VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (46,817)

page 269 of 2,341
  • CVE-2022-22791MedJan 28, 2022
    risk 0.43cvss 6.6epss 0.00

    SYNEL - eharmony Authenticated Blind & Stored XSS. Inject JS code into the "comments" field could lead to potential stealing of cookies, loading of HTML tags and JS code onto the system.

  • CVE-2021-45425MedDec 28, 2021
    risk 0.43cvss 6.1epss 0.03

    Reflected Cross Site Scripting (XSS) in SAFARI Montage versions 8.3 and 8.5 allows remote attackers to execute JavaScript codes.

  • CVE-2021-31558MedDec 22, 2021
    risk 0.43cvss 6.5epss 0.11

    DIAEnergie Version 1.7.5 and prior is vulnerable to stored cross-site scripting when an unauthenticated user injects arbitrary code into the parameter “descr” of the script “DIAE_hierarchyHandler.ashx”.

  • CVE-2021-41183MedOct 26, 2021
    risk 0.43cvss 6.5epss 0.09

    jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of various `*Text` options of the Datepicker widget from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. The values passed to various…

  • CVE-2021-31682MedOct 22, 2021
    risk 0.43cvss 6.1epss 0.11

    The login portal for the Automated Logic WebCTRL/WebCTRL OEM web application contains a vulnerability that allows for reflected XSS attacks due to the operatorlocale GET parameter not being sanitized. This issue impacts versions 6.5 and below. This issue works by passing in a…

  • CVE-2021-35323MedOct 19, 2021
    risk 0.43cvss 6.1epss 0.06

    Cross Site Scripting (XSS) vulnerability exists in bludit 3-13-1 via the username in admin/login.

  • CVE-2021-42566MedOct 18, 2021
    risk 0.43cvss 6.1epss 0.06

    myfactory.FMS before 7.1-912 allows XSS via the Error parameter.

  • CVE-2021-42565MedOct 18, 2021
    risk 0.43cvss 6.1epss 0.06

    myfactory.FMS before 7.1-912 allows XSS via the UID parameter.

  • CVE-2018-16061MedOct 15, 2021
    risk 0.43cvss 6.1epss 0.04

    Mitsubishi Electric Europe B.V. SmartRTU devices allow XSS via the username parameter or PATH_INFO to login.php.

  • CVE-2021-24719MedOct 11, 2021
    risk 0.43cvss 6.1epss 0.03

    The Enfold Enfold WordPress theme before 4.8.4 was vulnerable to Reflected Cross-Site Scripting (XSS). The vulnerability is present on Enfold versions previous than 4.8.4 which use Avia Page Builder.

  • CVE-2021-41878MedOct 4, 2021
    risk 0.43cvss 6.1epss 0.10

    A reflected cross-site scripting (XSS) vulnerability exists in the i-Panel Administration System Version 2.0 that enables a remote attacker to execute arbitrary JavaScript code in the browser-based web console and it is possible to insert a vulnerable malicious button.

  • CVE-2021-41318MedSep 28, 2021
    risk 0.43cvss 6.1epss 0.06

    In Progress WhatsUp Gold prior to version 21.1.0, an application endpoint failed to adequately sanitize malicious input. which could allow an unauthenticated attacker to execute arbitrary code in a victim's browser.

  • CVE-2021-36823MedSep 23, 2021
    risk 0.43cvss 6.6epss 0.01

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Cusmin AGCA - Absolutely Glamorous Custom Admin (WordPress plugin) allows Stored XSS.This issue affects AGCA - Absolutely Glamorous Custom Admin (WordPress plugin): from n/a…

  • CVE-2021-40868MedSep 21, 2021
    risk 0.43cvss 6.1epss 0.09

    In Cloudron 6.2, the returnTo parameter on the login page is vulnerable to Reflected XSS.

  • CVE-2021-39201HigSep 9, 2021
    risk 0.43cvss 7.6epss 0.01

    WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database. ### Impact The issue allows an authenticated but low-privileged user (like contributor/author) to execute XSS in the editor. This bypasses the restrictions…

  • CVE-2019-25046MedJun 10, 2021
    risk 0.43cvss 6.1epss 0.02

    The Web Client in Cerberus FTP Server Enterprise before 10.0.19 and 11.x before 11.0.4 allows XSS via an SVG document.

  • CVE-2021-34370MedJun 9, 2021
    risk 0.43cvss 6.1epss 0.10

    Accela Civic Platform through 20.1 allows ssoAdapter/logoutAction.do successURL XSS. NOTE: the vendor states "there are configurable security flags and we are unable to reproduce them with the available information.

  • CVE-2021-26078MedJun 7, 2021
    risk 0.43cvss 6.1epss 0.04

    The number range searcher component in Jira Server and Jira Data Center before version 8.5.14, from version 8.6.0 before version 8.13.6, and from version 8.14.0 before version 8.16.1 allows remote attackers inject arbitrary HTML or JavaScript via a cross site scripting (XSS)…

  • CVE-2021-33904MedJun 7, 2021
    risk 0.43cvss 6.1epss 0.10

    In Accela Civic Platform through 21.1, the security/hostSignon.do parameter servProvCode is vulnerable to XSS. NOTE: The vendor states "there are configurable security flags and we are unable to reproduce them with the available information.

  • CVE-2021-24300MedMay 24, 2021
    risk 0.43cvss 6.1epss 0.11

    The slider import search feature of the PickPlugins Product Slider for WooCommerce WordPress plugin before 1.13.22 did not properly sanitised the keyword GET parameter, leading to reflected Cross-Site Scripting issue