CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Description
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85
CVEs mapped to this weakness (46,817)
page 270 of 2,341| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-29625 | Hig | 0.43 | 7.5 | 0.10 | May 19, 2021 | Adminer is open-source database management software. A cross-site scripting vulnerability in Adminer versions 4.6.1 to 4.8.0 affects users of MySQL, MariaDB, PgSQL and SQLite. XSS is in most cases prevented by strict CSP in all modern browsers. The only exception is when Adminer… | ||
| CVE-2021-24299 | Med | 0.43 | 6.1 | 0.06 | May 17, 2021 | The ReDi Restaurant Reservation WordPress plugin before 21.0426 provides the functionality to let users make restaurant reservations. These reservations are stored and can be listed on an 'Upcoming' page provided by the plugin. An unauthenticated user can fill in the form to… | ||
| CVE-2021-24287 | Med | 0.43 | 6.1 | 0.10 | May 14, 2021 | The settings page of the Select All Categories and Taxonomies, Change Checkbox to Radio Buttons WordPress plugin before 1.3.2 did not properly sanitise the tab parameter before outputting it back, leading to a reflected Cross-Site Scripting issue | ||
| CVE-2021-24245 | Med | 0.43 | 6.1 | 0.06 | May 6, 2021 | The Stop Spammers WordPress plugin before 2021.9 did not escape user input when blocking requests (such as matching a spam word), outputting it in an attribute after sanitising it to remove HTML tags, which is not sufficient and lead to a reflected Cross-Site Scripting issue. | ||
| CVE-2021-25680 | Med | 0.43 | 6.1 | 0.02 | Apr 20, 2021 | The AdTran Personal Phone Manager software is vulnerable to multiple reflected cross-site scripting (XSS) issues. These issues impact at minimum versions 10.8.1 and below but potentially impact later versions as well since they have not previously been disclosed. Only version… | ||
| CVE-2021-30150 | Med | 0.43 | 6.1 | 0.03 | Apr 6, 2021 | Composr 10.0.36 allows XSS in an XML script. | ||
| CVE-2021-24169 | Med | 0.43 | 6.1 | 0.10 | Apr 5, 2021 | This Advanced Order Export For WooCommerce WordPress plugin before 3.1.8 helps you to easily export WooCommerce order data. The tab parameter in the Admin Panel is vulnerable to reflected XSS. | ||
| CVE-2021-27520 | Med | 0.43 | 6.1 | 0.06 | Mar 19, 2021 | A cross-site scripting (XSS) issue in FUDForum 3.1.0 allows remote attackers to inject JavaScript via index.php in the "author" parameter. | ||
| CVE-2021-27519 | Med | 0.43 | 6.1 | 0.08 | Mar 19, 2021 | A cross-site scripting (XSS) issue in FUDForum 3.1.0 allows remote attackers to inject JavaScript via index.php in the "srch" parameter. | ||
| CVE-2021-27889 | Med | 0.43 | 6.1 | 0.05 | Mar 15, 2021 | Cross-site Scripting (XSS) vulnerability in MyBB before 1.8.26 via Nested Auto URL when parsing messages. | ||
| CVE-2021-27695 | Med | 0.43 | 6.1 | 0.03 | Mar 15, 2021 | Multiple stored cross-site scripting (XSS) vulnerabilities in openMAINT 2.1-3.3-b allow remote attackers to inject arbitrary web script or HTML via any "Add" sections, such as Add Card Building & Floor, or others in the Name and Code Parameters. | ||
| CVE-2021-20660 | Med | 0.43 | 6.1 | 0.47 | Feb 24, 2021 | Cross-site scripting vulnerability in SolarView Compact SV-CPT-MC310 prior to Ver.6.5 allows an attacker to inject an arbitrary script via unspecified vectors. | ||
| CVE-2021-26929 | Med | 0.43 | 6.1 | 0.05 | Feb 14, 2021 | An XSS issue was discovered in Horde Groupware Webmail Edition through 5.2.22 (where the Horde_Text_Filter library before 2.3.7 is used). The attacker can send a plain text e-mail message, with JavaScript encoded as a link or email that is mishandled by preProcess in… | ||
| CVE-2021-3318 | Med | 0.43 | 6.1 | 0.03 | Jan 27, 2021 | attach/ajax.php in DzzOffice through 2.02.1 allows XSS via the editorid parameter. | ||
| CVE-2020-35437 | Med | 0.43 | 6.1 | 0.03 | Dec 26, 2020 | Subrion CMS 4.2.1 is affected by: Cross Site Scripting (XSS) through the avatar[path] parameter in a POST request to the /_core/profile/ URI. | ||
| CVE-2020-25495 | Med | 0.43 | 6.1 | 0.09 | Dec 18, 2020 | A reflected Cross-site scripting (XSS) vulnerability in Xinuo (formerly SCO) Openserver version 5 and 6 allows remote attackers to inject arbitrary web script or HTML tag via the parameter 'section'. | ||
| CVE-2020-20142 | Med | 0.43 | 6.1 | 0.02 | Dec 17, 2020 | Cross Site Scripting (XSS) vulnerability in the "To Remote CSV" component under "Open" Menu in Flexmonster Pivot Table & Charts 2.7.17. | ||
| CVE-2020-20141 | Med | 0.43 | 6.1 | 0.02 | Dec 17, 2020 | Cross Site Scripting (XSS) vulnerability in the To OLAP (XMLA) component Under the Connect menu in Flexmonster Pivot Table & Charts 2.7.17. | ||
