve an information leak.

  • CVE-2022-24384HigMar 14, 2022
    risk 0.58cvss 8.8epss 0.04

    Cross-site Scripting (XSS) vulnerability in SmarterTools SmarterTrack This issue affects: SmarterTools SmarterTrack 100.0.8019.14010.

  • CVE-2021-39199CriSep 7, 2021
    risk 0.58cvss 10.0epss 0.01

    remark-html is an open source nodejs library which compiles Markdown to HTML. In affected versions the documentation of remark-html has mentioned that it was safe by default. In practice the default was never safe and had to be opted into. That is, user input was not sanitized.…

  • CVE-2021-32798CriAug 9, 2021
    risk 0.58cvss 10.0epss 0.02

    The Jupyter notebook is a web-based notebook environment for interactive computing. In affected versions untrusted notebook can execute code on load. Jupyter Notebook uses a deprecated version of Google Caja to sanitize user inputs. A public Caja bypass can be used to trigger an…

  • CVE-2020-24897HigAug 29, 2020
    risk 0.58cvss 8.9epss 0.01

    The Table Filter and Charts for Confluence Server app before 5.3.25 (for Atlassian Confluence) allow remote attackers to inject arbitrary HTML or JavaScript via cross site scripting (XSS) through the provided Markdown markup to the "Table from CSV" macro.

  • CVE-2020-8775HigApr 29, 2020
    risk 0.58cvss 8.9epss 0.01

    Pega Platform before version 8.2.6 is affected by a Stored Cross-Site Scripting (XSS) vulnerability in the comment tags.

  • CVE-2020-8773HigApr 29, 2020
    risk 0.58cvss 8.9epss 0.01

    The Richtext Editor in Pega Platform before 8.2.6 is affected by a Stored Cross-Site Scripting (XSS) vulnerability.

  • CVE-2019-0668HigMar 5, 2019
    risk 0.58cvss 8.8epss 0.03

    An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft SharePoint Elevation of Privilege Vulnerability'.