CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Description
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85
CVEs mapped to this weakness (46,817)
page 269 of 2,341| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-22791 | Med | 0.43 | 6.6 | 0.00 | Jan 28, 2022 | SYNEL - eharmony Authenticated Blind & Stored XSS. Inject JS code into the "comments" field could lead to potential stealing of cookies, loading of HTML tags and JS code onto the system. | ||
| CVE-2021-45425 | Med | 0.43 | 6.1 | 0.03 | Dec 28, 2021 | Reflected Cross Site Scripting (XSS) in SAFARI Montage versions 8.3 and 8.5 allows remote attackers to execute JavaScript codes. | ||
| CVE-2021-31558 | Med | 0.43 | 6.5 | 0.11 | Dec 22, 2021 | DIAEnergie Version 1.7.5 and prior is vulnerable to stored cross-site scripting when an unauthenticated user injects arbitrary code into the parameter “descr” of the script “DIAE_hierarchyHandler.ashx”. | ||
| CVE-2021-41183 | Med | 0.43 | 6.5 | 0.09 | Oct 26, 2021 | jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of various `*Text` options of the Datepicker widget from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. The values passed to various… | ||
| CVE-2021-31682 | Med | 0.43 | 6.1 | 0.11 | Oct 22, 2021 | The login portal for the Automated Logic WebCTRL/WebCTRL OEM web application contains a vulnerability that allows for reflected XSS attacks due to the operatorlocale GET parameter not being sanitized. This issue impacts versions 6.5 and below. This issue works by passing in a… | ||
| CVE-2021-35323 | Med | 0.43 | 6.1 | 0.06 | Oct 19, 2021 | Cross Site Scripting (XSS) vulnerability exists in bludit 3-13-1 via the username in admin/login. | ||
| CVE-2021-42566 | Med | 0.43 | 6.1 | 0.06 | Oct 18, 2021 | myfactory.FMS before 7.1-912 allows XSS via the Error parameter. | ||
| CVE-2021-42565 | Med | 0.43 | 6.1 | 0.06 | Oct 18, 2021 | myfactory.FMS before 7.1-912 allows XSS via the UID parameter. | ||
| CVE-2018-16061 | Med | 0.43 | 6.1 | 0.04 | Oct 15, 2021 | Mitsubishi Electric Europe B.V. SmartRTU devices allow XSS via the username parameter or PATH_INFO to login.php. | ||
| CVE-2021-24719 | Med | 0.43 | 6.1 | 0.03 | Oct 11, 2021 | The Enfold Enfold WordPress theme before 4.8.4 was vulnerable to Reflected Cross-Site Scripting (XSS). The vulnerability is present on Enfold versions previous than 4.8.4 which use Avia Page Builder. | ||
| CVE-2021-41878 | Med | 0.43 | 6.1 | 0.10 | Oct 4, 2021 | A reflected cross-site scripting (XSS) vulnerability exists in the i-Panel Administration System Version 2.0 that enables a remote attacker to execute arbitrary JavaScript code in the browser-based web console and it is possible to insert a vulnerable malicious button. | ||
| CVE-2021-41318 | Med | 0.43 | 6.1 | 0.06 | Sep 28, 2021 | In Progress WhatsUp Gold prior to version 21.1.0, an application endpoint failed to adequately sanitize malicious input. which could allow an unauthenticated attacker to execute arbitrary code in a victim's browser. | ||
| CVE-2021-36823 | Med | 0.43 | 6.6 | 0.01 | Sep 23, 2021 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Cusmin AGCA - Absolutely Glamorous Custom Admin (WordPress plugin) allows Stored XSS.This issue affects AGCA - Absolutely Glamorous Custom Admin (WordPress plugin): from n/a… | ||
| CVE-2021-40868 | Med | 0.43 | 6.1 | 0.09 | Sep 21, 2021 | In Cloudron 6.2, the returnTo parameter on the login page is vulnerable to Reflected XSS. | ||
| CVE-2021-39201 | Hig | 0.43 | 7.6 | 0.01 | Sep 9, 2021 | WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database. ### Impact The issue allows an authenticated but low-privileged user (like contributor/author) to execute XSS in the editor. This bypasses the restrictions… | ||
| CVE-2019-25046 | Med | 0.43 | 6.1 | 0.02 | Jun 10, 2021 | The Web Client in Cerberus FTP Server Enterprise before 10.0.19 and 11.x before 11.0.4 allows XSS via an SVG document. | ||
| CVE-2021-34370 | Med | 0.43 | 6.1 | 0.10 | Jun 9, 2021 | Accela Civic Platform through 20.1 allows ssoAdapter/logoutAction.do successURL XSS. NOTE: the vendor states "there are configurable security flags and we are unable to reproduce them with the available information. | ||
| CVE-2021-26078 | Med | 0.43 | 6.1 | 0.04 | Jun 7, 2021 | The number range searcher component in Jira Server and Jira Data Center before version 8.5.14, from version 8.6.0 before version 8.13.6, and from version 8.14.0 before version 8.16.1 allows remote attackers inject arbitrary HTML or JavaScript via a cross site scripting (XSS)… | ||
| CVE-2021-33904 | Med | 0.43 | 6.1 | 0.10 | Jun 7, 2021 | In Accela Civic Platform through 21.1, the security/hostSignon.do parameter servProvCode is vulnerable to XSS. NOTE: The vendor states "there are configurable security flags and we are unable to reproduce them with the available information. | ||
| CVE-2021-24300 | Med | 0.43 | 6.1 | 0.11 | May 24, 2021 | The slider import search feature of the PickPlugins Product Slider for WooCommerce WordPress plugin before 1.13.22 did not properly sanitised the keyword GET parameter, leading to reflected Cross-Site Scripting issue |
- risk 0.43cvss 6.6epss 0.00
SYNEL - eharmony Authenticated Blind & Stored XSS. Inject JS code into the "comments" field could lead to potential stealing of cookies, loading of HTML tags and JS code onto the system.
