VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (46,817)

page 264 of 2,341
  • CVE-2021-43062MedFeb 2, 2022
    risk 0.44cvss 6.1epss 0.13

    A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiMail version 7.0.1 and 7.0.0, version 6.4.5 and below, version 6.3.7 and below, version 6.0.11 and below allows attacker to execute unauthorized code or commands via crafted…

  • CVE-2021-24926MedFeb 1, 2022
    risk 0.44cvss 6.1epss 0.13

    The Domain Check WordPress plugin before 1.0.17 does not sanitise and escape the domain parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting issue

  • CVE-2021-43942MedJan 4, 2022
    risk 0.44cvss 6.1epss 0.55

    Affected versions of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript via a Reflected Cross-Site Scripting (XSS) vulnerability in the /rest/collectors/1.0/template/custom endpoint. To exploit this issue, the attacker must trick…

  • CVE-2021-43991MedDec 3, 2021
    risk 0.44cvss 6.8epss 0.01

    The Kentico Xperience CMS version 13.0 – 13.0.43 is vulnerable to a persistent Cross-Site Scripting (XSS) vulnerability (also known as Stored or Second-Order XSS). Persistent XSS vulnerabilities occur when the application stores and retrieves client supplied data without…

  • CVE-2021-41156MedOct 18, 2021
    risk 0.44cvss 6.8epss 0.00

    anuko/timetracker is an, open source time tracking system. In affected versions Time Tracker uses browser_today hidden control on a few pages to collect the today's date from user browsers. Because of not checking this parameter for sanity in versions prior to 1.19.30.5601, it…

  • CVE-2021-24488MedAug 2, 2021
    risk 0.44cvss 6.1epss 0.11

    The slider import search feature and tab parameter of the Post Grid WordPress plugin before 2.1.8 settings are not properly sanitised before being output back in the pages, leading to Reflected Cross-Site Scripting issues

  • CVE-2021-32750MedJul 15, 2021
    risk 0.44cvss 6.8epss 0.01

    MuWire is a file publishing and networking tool that protects the identity of its users by using I2P technology. Users of MuWire desktop client prior to version 0.8.8 can be de-anonymized by an attacker who knows their full ID. An attacker could send a message with a subject…

  • CVE-2021-24286MedMay 14, 2021
    risk 0.44cvss 6.1epss 0.14

    The settings page of the Redirect 404 to parent WordPress plugin before 1.3.1 did not properly sanitise the tab parameter before outputting it back, leading to a reflected Cross-Site Scripting issue

  • CVE-2021-24276MedMay 5, 2021
    risk 0.44cvss 6.1epss 0.16

    The Contact Form by Supsystic WordPress plugin before 1.7.15 did not sanitise the tab parameter of its options page before outputting it in an attribute, leading to a reflected Cross-Site Scripting issue

  • CVE-2021-24275MedMay 5, 2021
    risk 0.44cvss 6.1epss 0.18

    The Popup by Supsystic WordPress plugin before 1.10.5 did not sanitise the tab parameter of its options page before outputting it in an attribute, leading to a reflected Cross-Site Scripting issue

  • CVE-2021-24274MedMay 5, 2021
    risk 0.44cvss 6.1epss 0.18

    The Ultimate Maps by Supsystic WordPress plugin before 1.2.5 did not sanitise the tab parameter of its options page before outputting it in an attribute, leading to a reflected Cross-Site Scripting issue

  • CVE-2021-25161MedMar 30, 2021
    risk 0.44cvss 6.1epss 0.16

    A remote cross-site scripting (xss) vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba Instant 6.4.x: 6.4.4.8-4.2.4.17 and below; Aruba Instant 6.5.x: 6.5.4.18 and below; Aruba Instant 8.3.x: 8.3.0.14 and below; Aruba Instant…

  • CVE-2020-15221MedJan 13, 2021
    risk 0.44cvss 6.8epss 0.01

    Combodo iTop is a web based IT Service Management tool. In iTop before versions 2.7.2 and 3.0.0, by modifying target browser local storage, an XSS can be generated in the iTop console breadcrumb. This is fixed in versions 2.7.2 and 3.0.0.

  • CVE-2020-29395MedNov 30, 2020
    risk 0.44cvss 6.1epss 0.13

    The EventON plugin through 3.0.5 for WordPress allows addons/?q= XSS via the search field.

  • CVE-2020-28351MedNov 9, 2020
    risk 0.44cvss 6.1epss 0.16

    The conferencing component on Mitel ShoreTel 19.46.1802.0 devices could allow an unauthenticated attacker to conduct a reflected cross-site scripting (XSS) attack (via the PATH_INFO to index.php) due to insufficient validation for the time_zone object in the HOME_MEETING& page.

  • CVE-2020-9738MedSep 10, 2020
    risk 0.44cvss 6.8epss 0.02

    AEM versions 6.5.5.0 (and below), 6.4.8.1 (and below), 6.3.3.8 (and below) and 6.2 SP1-CFP20 (and below) are affected by a stored XSS vulnerability that allows users with access to the Content Repository Development Environment to store malicious scripts in certain node fields.…

  • CVE-2020-9737MedSep 10, 2020
    risk 0.44cvss 6.8epss 0.02

    AEM versions 6.5.5.0 (and below), 6.4.8.1 (and below), 6.3.3.8 (and below) and 6.2 SP1-CFP20 (and below) are affected by a stored XSS vulnerability that allows users with access to the Content Repository Development Environment to store malicious scripts in certain node fields.…

  • CVE-2020-9736MedSep 10, 2020
    risk 0.44cvss 6.8epss 0.02

    AEM versions 6.5.5.0 (and below), 6.4.8.1 (and below), 6.3.3.8 (and below) and 6.2 SP1-CFP20 (and below) are affected by a stored XSS vulnerability that allows users with access to the Content Repository Development Environment to store malicious scripts in certain node fields.…

  • CVE-2020-9735MedSep 10, 2020
    risk 0.44cvss 6.8epss 0.02

    AEM versions 6.5.5.0 (and below), 6.4.8.1 (and below), 6.3.3.8 (and below) and 6.2 SP1-CFP20 (and below) are affected by a stored XSS vulnerability that allows users with access to the Content Repository Development Environment to store malicious scripts in certain node fields.…

  • CVE-2020-24223MedAug 30, 2020
    risk 0.44cvss 6.1epss 0.15

    Mara CMS 7.5 allows cross-site scripting (XSS) in contact.php via the theme or pagetheme parameters.