VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (46,610)

page 251 of 2,331
  • CVE-2025-55742HigAug 21, 2025
    risk 0.45cvss 8.0epss 0.00

    UnoPim is an open-source Product Information Management (PIM) system built on the Laravel framework. Before 0.2.1, UnoPim contains a stored cross-site scripting vulnerability via SVG MIME/sanitizer bypass in the /admin/settings/users/create endpoint. This vulnerability is fixed…

  • CVE-2025-53924MedJul 16, 2025
    risk 0.45cvss 6.9epss 0.00

    Emlog is an open source website building system. A cross-site scripting (XSS) vulnerability in emlog up to and including pro-2.5.17 allows authenticated remote attackers to inject arbitrary web script or HTML via the siteurl parameter. It is possible to inject malicious code…

  • CVE-2025-53121MedJun 26, 2025
    risk 0.45cvss epss 0.00

    Multiple stored XSS were found on different nodes with unsanitized parameters in OpenMNS Horizon 33.0.8 and versions earlier than 33.1.6 on multiple platforms that allow an attacker to store on database and then inject HTML and/or Javascript on the page. The solution is to…

  • CVE-2025-48700MedKEVJun 23, 2025
    risk 0.45cvss 6.1epss 0.02

    An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0 and 10.0 and 10.1. A Cross-Site Scripting (XSS) vulnerability in the Zimbra Classic UI allows attackers to execute arbitrary JavaScript within the user's session, potentially leading to unauthorized access to…

  • CVE-2024-25573MedJun 15, 2025
    risk 0.45cvss epss 0.00

    Unsanitized user-supplied data saved in the PingFederate Administrative Console could trigger the execution of JavaScript code in subsequent user processing.

  • CVE-2025-5806HigJun 6, 2025
    risk 0.45cvss 8.0epss 0.00

    Jenkins Gatling Plugin 136.vb_9009b_3d33a_e serves Gatling reports in a manner that bypasses the Content-Security-Policy protection introduced in Jenkins 1.641 and 1.625, resulting in a cross-site scripting (XSS) vulnerability exploitable by users able to change report content.

  • CVE-2025-22244MedJun 4, 2025
    risk 0.45cvss 6.9epss 0.00

    VMware NSX contains a stored Cross-Site Scripting (XSS) vulnerability in the gateway firewall due to improper input validation.

  • CVE-2025-2703MedApr 23, 2025
    risk 0.45cvss 6.8epss 0.18

    The built-in XY Chart plugin is vulnerable to a DOM XSS vulnerability. A user with Editor permissions is able to modify such a panel in order to make it execute arbitrary JavaScript.

  • CVE-2025-30676MedApr 1, 2025
    risk 0.45cvss 6.1epss 0.67

    Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 18.12.19. Users are recommended to upgrade to version 18.12.19, which fixes the issue.

  • CVE-2025-31165MedMar 27, 2025
    risk 0.45cvss epss 0.00

    Cross-Site Scripting (XSS) vulnerability in the Logbug module of NightWolf Penetration Testing Platform 1.2.2 allows attackers to execute JavaScript through the markdown editor feature.

  • CVE-2024-13919HigMar 10, 2025
    risk 0.45cvss 8.0epss 0.01

    The Laravel framework versions between 11.9.0 and 11.35.1 are susceptible to reflected cross-site scripting due to an improper encoding of route parameters in the debug-mode error page.

  • CVE-2024-13918HigMar 10, 2025
    risk 0.45cvss 8.0epss 0.01

    The Laravel framework versions between 11.9.0 and 11.35.1 are susceptible to reflected cross-site scripting due to an improper encoding of request parameters in the debug-mode error page.

  • CVE-2024-50599MedNov 7, 2024
    risk 0.45cvss 6.1epss 0.61

    A reflected Cross-Site Scripting (XSS) vulnerability has been identified in Zimbra Collaboration Suite (ZCS) 8.8.15, affecting one of the webmail calendar endpoints. This arises from improper handling of user-supplied input, allowing an attacker to inject malicious code that is…

  • CVE-2024-43612MedOct 8, 2024
    risk 0.45cvss 6.9epss 0.01

    Power BI Report Server Spoofing Vulnerability

  • CVE-2024-24494MedFeb 8, 2024
    risk 0.45cvss 6.1epss 0.26

    Cross Site Scripting vulnerability in Daily Habit Tracker v.1.0 allows a remote attacker to execute arbitrary code via the day, exercise, pray, read_book, vitamins, laundry, alcohol and meat parameters in the add-tracker.php and update-tracker.php components.

  • CVE-2023-51739MedJan 17, 2024
    risk 0.45cvss 6.9epss 0.00

    This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to insufficient validation of user supplied input for the Device Name parameter at its web interface. A remote attacker could exploit this vulnerability by supplying specially crafted input to the…

  • CVE-2023-51738MedJan 17, 2024
    risk 0.45cvss 6.9epss 0.00

    This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to insufficient validation of user supplied input for the Network Name (SSID) parameter at its web interface. A remote attacker could exploit this vulnerability by supplying specially crafted input to the…

  • CVE-2023-51737MedJan 17, 2024
    risk 0.45cvss 6.9epss 0.00

    This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to insufficient validation of user supplied input for the Preshared Phrase parameter at its web interface. A remote attacker could exploit this vulnerability by supplying specially crafted input to the…

  • CVE-2023-51736MedJan 17, 2024
    risk 0.45cvss 6.9epss 0.00

    This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to insufficient validation of user supplied input for the L2TP/PPTP Username parameter at its web interface. A remote attacker could exploit this vulnerability by supplying specially crafted input to the…

  • CVE-2023-51735MedJan 17, 2024
    risk 0.45cvss 6.9epss 0.00

    This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to insufficient validation of user supplied input for the Pre-shared key parameter at its web interface. A remote attacker could exploit this vulnerability by supplying specially crafted input to the…