CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Description
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85
CVEs mapped to this weakness (46,817)
page 268 of 2,341| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-0448 | Med | 0.43 | 6.1 | 0.43 | Jan 26, 2023 | The WP Helper Lite WordPress plugin, in versions < 4.3, returns all GET parameters unsanitized in the response, resulting in a reflected cross-site scripting vulnerability. | ||
| CVE-2022-41441 | Med | 0.43 | 6.1 | 0.05 | Jan 20, 2023 | Multiple cross-site scripting (XSS) vulnerabilities in ReQlogic v11.3 allow attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the POBatch and WaitDuration parameters. | ||
| CVE-2023-0214 | Med | 0.43 | 6.1 | 0.02 | Jan 18, 2023 | A cross-site scripting vulnerability in Skyhigh SWG in main releases 11.x prior to 11.2.6, 10.x prior to 10.2.17, and controlled release 12.x prior to 12.0.1 allows a remote attacker to craft SWG-specific internal requests with URL paths to any third-party website, causing… | ||
| CVE-2022-39195 | Med | 0.43 | 6.1 | 0.06 | Jan 17, 2023 | A cross-site scripting (XSS) vulnerability in the LISTSERV 17 web interface allows remote attackers to inject arbitrary JavaScript or HTML via the c parameter. | ||
| CVE-2022-48197 | Med | 0.43 | 6.1 | 0.07 | Jan 2, 2023 | Reflected cross-site scripting (XSS) exists in Sandbox examples in the YUI2 repository. The download distributions, TreeView component and the YUI Javascript library overall are not affected. NOTE: This vulnerability only affects products that are no longer supported by the… | ||
| CVE-2022-30519 | Med | 0.43 | 6.1 | 0.03 | Dec 29, 2022 | XSS in signing form in Reprise Software RLM License Administration v14.2BL4 allows remote attacker to inject arbitrary code via password field. | ||
| CVE-2022-36664 | Med | 0.43 | 6.1 | 0.04 | Dec 26, 2022 | Password Manager for IIS 2.0 has a cross-site scripting (XSS) vulnerability via the /isapi/PasswordManager.dll ResultURL parameter. | ||
| CVE-2022-35155 | Med | 0.43 | 6.1 | 0.02 | Sep 30, 2022 | Bus Pass Management System v1.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the searchdata parameter. | ||
| CVE-2022-3062 | Med | 0.43 | 6.1 | 0.44 | Sep 26, 2022 | The Simple File List WordPress plugin before 4.4.12 does not escape parameters before outputting them back in attributes, leading to Reflected Cross-Site Scripting | ||
| CVE-2022-28598 | Med | 0.43 | 6.1 | 0.04 | Aug 22, 2022 | Frappe ERPNext 12.29.0 is vulnerable to XSS where the software does not neutralize or incorrectly neutralize user-controllable input before it is placed in output that is used as a web page that is served to other users. | ||
| CVE-2022-34048 | Med | 0.43 | 6.1 | 0.06 | Jul 20, 2022 | Wavlink WN533A8 M33A8.V5030.190716 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the login_page parameter. | ||
| CVE-2022-29296 | Med | 0.43 | 6.1 | 0.02 | Jun 6, 2022 | A reflected cross-site scripting (XSS) vulnerability in the login portal of Avantune Genialcloud ProJ - 10 allows attackers to execute arbitrary web scripts or HTML via a crafted payload. | ||
| CVE-2021-27781 | Med | 0.43 | 6.6 | 0.00 | May 27, 2022 | The Master operator may be able to embed script tag in HTML with alert pop-up display cookie. | ||
| CVE-2022-28818 | Med | 0.43 | 6.1 | 0.44 | May 12, 2022 | ColdFusion versions CF2021U3 (and earlier) and CF2018U13 are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the… | ||
| CVE-2021-31674 | Med | 0.43 | 6.1 | 0.04 | May 2, 2022 | Cyclos 4 PRO 4.14.7 and before does not validate user input at error inform, which allows remote unauthenticated attacker to execute javascript code via undefine enum constant. | ||
| CVE-2021-31673 | Med | 0.43 | 6.1 | 0.03 | May 2, 2022 | A Dom-based Cross-site scripting (XSS) vulnerability at registration account in Cyclos 4 PRO.14.7 and before allows remote attackers to inject arbitrary web script or HTML via the groupId parameter. | ||
| CVE-2021-43009 | Med | 0.43 | 6.1 | 0.02 | Apr 8, 2022 | A Cross Site Scripting (XSS) vulnerability exists in OpServices OpMon through 9.11 via the search parameter in the request URL. | ||
| CVE-2022-24181 | Med | 0.43 | 6.1 | 0.06 | Apr 1, 2022 | Cross-site scripting (XSS) via Host Header injection in PKP Open Journals System 2.4.8 >= 3.3 allows remote attackers to inject arbitary code via the X-Forwarded-Host Header. | ||
| CVE-2021-20323 | Med | 0.43 | 6.1 | 0.37 | Mar 25, 2022 | A POST based reflected Cross Site Scripting vulnerability on has been identified in Keycloak. | ||
| CVE-2022-26263 | Med | 0.43 | 6.1 | 0.42 | Mar 25, 2022 | Yonyou u8 v13.0 was discovered to contain a DOM-based cross-site scripting (XSS) vulnerability via the component /u8sl/WebHelp. |
- risk 0.43cvss 6.1epss 0.43
The WP Helper Lite WordPress plugin, in versions < 4.3, returns all GET parameters unsanitized in the response, resulting in a reflected cross-site scripting vulnerability.
