VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (46,610)

page 254 of 2,331
  • CVE-2020-15178HigSep 15, 2020
    risk 0.45cvss 8.0epss 0.01

    In PrestaShop contactform module (prestashop/contactform) before version 4.3.0, an attacker is able to inject JavaScript while using the contact form. The `message` field was incorrectly unescaped, possibly allowing attackers to execute arbitrary JavaScript in a victim's browser.

  • CVE-2020-23835MedSep 1, 2020
    risk 0.45cvss 6.4epss 0.02

    A Reflected Cross-Site Scripting (XSS) vulnerability in the index.php login-portal webpage of SourceCodester Tailor Management System v1.0 allows remote attackers to harvest keys pressed by an unauthenticated victim who clicks on a malicious URL and begins typing.

  • CVE-2019-11999MedApr 16, 2020
    risk 0.45cvss 6.9epss 0.01

    Potential security vulnerabilities have been identified in HPE OpenCall Media Platform (OCMP) resulting in remote arbitrary file download and cross site scripting. HPE has made the following updates available to resolve the vulnerability in the impacted versions of OCMP. * For…

  • CVE-2019-14974MedAug 14, 2019
    risk 0.45cvss 6.1epss 0.19

    SugarCRM Enterprise 9.0.0 allows mobile/error-not-supported-platform.html?desktop_url= XSS.

  • CVE-2018-16833MedSep 21, 2018
    risk 0.45cvss 6.1epss 0.52

    Zoho ManageEngine Desktop Central 10.0.271 has XSS via the "Features & Articles" search field to the /advsearch.do?SUBREQUEST=XMLHTTP URI.

  • CVE-2018-8046MedJul 5, 2018
    risk 0.45cvss 6.1epss 0.43

    The getTip() method of Action Columns of Sencha Ext JS 4 to 6 before 6.6.0 is vulnerable to XSS attacks, even when passed HTML-escaped data. This framework brings no built-in XSS protection, so the developer has to ensure that data is correctly sanitized. However, the getTip()…

  • CVE-2015-6005MedDec 27, 2015
    risk 0.45cvss 6.9epss 0.02

    Multiple cross-site scripting (XSS) vulnerabilities in IPSwitch WhatsUp Gold before 16.4 allow remote attackers to inject arbitrary web script or HTML via (1) an SNMP OID object, (2) an SNMP trap message, (3) the View Names field, (4) the Group Names field, (5) the Flow Monitor…

  • CVE-2026-19226MedAug 26, 2026
    risk 0.44cvss 6.8epss 0.00

    The Royal Addons for Elementor WordPress plugin before 1.7.1066 does not validate some widget settings before outputting them inside an HTML attribute, which could allow users with the Contributor role and above to perform Stored Cross-Site Scripting attacks.

  • CVE-2026-17033MedAug 24, 2026
    risk 0.44cvss 6.8epss 0.00

    An authenticated attacker with Editor access or alert.instances.external:write can submit an external Alertmanager alert containing a controlled generatorURL. The attacker is authorized to create the alert, but not to execute script in another user's Grafana session. Grafana…

  • CVE-2026-16260MedAug 22, 2026
    risk 0.44cvss 6.8epss 0.00

    The Post Grid, Slider & Carousel Ultimate WordPress plugin before 1.8.1 does not sanitise and escape one of its custom post type settings before outputting it in an HTML attribute on the admin edit screen, allowing users with the Contributor role and above to inject JavaScript…

  • CVE-2026-74992MedAug 20, 2026
    risk 0.44cvss 6.8epss 0.00

    The Kirki WordPress plugin before 6.2.3 does not properly validate the files contained in archives uploaded by users with the Editor role, and does not remove all unwanted files after extracting them, allowing such users to upload arbitrary files to a web accessible directory,…

  • CVE-2026-19697MedAug 20, 2026
    risk 0.44cvss 6.8epss 0.00

    The GutenKit WordPress plugin before 2.5.0 does not sanitise uploaded SVG files on all of the upload paths it enables, allowing users with the file upload capability, such as Author, to upload a malicious SVG and perform Stored Cross-Site Scripting attacks against any user…

  • CVE-2026-19615MedAug 20, 2026
    risk 0.44cvss 6.8epss 0.00

    The Admin and Site Enhancements (ASE) WordPress plugin before 9.0.1 does not sanitise uploaded SVG files on every route it accepts them through, allowing users with a role the site owner granted upload access to store a file containing JavaScript which then executes in the…

  • CVE-2026-76252MedAug 19, 2026
    risk 0.44cvss 6.8epss 0.00

    In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.13, an unauthenticated user who tricks another user into visiting a malicious web page could run unauthorized JavaScript in that user's browser. This could allow for unauthorized access to all relevant data…

  • CVE-2026-18202MedAug 19, 2026
    risk 0.44cvss 6.8epss 0.00

    The JetEngine WordPress plugin before 3.8.14 adds SVG to the site-wide list of allowed upload types without sanitising the file contents, allowing users with the upload files capability, such as Authors, to upload a file containing malicious JavaScript that executes in the…

  • CVE-2026-15253MedAug 19, 2026
    risk 0.44cvss 6.8epss 0.00

    The Easy Media Replace WordPress plugin through 0.2.0 does not sanitise and escape an attachment title before outputting it in an HTML attribute in the media library list view, allowing users with the Author role and above to inject arbitrary web scripts that are executed in the…

  • CVE-2025-9211MedAug 18, 2026
    risk 0.44cvss 6.7epss 0.00

    Unescaped stored values in application security page in Otalio Ship Property Management System versions before 2.22.0 allows authenticated attackers to escalate privileges via persistent cross-site scripting

  • CVE-2026-14290MedAug 14, 2026
    risk 0.44cvss 6.8epss 0.00

    The Embed Google Photos album WordPress plugin through 2.2.1 does not escape a shortcode attribute value before outputting it inside an HTML attribute, allowing users with the Contributor role or above to inject arbitrary JavaScript that executes in the browser of any user,…

  • CVE-2026-57279MedAug 10, 2026
    risk 0.44cvss 6.8epss 0.00

    Cybozu Garoon contains a cross-site scripting vulnerability. If this vulnerability is exploited, an arbitrary script may be executed in the web browser of a user logged in to the product.

  • CVE-2026-15047MedAug 10, 2026
    risk 0.44cvss 6.8epss 0.00

    The s2Member WordPress plugin before 260805 does not escape several shortcode attributes before outputting them inside an inline script context, allowing users with contributor-level access to inject arbitrary JavaScript that executes when a viewer opens the post (stored XSS).