VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (46,817)

page 268 of 2,341
  • CVE-2023-0448MedJan 26, 2023
    risk 0.43cvss 6.1epss 0.43

    The WP Helper Lite WordPress plugin, in versions < 4.3, returns all GET parameters unsanitized in the response, resulting in a reflected cross-site scripting vulnerability.

  • CVE-2022-41441MedJan 20, 2023
    risk 0.43cvss 6.1epss 0.05

    Multiple cross-site scripting (XSS) vulnerabilities in ReQlogic v11.3 allow attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the POBatch and WaitDuration parameters.

  • CVE-2023-0214MedJan 18, 2023
    risk 0.43cvss 6.1epss 0.02

    A cross-site scripting vulnerability in Skyhigh SWG in main releases 11.x prior to 11.2.6, 10.x prior to 10.2.17, and controlled release 12.x prior to 12.0.1 allows a remote attacker to craft SWG-specific internal requests with URL paths to any third-party website, causing…

  • CVE-2022-39195MedJan 17, 2023
    risk 0.43cvss 6.1epss 0.06

    A cross-site scripting (XSS) vulnerability in the LISTSERV 17 web interface allows remote attackers to inject arbitrary JavaScript or HTML via the c parameter.

  • CVE-2022-48197MedJan 2, 2023
    risk 0.43cvss 6.1epss 0.07

    Reflected cross-site scripting (XSS) exists in Sandbox examples in the YUI2 repository. The download distributions, TreeView component and the YUI Javascript library overall are not affected. NOTE: This vulnerability only affects products that are no longer supported by the…

  • CVE-2022-30519MedDec 29, 2022
    risk 0.43cvss 6.1epss 0.03

    XSS in signing form in Reprise Software RLM License Administration v14.2BL4 allows remote attacker to inject arbitrary code via password field.

  • CVE-2022-36664MedDec 26, 2022
    risk 0.43cvss 6.1epss 0.04

    Password Manager for IIS 2.0 has a cross-site scripting (XSS) vulnerability via the /isapi/PasswordManager.dll ResultURL parameter.

  • CVE-2022-35155MedSep 30, 2022
    risk 0.43cvss 6.1epss 0.02

    Bus Pass Management System v1.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the searchdata parameter.

  • CVE-2022-3062MedSep 26, 2022
    risk 0.43cvss 6.1epss 0.44

    The Simple File List WordPress plugin before 4.4.12 does not escape parameters before outputting them back in attributes, leading to Reflected Cross-Site Scripting

  • CVE-2022-28598MedAug 22, 2022
    risk 0.43cvss 6.1epss 0.04

    Frappe ERPNext 12.29.0 is vulnerable to XSS where the software does not neutralize or incorrectly neutralize user-controllable input before it is placed in output that is used as a web page that is served to other users.

  • CVE-2022-34048MedJul 20, 2022
    risk 0.43cvss 6.1epss 0.06

    Wavlink WN533A8 M33A8.V5030.190716 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the login_page parameter.

  • CVE-2022-29296MedJun 6, 2022
    risk 0.43cvss 6.1epss 0.02

    A reflected cross-site scripting (XSS) vulnerability in the login portal of Avantune Genialcloud ProJ - 10 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

  • CVE-2021-27781MedMay 27, 2022
    risk 0.43cvss 6.6epss 0.00

    The Master operator may be able to embed script tag in HTML with alert pop-up display cookie.

  • CVE-2022-28818MedMay 12, 2022
    risk 0.43cvss 6.1epss 0.44

    ColdFusion versions CF2021U3 (and earlier) and CF2018U13 are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the…

  • CVE-2021-31674MedMay 2, 2022
    risk 0.43cvss 6.1epss 0.04

    Cyclos 4 PRO 4.14.7 and before does not validate user input at error inform, which allows remote unauthenticated attacker to execute javascript code via undefine enum constant.

  • CVE-2021-31673MedMay 2, 2022
    risk 0.43cvss 6.1epss 0.03

    A Dom-based Cross-site scripting (XSS) vulnerability at registration account in Cyclos 4 PRO.14.7 and before allows remote attackers to inject arbitrary web script or HTML via the groupId parameter.

  • CVE-2021-43009MedApr 8, 2022
    risk 0.43cvss 6.1epss 0.02

    A Cross Site Scripting (XSS) vulnerability exists in OpServices OpMon through 9.11 via the search parameter in the request URL.

  • CVE-2022-24181MedApr 1, 2022
    risk 0.43cvss 6.1epss 0.06

    Cross-site scripting (XSS) via Host Header injection in PKP Open Journals System 2.4.8 >= 3.3 allows remote attackers to inject arbitary code via the X-Forwarded-Host Header.

  • CVE-2021-20323MedMar 25, 2022
    risk 0.43cvss 6.1epss 0.37

    A POST based reflected Cross Site Scripting vulnerability on has been identified in Keycloak.

  • CVE-2022-26263MedMar 25, 2022
    risk 0.43cvss 6.1epss 0.42

    Yonyou u8 v13.0 was discovered to contain a DOM-based cross-site scripting (XSS) vulnerability via the component /u8sl/WebHelp.