- risk 0.43cvss 6.1epss 0.05
Multiple cross-site scripting (XSS) vulnerabilities in ReQlogic v11.3 allow attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the POBatch and WaitDuration parameters.
- risk 0.43cvss 6.1epss 0.02
A cross-site scripting vulnerability in Skyhigh SWG in main releases 11.x prior to 11.2.6, 10.x prior to 10.2.17, and controlled release 12.x prior to 12.0.1 allows a remote attacker to craft SWG-specific internal requests with URL paths to any third-party website, causing…
- risk 0.43cvss 6.1epss 0.06
A cross-site scripting (XSS) vulnerability in the LISTSERV 17 web interface allows remote attackers to inject arbitrary JavaScript or HTML via the c parameter.
- risk 0.43cvss 6.1epss 0.07
Reflected cross-site scripting (XSS) exists in Sandbox examples in the YUI2 repository. The download distributions, TreeView component and the YUI Javascript library overall are not affected. NOTE: This vulnerability only affects products that are no longer supported by the…
- risk 0.43cvss 6.1epss 0.03
XSS in signing form in Reprise Software RLM License Administration v14.2BL4 allows remote attacker to inject arbitrary code via password field.
- risk 0.43cvss 6.1epss 0.04
Password Manager for IIS 2.0 has a cross-site scripting (XSS) vulnerability via the /isapi/PasswordManager.dll ResultURL parameter.
- risk 0.43cvss 6.1epss 0.02
Bus Pass Management System v1.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the searchdata parameter.
- risk 0.43cvss 6.1epss 0.44
The Simple File List WordPress plugin before 4.4.12 does not escape parameters before outputting them back in attributes, leading to Reflected Cross-Site Scripting
- risk 0.43cvss 6.1epss 0.04
Frappe ERPNext 12.29.0 is vulnerable to XSS where the software does not neutralize or incorrectly neutralize user-controllable input before it is placed in output that is used as a web page that is served to other users.
- risk 0.43cvss 6.1epss 0.06
Wavlink WN533A8 M33A8.V5030.190716 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the login_page parameter.
- risk 0.43cvss 6.1epss 0.02
A reflected cross-site scripting (XSS) vulnerability in the login portal of Avantune Genialcloud ProJ - 10 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
- risk 0.43cvss 6.6epss 0.00
The Master operator may be able to embed script tag in HTML with alert pop-up display cookie.
- risk 0.43cvss 6.1epss 0.44
ColdFusion versions CF2021U3 (and earlier) and CF2018U13 are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the…
- risk 0.43cvss 6.1epss 0.04
Cyclos 4 PRO 4.14.7 and before does not validate user input at error inform, which allows remote unauthenticated attacker to execute javascript code via undefine enum constant.
- risk 0.43cvss 6.1epss 0.03
A Dom-based Cross-site scripting (XSS) vulnerability at registration account in Cyclos 4 PRO.14.7 and before allows remote attackers to inject arbitrary web script or HTML via the groupId parameter.
- risk 0.43cvss 6.1epss 0.02
A Cross Site Scripting (XSS) vulnerability exists in OpServices OpMon through 9.11 via the search parameter in the request URL.
- risk 0.43cvss 6.1epss 0.06
Cross-site scripting (XSS) via Host Header injection in PKP Open Journals System 2.4.8 >= 3.3 allows remote attackers to inject arbitary code via the X-Forwarded-Host Header.
- risk 0.43cvss 6.1epss 0.37
A POST based reflected Cross Site Scripting vulnerability on has been identified in Keycloak.
- risk 0.43cvss 6.1epss 0.42
Yonyou u8 v13.0 was discovered to contain a DOM-based cross-site scripting (XSS) vulnerability via the component /u8sl/WebHelp.