VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (46,817)

page 267 of 2,341
  • CVE-2024-30248HigApr 2, 2024
    risk 0.43cvss 7.7epss 0.00

    Piccolo Admin is an admin interface/content management system for Python, built on top of Piccolo. Piccolo's admin panel allows media files to be uploaded. As a default, SVG is an allowed file type for upload. An attacker can upload an SVG which when loaded can allow arbitrary…

  • CVE-2024-28623MedMar 13, 2024
    risk 0.43cvss 6.1epss 0.01

    RiteCMS v3.0.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component main_menu/edit_section.

  • CVE-2024-27744MedMar 1, 2024
    risk 0.43cvss 6.1epss 0.01

    Cross Site Scripting vulnerability in Petrol Pump Mangement Software v.1.0 allows an attacker to execute arbitrary code via a crafted payload to the image parameter in the profile.php component.

  • CVE-2024-27743MedMar 1, 2024
    risk 0.43cvss 6.1epss 0.01

    Cross Site Scripting vulnerability in Petrol Pump Mangement Software v.1.0 allows an attacker to execute arbitrary code via a crafted payload to the Address parameter in the add_invoices.php component.

  • CVE-2024-26300MedFeb 27, 2024
    risk 0.43cvss 6.6epss 0.00

    A vulnerability in the guest interface of ClearPass Policy Manager could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against an administrative user of the interface. A successful exploit allows an attacker to execute arbitrary…

  • CVE-2024-26299MedFeb 27, 2024
    risk 0.43cvss 6.6epss 0.00

    A vulnerability in the web-based management interface of ClearPass Policy Manager could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against an administrative user of the interface. A successful exploit allows an attacker to…

  • CVE-2023-28025MedDec 21, 2023
    risk 0.43cvss 6.6epss 0.00

    Due to this vulnerability, the Master operator could potentially incorporate an SVG tag into HTML, leading to an alert pop-up displaying a cookie. To mitigate stored XSS vulnerabilities, a preventive measure involves thoroughly sanitizing and validating all user inputs before…

  • CVE-2023-36306MedAug 8, 2023
    risk 0.43cvss 6.1epss 0.05

    A Cross Site Scripting (XSS) vulnerability in Adiscon Aiscon LogAnalyzer through 4.1.13 allows a remote attacker to execute arbitrary code via the asktheoracle.php, details.php, index.php, search.php, export.php, reports.php, and statistics.php components.

  • CVE-2023-28014MedJul 27, 2023
    risk 0.43cvss 6.6epss 0.00

    HCL BigFix Mobile is vulnerable to a cross-site scripting attack. An authenticated attacker could inject malicious scripts into the application.

  • CVE-2023-36163MedJul 11, 2023
    risk 0.43cvss 6.1epss 0.04

    Cross Site Scripting vulnerability in IP-DOT BuildaGate v.BuildaGate5 allows a remote attacker to execute arbitrary code via a crafted script to the mc parameter of the URL.

  • CVE-2023-36346MedJun 23, 2023
    risk 0.43cvss 6.1epss 0.05

    POS Codekop v2.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the nm_member parameter at print.php.

  • CVE-2023-25439MedMay 25, 2023
    risk 0.43cvss 6.1epss 0.02

    Stored Cross Site Scripting (XSS) vulnerability in Square Pig FusionInvoice 2023-1.0, allows attackers to execute arbitrary code via the description or content fields to the expenses, tasks, and customer details.

  • CVE-2023-30256MedMay 11, 2023
    risk 0.43cvss 6.1epss 0.09

    Cross Site Scripting vulnerability found in Webkil QloApps v.1.5.2 allows a remote attacker to obtain sensitive information via the back and email_create parameters in the AuthController.php file.

  • CVE-2023-29515HigApr 19, 2023
    risk 0.43cvss 7.7epss 0.01

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user who can create a space can become admin of that space through App Within Minutes. The admin right implies the script right and thus allows JavaScript injection. The…

  • CVE-2022-47870MedApr 4, 2023
    risk 0.43cvss 6.1epss 0.02

    A Cross Site Scripting (XSS) vulnerability in the web SQL monitor login page in Redgate SQL Monitor 12.1.31.893 allows remote attackers to inject arbitrary web Script or HTML via the returnUrl parameter.

  • CVE-2023-26692MedMar 30, 2023
    risk 0.43cvss 6.1epss 0.03

    ZCBS Zijper Collectie Beheer Systeem (ZCBS), Zijper Publication Management System (ZPBS), and Zijper Image Bank Management System (ZBBS) 4.14k is vulnerable to Cross Site Scripting (XSS).

  • CVE-2023-24657MedMar 8, 2023
    risk 0.43cvss 6.1epss 0.04

    phpipam v1.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the closeClass parameter at /subnet-masks/popup.php.

  • CVE-2022-48110MedFeb 13, 2023
    risk 0.43cvss 6.1epss 0.02

    CKSource CKEditor 5 35.4.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Full Featured CKEditor5 widget. NOTE: the vendor's position is that this is not a vulnerability. The CKEditor 5 documentation discusses that it is the responsibility of an…

  • CVE-2023-23161MedFeb 10, 2023
    risk 0.43cvss 6.1epss 0.06

    A reflected cross-site scripting (XSS) vulnerability in Art Gallery Management System Project v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the artname parameter under ART TYPE option in the navigation bar.

  • CVE-2023-23286MedFeb 10, 2023
    risk 0.43cvss 6.1epss 0.03

    Cross Site Scripting (XSS) vulnerability in Provide server 14.4 allows attackers to execute arbitrary code through the server-log via username field from the login form.