| CVE-2020-20140 | Med | 0.43 | 6.1 | 0.02 | Dec 17, 2020 | Cross Site Scripting (XSS) vulnerability in Remote Report component under the Open menu in Flexmonster Pivot Table & Charts 2.7.17. | ||
| CVE-2020-20139 | Med | 0.43 | 6.1 | 0.02 | Dec 17, 2020 | Cross Site Scripting (XSS) vulnerability in the Remote JSON component Under the Connect menu in Flexmonster Pivot Table & Charts 2.7.17. |
- risk 0.43cvss 7.5epss 0.10
Adminer is open-source database management software. A cross-site scripting vulnerability in Adminer versions 4.6.1 to 4.8.0 affects users of MySQL, MariaDB, PgSQL and SQLite. XSS is in most cases prevented by strict CSP in all modern browsers. The only exception is when Adminer…
- risk 0.43cvss 6.1epss 0.06
The ReDi Restaurant Reservation WordPress plugin before 21.0426 provides the functionality to let users make restaurant reservations. These reservations are stored and can be listed on an 'Upcoming' page provided by the plugin. An unauthenticated user can fill in the form to…
- risk 0.43cvss 6.1epss 0.10
The settings page of the Select All Categories and Taxonomies, Change Checkbox to Radio Buttons WordPress plugin before 1.3.2 did not properly sanitise the tab parameter before outputting it back, leading to a reflected Cross-Site Scripting issue
- risk 0.43cvss 6.1epss 0.06
The Stop Spammers WordPress plugin before 2021.9 did not escape user input when blocking requests (such as matching a spam word), outputting it in an attribute after sanitising it to remove HTML tags, which is not sufficient and lead to a reflected Cross-Site Scripting issue.
- risk 0.43cvss 6.1epss 0.02
The AdTran Personal Phone Manager software is vulnerable to multiple reflected cross-site scripting (XSS) issues. These issues impact at minimum versions 10.8.1 and below but potentially impact later versions as well since they have not previously been disclosed. Only version…
- risk 0.43cvss 6.1epss 0.03
Composr 10.0.36 allows XSS in an XML script.
- risk 0.43cvss 6.1epss 0.10
This Advanced Order Export For WooCommerce WordPress plugin before 3.1.8 helps you to easily export WooCommerce order data. The tab parameter in the Admin Panel is vulnerable to reflected XSS.
- risk 0.43cvss 6.1epss 0.06
A cross-site scripting (XSS) issue in FUDForum 3.1.0 allows remote attackers to inject JavaScript via index.php in the "author" parameter.
- risk 0.43cvss 6.1epss 0.08
A cross-site scripting (XSS) issue in FUDForum 3.1.0 allows remote attackers to inject JavaScript via index.php in the "srch" parameter.
- risk 0.43cvss 6.1epss 0.05
Cross-site Scripting (XSS) vulnerability in MyBB before 1.8.26 via Nested Auto URL when parsing messages.
- risk 0.43cvss 6.1epss 0.03
Multiple stored cross-site scripting (XSS) vulnerabilities in openMAINT 2.1-3.3-b allow remote attackers to inject arbitrary web script or HTML via any "Add" sections, such as Add Card Building & Floor, or others in the Name and Code Parameters.
- risk 0.43cvss 6.1epss 0.47
Cross-site scripting vulnerability in SolarView Compact SV-CPT-MC310 prior to Ver.6.5 allows an attacker to inject an arbitrary script via unspecified vectors.
- risk 0.43cvss 6.1epss 0.05
An XSS issue was discovered in Horde Groupware Webmail Edition through 5.2.22 (where the Horde_Text_Filter library before 2.3.7 is used). The attacker can send a plain text e-mail message, with JavaScript encoded as a link or email that is mishandled by preProcess in…
- risk 0.43cvss 6.1epss 0.03
attach/ajax.php in DzzOffice through 2.02.1 allows XSS via the editorid parameter.
- risk 0.43cvss 6.1epss 0.03
Subrion CMS 4.2.1 is affected by: Cross Site Scripting (XSS) through the avatar[path] parameter in a POST request to the /_core/profile/ URI.
- risk 0.43cvss 6.1epss 0.09
A reflected Cross-site scripting (XSS) vulnerability in Xinuo (formerly SCO) Openserver version 5 and 6 allows remote attackers to inject arbitrary web script or HTML tag via the parameter 'section'.
- risk 0.43cvss 6.1epss 0.02
Cross Site Scripting (XSS) vulnerability in the "To Remote CSV" component under "Open" Menu in Flexmonster Pivot Table & Charts 2.7.17.
- risk 0.43cvss 6.1epss 0.02
Cross Site Scripting (XSS) vulnerability in the To OLAP (XMLA) component Under the Connect menu in Flexmonster Pivot Table & Charts 2.7.17.
- risk 0.43cvss 6.1epss 0.02
Cross Site Scripting (XSS) vulnerability in Remote Report component under the Open menu in Flexmonster Pivot Table & Charts 2.7.17.
- risk 0.43cvss 6.1epss 0.02
Cross Site Scripting (XSS) vulnerability in the Remote JSON component Under the Connect menu in Flexmonster Pivot Table & Charts 2.7.17.