VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (46,817)

page 270 of 2,341
  • CVE-2021-29625HigMay 19, 2021
    risk 0.43cvss 7.5epss 0.10

    Adminer is open-source database management software. A cross-site scripting vulnerability in Adminer versions 4.6.1 to 4.8.0 affects users of MySQL, MariaDB, PgSQL and SQLite. XSS is in most cases prevented by strict CSP in all modern browsers. The only exception is when Adminer…

  • CVE-2021-24299MedMay 17, 2021
    risk 0.43cvss 6.1epss 0.06

    The ReDi Restaurant Reservation WordPress plugin before 21.0426 provides the functionality to let users make restaurant reservations. These reservations are stored and can be listed on an 'Upcoming' page provided by the plugin. An unauthenticated user can fill in the form to…

  • CVE-2021-24287MedMay 14, 2021
    risk 0.43cvss 6.1epss 0.10

    The settings page of the Select All Categories and Taxonomies, Change Checkbox to Radio Buttons WordPress plugin before 1.3.2 did not properly sanitise the tab parameter before outputting it back, leading to a reflected Cross-Site Scripting issue

  • CVE-2021-24245MedMay 6, 2021
    risk 0.43cvss 6.1epss 0.06

    The Stop Spammers WordPress plugin before 2021.9 did not escape user input when blocking requests (such as matching a spam word), outputting it in an attribute after sanitising it to remove HTML tags, which is not sufficient and lead to a reflected Cross-Site Scripting issue.

  • CVE-2021-25680MedApr 20, 2021
    risk 0.43cvss 6.1epss 0.02

    The AdTran Personal Phone Manager software is vulnerable to multiple reflected cross-site scripting (XSS) issues. These issues impact at minimum versions 10.8.1 and below but potentially impact later versions as well since they have not previously been disclosed. Only version…

  • CVE-2021-30150MedApr 6, 2021
    risk 0.43cvss 6.1epss 0.03

    Composr 10.0.36 allows XSS in an XML script.

  • CVE-2021-24169MedApr 5, 2021
    risk 0.43cvss 6.1epss 0.10

    This Advanced Order Export For WooCommerce WordPress plugin before 3.1.8 helps you to easily export WooCommerce order data. The tab parameter in the Admin Panel is vulnerable to reflected XSS.

  • CVE-2021-27520MedMar 19, 2021
    risk 0.43cvss 6.1epss 0.06

    A cross-site scripting (XSS) issue in FUDForum 3.1.0 allows remote attackers to inject JavaScript via index.php in the "author" parameter.

  • CVE-2021-27519MedMar 19, 2021
    risk 0.43cvss 6.1epss 0.08

    A cross-site scripting (XSS) issue in FUDForum 3.1.0 allows remote attackers to inject JavaScript via index.php in the "srch" parameter.

  • CVE-2021-27889MedMar 15, 2021
    risk 0.43cvss 6.1epss 0.05

    Cross-site Scripting (XSS) vulnerability in MyBB before 1.8.26 via Nested Auto URL when parsing messages.

  • CVE-2021-27695MedMar 15, 2021
    risk 0.43cvss 6.1epss 0.03

    Multiple stored cross-site scripting (XSS) vulnerabilities in openMAINT 2.1-3.3-b allow remote attackers to inject arbitrary web script or HTML via any "Add" sections, such as Add Card Building & Floor, or others in the Name and Code Parameters.

  • CVE-2021-20660MedFeb 24, 2021
    risk 0.43cvss 6.1epss 0.47

    Cross-site scripting vulnerability in SolarView Compact SV-CPT-MC310 prior to Ver.6.5 allows an attacker to inject an arbitrary script via unspecified vectors.

  • CVE-2021-26929MedFeb 14, 2021
    risk 0.43cvss 6.1epss 0.05

    An XSS issue was discovered in Horde Groupware Webmail Edition through 5.2.22 (where the Horde_Text_Filter library before 2.3.7 is used). The attacker can send a plain text e-mail message, with JavaScript encoded as a link or email that is mishandled by preProcess in…

  • CVE-2021-3318MedJan 27, 2021
    risk 0.43cvss 6.1epss 0.03

    attach/ajax.php in DzzOffice through 2.02.1 allows XSS via the editorid parameter.

  • CVE-2020-35437MedDec 26, 2020
    risk 0.43cvss 6.1epss 0.03

    Subrion CMS 4.2.1 is affected by: Cross Site Scripting (XSS) through the avatar[path] parameter in a POST request to the /_core/profile/ URI.

  • CVE-2020-25495MedDec 18, 2020
    risk 0.43cvss 6.1epss 0.09

    A reflected Cross-site scripting (XSS) vulnerability in Xinuo (formerly SCO) Openserver version 5 and 6 allows remote attackers to inject arbitrary web script or HTML tag via the parameter 'section'.

  • CVE-2020-20142MedDec 17, 2020
    risk 0.43cvss 6.1epss 0.02

    Cross Site Scripting (XSS) vulnerability in the "To Remote CSV" component under "Open" Menu in Flexmonster Pivot Table & Charts 2.7.17.

  • CVE-2020-20141MedDec 17, 2020
    risk 0.43cvss 6.1epss 0.02

    Cross Site Scripting (XSS) vulnerability in the To OLAP (XMLA) component Under the Connect menu in Flexmonster Pivot Table & Charts 2.7.17.

  • CVE-2020-20140MedDec 17, 2020
    risk 0.43cvss 6.1epss 0.02

    Cross Site Scripting (XSS) vulnerability in Remote Report component under the Open menu in Flexmonster Pivot Table & Charts 2.7.17.

  • CVE-2020-20139MedDec 17, 2020
    risk 0.43cvss 6.1epss 0.02

    Cross Site Scripting (XSS) vulnerability in the Remote JSON component Under the Connect menu in Flexmonster Pivot Table & Charts 2.7.17.