- risk 0.43cvss 6.1epss 0.03
Reflected Cross Site Scripting (XSS) in SAFARI Montage versions 8.3 and 8.5 allows remote attackers to execute JavaScript codes.
- risk 0.43cvss 6.5epss 0.11
DIAEnergie Version 1.7.5 and prior is vulnerable to stored cross-site scripting when an unauthenticated user injects arbitrary code into the parameter “descr” of the script “DIAE_hierarchyHandler.ashx”.
- risk 0.43cvss 6.5epss 0.09
jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of various `*Text` options of the Datepicker widget from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. The values passed to various…
- risk 0.43cvss 6.1epss 0.11
The login portal for the Automated Logic WebCTRL/WebCTRL OEM web application contains a vulnerability that allows for reflected XSS attacks due to the operatorlocale GET parameter not being sanitized. This issue impacts versions 6.5 and below. This issue works by passing in a…
- risk 0.43cvss 6.1epss 0.06
Cross Site Scripting (XSS) vulnerability exists in bludit 3-13-1 via the username in admin/login.
- risk 0.43cvss 6.1epss 0.06
myfactory.FMS before 7.1-912 allows XSS via the Error parameter.
- risk 0.43cvss 6.1epss 0.06
myfactory.FMS before 7.1-912 allows XSS via the UID parameter.
- risk 0.43cvss 6.1epss 0.04
Mitsubishi Electric Europe B.V. SmartRTU devices allow XSS via the username parameter or PATH_INFO to login.php.
- risk 0.43cvss 6.1epss 0.03
The Enfold Enfold WordPress theme before 4.8.4 was vulnerable to Reflected Cross-Site Scripting (XSS). The vulnerability is present on Enfold versions previous than 4.8.4 which use Avia Page Builder.
- risk 0.43cvss 6.1epss 0.10
A reflected cross-site scripting (XSS) vulnerability exists in the i-Panel Administration System Version 2.0 that enables a remote attacker to execute arbitrary JavaScript code in the browser-based web console and it is possible to insert a vulnerable malicious button.
- risk 0.43cvss 6.1epss 0.06
In Progress WhatsUp Gold prior to version 21.1.0, an application endpoint failed to adequately sanitize malicious input. which could allow an unauthenticated attacker to execute arbitrary code in a victim's browser.
- risk 0.43cvss 6.6epss 0.01
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Cusmin AGCA - Absolutely Glamorous Custom Admin (WordPress plugin) allows Stored XSS.This issue affects AGCA - Absolutely Glamorous Custom Admin (WordPress plugin): from n/a…
- risk 0.43cvss 6.1epss 0.09
In Cloudron 6.2, the returnTo parameter on the login page is vulnerable to Reflected XSS.
- risk 0.43cvss 7.6epss 0.01
WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database. ### Impact The issue allows an authenticated but low-privileged user (like contributor/author) to execute XSS in the editor. This bypasses the restrictions…
- risk 0.43cvss 6.1epss 0.02
The Web Client in Cerberus FTP Server Enterprise before 10.0.19 and 11.x before 11.0.4 allows XSS via an SVG document.
- risk 0.43cvss 6.1epss 0.10
Accela Civic Platform through 20.1 allows ssoAdapter/logoutAction.do successURL XSS. NOTE: the vendor states "there are configurable security flags and we are unable to reproduce them with the available information.
- risk 0.43cvss 6.1epss 0.04
The number range searcher component in Jira Server and Jira Data Center before version 8.5.14, from version 8.6.0 before version 8.13.6, and from version 8.14.0 before version 8.16.1 allows remote attackers inject arbitrary HTML or JavaScript via a cross site scripting (XSS)…
- risk 0.43cvss 6.1epss 0.10
In Accela Civic Platform through 21.1, the security/hostSignon.do parameter servProvCode is vulnerable to XSS. NOTE: The vendor states "there are configurable security flags and we are unable to reproduce them with the available information.
- risk 0.43cvss 6.1epss 0.11
The slider import search feature of the PickPlugins Product Slider for WooCommerce WordPress plugin before 1.13.22 did not properly sanitised the keyword GET parameter, leading to reflected Cross-Site Scripting issue