VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (46,610)

page 245 of 2,331
  • CVE-2022-45825HigMar 28, 2023
    risk 0.46cvss 7.1epss 0.01

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in iThemes WPComplete plugin <= 2.9.2 versions.

  • CVE-2022-47146HigMar 27, 2023
    risk 0.46cvss 7.1epss 0.00

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Contempoinc Real Estate 7 WordPress theme <= 3.3.1 versions.

  • CVE-2022-46843HigMar 27, 2023
    risk 0.46cvss 7.1epss 0.00

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Le Van Toan Woocommerce Vietnam Checkout plugin <= 2.0.4 versions.

  • CVE-2022-47145HigMar 23, 2023
    risk 0.46cvss 7.1epss 0.00

    Reflected Cross-Site Scripting (XSS) vulnerability in Blockonomics WordPress Bitcoin Payments – Blockonomics plugin <= 3.5.7 versions.

  • CVE-2023-22704HigMar 23, 2023
    risk 0.46cvss 7.1epss 0.00

    Reflected Cross-Site Scripting (XSS) vulnerability in Michael Winkler teachPress plugin <= 8.1.8 versions.

  • CVE-2022-47431HigMar 23, 2023
    risk 0.46cvss 7.1epss 0.00

    Reflected Cross-Site Scripting (XSS) vulnerability in Tussendoor internet & marketing Open RDW kenteken voertuiginformatie plugin <= 2.0.14 versions.

  • CVE-2023-25593HigMar 22, 2023
    risk 0.46cvss 7.1epss 0.00

    Vulnerabilities within the web-based management interface of ClearPass Policy Manager could allow a remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the interface. A successful exploit allows an attacker to execute arbitrary script code…

  • CVE-2023-25592HigMar 22, 2023
    risk 0.46cvss 7.1epss 0.00

    Vulnerabilities within the web-based management interface of ClearPass Policy Manager could allow a remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the interface. A successful exploit allows an attacker to execute arbitrary script code…

  • CVE-2022-47591HigMar 20, 2023
    risk 0.46cvss 7.1epss 0.00

    Reflected Cross-Site Scripting (XSS) vulnerability in Mickael Austoni Map Multi Marker plugin <= 3.2.1 versions.

  • CVE-2023-22682HigMar 20, 2023
    risk 0.46cvss 7.1epss 0.00

    Reflected Cross-Site Scripting (XSS) vulnerability in Manuel Masia | Pixedelic.Com Camera slideshow plugin <= 1.4.0.1 versions.

  • CVE-2022-47592HigMar 20, 2023
    risk 0.46cvss 7.1epss 0.00

    Reflected Cross-Site Scripting (XSS) vulnerability in Dmytriy.Cooperman MagicForm plugin <= 0.1 versions.

  • CVE-2021-36821HigMar 16, 2023
    risk 0.46cvss 7.1epss 0.00

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WPMU DEV Forminator allows Stored XSS.This issue affects Forminator: from n/a through 1.14.11.

  • CVE-2023-24810HigFeb 22, 2023
    risk 0.46cvss 7.1epss 0.00

    Misskey is an open source, decentralized social media platform. Due to insufficient validation of the redirect URL during `miauth` authentication in Misskey, arbitrary JavaScript can be executed when a user allows the link. All versions below 13.3.1 (including 12.x) are…

  • CVE-2023-25154HigFeb 22, 2023
    risk 0.46cvss 7.1epss 0.00

    Misskey is an open source, decentralized social media platform. In versions prior to 13.5.0 the link to the instance to the sender that appears when viewing a user or note received through ActivityPub is not properly validated, so by inserting a URL with a javascript scheme an…

  • CVE-2023-22638HigFeb 16, 2023
    risk 0.46cvss 7.1epss 0.00

    Several improper neutralization of inputs during web page generation vulnerability [CWE-79] in FortiNAC 9.4.1 and below, 9.2.6 and below, 9.1.8 and below, 8.8.11 and below, 8.7.6 and below, 8.6.5 and below, 8.5.4 and below, 8.3.7 and below may allow an authenticated attacker to…

  • CVE-2023-21564HigFeb 14, 2023
    risk 0.46cvss 7.1epss 0.01

    Azure DevOps Server Cross-Site Scripting Vulnerability

  • CVE-2023-0787HigFeb 12, 2023
    risk 0.46cvss 8.1epss 0.01

    Cross-site Scripting (XSS) - Generic in GitHub repository thorsten/phpmyfaq prior to 3.1.11.

  • CVE-2023-23074MedFeb 1, 2023
    risk 0.46cvss 6.1epss 0.84

    Cross site scripting (XSS) vulnerability in Zoho ManageEngine ServiceDesk Plus 14 via embedding videos in the language component.

  • CVE-2022-46670HigDec 16, 2022
    risk 0.46cvss 7.1epss 0.01

    Rockwell Automation was made aware of a vulnerability by a security researcher from Georgia Institute of Technology that the MicroLogix 1100 and 1400 controllers contain a vulnerability that may give an attacker the ability to accomplish remote code execution.  The…

  • CVE-2022-46148HigNov 29, 2022
    risk 0.46cvss 7.1epss 0.00

    Discourse is an open-source messaging platform. In versions 2.8.10 and prior on the `stable` branch and versions 2.9.0.beta11 and prior on the `beta` and `tests-passed` branches, users composing malicious messages and navigating to drafts page could self-XSS. This vulnerability…