VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (46,610)

page 258 of 2,331
  • CVE-2024-2907MedApr 25, 2024
    risk 0.44cvss 6.8epss 0.01

    The AGCA WordPress plugin before 7.2.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

  • CVE-2024-2761MedApr 19, 2024
    risk 0.44cvss 6.8epss 0.01

    The Genesis Blocks WordPress plugin before 3.1.3 does not properly escape data input provided to some of its blocks, allowing using with at least contributor privileges to conduct Stored XSS attacks.

  • CVE-2024-32326MedApr 18, 2024
    risk 0.44cvss 6.8epss 0.01

    TOTOLINK EX200 V4.0.3c.7646_B20201211 contains a Cross-site scripting (XSS) vulnerability through the key parameter in the setWiFiExtenderConfig function.

  • CVE-2024-32344MedApr 17, 2024
    risk 0.44cvss 6.8epss 0.01

    A cross-site scripting (XSS) vulnerability in the Settings menu of CMSimple v5.15 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Edit parameter under the Language section.

  • CVE-2024-30988MedApr 17, 2024
    risk 0.44cvss 6.8epss 0.01

    Cross Site Scripting vulnerability in /search-invoices.php of phpgurukul Client Management System using PHP & MySQL 1.1 allows attackers to execute arbitrary code and obtain sensitive information via the Search bar.

  • CVE-2024-30987MedApr 17, 2024
    risk 0.44cvss 6.8epss 0.01

    Cross Site Scripting vulnerability in /bwdates-reports-ds.php of phpgurukul Client Management System using PHP & MySQL 1.1 allows attackers to execute arbitrary code and obtain sensitive information via the fromdate and todate parameters.

  • CVE-2024-26251MedApr 9, 2024
    risk 0.44cvss 6.8epss 0.01

    Microsoft SharePoint Server Spoofing Vulnerability

  • CVE-2024-1588MedApr 8, 2024
    risk 0.44cvss 6.8epss 0.01

    The SendPress Newsletters WordPress plugin through 1.23.11.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example…

  • CVE-2023-49965MedApr 5, 2024
    risk 0.44cvss 6.8epss 0.00

    SpaceX Starlink Wi-Fi router Gen 2 before 2023.48.0 allows XSS via the ssid and password parameters on the Setup Page.

  • CVE-2024-31137MedMar 28, 2024
    risk 0.44cvss 6.8epss 0.00

    In JetBrains TeamCity before 2024.03 reflected XSS was possible via Space connection configuration

  • CVE-2023-49983MedMar 21, 2024
    risk 0.44cvss 6.8epss 0.01

    A cross-site scripting (XSS) vulnerability in the component /management/class of School Fees Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the name parameter.

  • CVE-2024-28070MedMar 16, 2024
    risk 0.44cvss 6.8epss 0.00

    A vulnerability in the legacy chat component of Mitel MiContact Center Business through 10.0.0.4 could allow an unauthenticated attacker to conduct a reflected cross-site scripting (XSS) attack due to insufficient input validation. A successful exploit could allow an attacker to…

  • CVE-2024-21838MedMar 5, 2024
    risk 0.44cvss 6.8epss 0.00

    Improper neutralization of special elements in output (CWE-74) used by the email generation feature of the Command Centre Server could lead to HTML code injection in emails generated by Command Centre. This issue affects: Gallagher Command Centre 9.00 prior to vEL9.00.1774…

  • CVE-2023-26206MedFeb 15, 2024
    risk 0.44cvss 6.8epss 0.00

    An improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiNAC 9.4.0 - 9.4.2, 9.2.0 - 9.2.8, 9.1.0 - 9.1.10 and 7.2.0 allows an attacker to execute unauthorized code or commands via the name fields observed in the policy audit logs.

  • CVE-2024-0007MedFeb 14, 2024
    risk 0.44cvss 6.8epss 0.00

    A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS software enables a malicious authenticated read-write administrator to store a JavaScript payload using the web interface on Panorama appliances. This enables the impersonation of another authenticated…

  • CVE-2023-42476MedDec 12, 2023
    risk 0.44cvss 6.8epss 0.01

    SAP Business Objects Web Intelligence - version 420, allows an authenticated attacker to inject JavaScript code into Web Intelligence documents which is then executed in the victim’s browser each time the vulnerable page is visited. Successful exploitation can lead to…

  • CVE-2023-47505MedNov 30, 2023
    risk 0.44cvss 6.5epss 0.25

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Elementor.Com Elementor allows Cross-Site Scripting (XSS).This issue affects Elementor: from n/a through 3.16.4.

  • CVE-2023-49145HigNov 27, 2023
    risk 0.44cvss 7.9epss 0.01

    Apache NiFi 0.7.0 through 1.23.2 include the JoltTransformJSON Processor, which provides an advanced configuration user interface that is vulnerable to DOM-based cross-site scripting. If an authenticated user, who is authorized to configure a JoltTransformJSON Processor, visits…

  • CVE-2023-47549MedNov 14, 2023
    risk 0.44cvss 6.8epss 0.00

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability on 302 response page in spider-themes EazyDocs plugin <= 2.3.3 versions.

  • CVE-2023-46252MedNov 7, 2023
    risk 0.44cvss 6.8epss 0.00

    Squidex is an open source headless CMS and content management hub. Affected versions are missing origin verification in a postMessage handler which introduces a Cross-Site Scripting (XSS) vulnerability. The editor-sdk.js file defines three different class-like functions, which…