VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (46,817)

page 271 of 2,341
  • CVE-2020-35416MedDec 15, 2020
    risk 0.43cvss 6.1epss 0.03

    Multiple cross-site scripting (XSS) vulnerabilities exist in PHPJabbers Appointment Scheduler 2.3, in the index.php admin login webpage (with different request parameters), allows remote attackers to inject arbitrary web script or HTML.

  • CVE-2020-26249HigDec 9, 2020
    risk 0.43cvss 7.7epss 0.01

    Red Discord Bot Dashboard is an easy-to-use interactive web dashboard to control your Redbot. In Red Discord Bot before version 0.1.7a an RCE exploit has been discovered. This exploit allows Discord users with specially crafted Server names and Usernames/Nicknames to inject code…

  • CVE-2020-28092MedNov 17, 2020
    risk 0.43cvss 6.1epss 0.03

    PESCMS Team 2.3.2 has multiple reflected XSS via the id parameter:?g=Team&m=Task&a=my&status=3&id=,?g=Team&m=Task&a=my&status=0&id=,?g=Team&m=Task&a=my&status=1&id=,?g=Team&m=Task&a=my&status=10&id=

  • CVE-2020-13954MedNov 12, 2020
    risk 0.43cvss 6.1epss 0.41

    By default, Apache CXF creates a /services page containing a listing of the available endpoint names and addresses. This webpage is vulnerable to a reflected Cross-Site Scripting (XSS) attack via the styleSheetPath, which allows a malicious actor to inject javascript into the…

  • CVE-2020-26211HigNov 3, 2020
    risk 0.43cvss 7.7epss 0.01

    In BookStack before version 0.30.4, a user with permissions to edit a page could insert JavaScript code through the use of `javascript:` URIs within a link or form which would run, within the context of the current page, when clicked or submitted. Additionally, a user with…

  • CVE-2020-15276HigOct 30, 2020
    risk 0.43cvss 7.7epss 0.01

    baserCMS before version 4.4.1 is vulnerable to Cross-Site Scripting. Arbitrary JavaScript may be executed by entering a crafted nickname in blog comments. The issue affects the blog comment component. It is fixed in version 4.4.1.

  • CVE-2020-7749HigOct 20, 2020
    risk 0.43cvss 7.6epss 0.02

    This affects all versions of package osm-static-maps. User input given to the package is passed directly to a template without escaping ({{{ ... }}}). As such, it is possible for an attacker to inject arbitrary HTML/JS code and depending on the context. It will be outputted as…

  • CVE-2020-13260MedSep 17, 2020
    risk 0.43cvss 6.1epss 0.02

    A vulnerability in the web-based management interface of RAD SecFlow-1v through 2020-05-21 could allow an authenticated attacker to upload a JavaScript file, with a stored XSS payload, that will remain stored in the system as an OVPN file in…

  • CVE-2020-23839MedSep 1, 2020
    risk 0.43cvss 6.1epss 0.10

    A Reflected Cross-Site Scripting (XSS) vulnerability in GetSimple CMS v3.3.16, in the admin/index.php login portal webpage, allows remote attackers to execute JavaScript code in the client's browser and harvest login credentials after a client clicks a link, enters credentials,…

  • CVE-2020-15159HigAug 28, 2020
    risk 0.43cvss 7.6epss 0.02

    baserCMS 4.3.6 and earlier is affected by Cross Site Scripting (XSS) and Remote Code Execution (RCE). This may be executed by logging in as a system administrator and uploading an executable script file such as a PHP file.The affected components are ThemeFilesController.php and…

  • CVE-2020-24609MedAug 25, 2020
    risk 0.43cvss 6.1epss 0.10

    TechKshetra Info Solutions Pvt. Ltd Savsoft Quiz 5.5 and earlier has XSS which can result in an attacker injecting the XSS payload in the User Registration section and each time the admin visits the manage user section from the admin panel, the XSS triggers and the attacker can…

  • CVE-2020-15299MedJul 9, 2020
    risk 0.43cvss 6.1epss 0.47

    A reflected Cross-Site Scripting (XSS) Vulnerability in the KingComposer plugin through 2.9.4 for WordPress allows remote attackers to trick a victim into submitting an install_online_preset AJAX request containing base64-encoded JavaScript (in the kc-online-preset-data POST…

  • CVE-2020-15599MedJul 7, 2020
    risk 0.43cvss 6.1epss 0.02

    Victor CMS through 2019-02-28 allows XSS via the register.php user_firstname or user_lastname field.

  • CVE-2020-15364MedJun 28, 2020
    risk 0.43cvss 6.1epss 0.04

    The Nexos theme through 1.7 for WordPress allows top-map/?search_location= reflected XSS.

  • CVE-2020-13228MedJun 2, 2020
    risk 0.43cvss 6.1epss 0.03

    An issue was discovered in Sysax Multi Server 6.90. There is reflected XSS via the /scgi sid parameter.

  • CVE-2020-12256MedMay 18, 2020
    risk 0.43cvss 5.4epss 0.96

    rConfig 3.9.4 is vulnerable to reflected XSS. The devicemgmnt.php file improperly validates user input. An attacker can exploit this by crafting arbitrary JavaScript in the deviceId GET parameter to devicemgmnt.php.

  • CVE-2020-12259MedMay 18, 2020
    risk 0.43cvss 5.4epss 0.96

    rConfig 3.9.4 is vulnerable to reflected XSS. The configDevice.php file improperly validates user input. An attacker can exploit this vulnerability by crafting arbitrary JavaScript in the rid GET parameter of devicemgmnt.php.

  • CVE-2019-15083MedMay 14, 2020
    risk 0.43cvss 6.1epss 0.06

    Default installations of Zoho ManageEngine ServiceDesk Plus 10.0 before 10500 are vulnerable to XSS injected by a workstation local administrator. Using the installed program names of the computer as a vector, the local administrator can execute code on the Manage Engine…

  • CVE-2020-12704MedMay 7, 2020
    risk 0.43cvss 6.1epss 0.01

    UliCMS before 2020.2 has PageController stored XSS.

  • CVE-2012-3351MedFeb 20, 2020
    risk 0.43cvss 6.1epss 0.03

    Multiple cross-site scripting (XSS) vulnerabilities in LongTail Video JW Player through 5.10.2295 allow remote attackers to inject arbitrary web script or HTML via the (1) link, (2) logo.link, or (3) aboutlink parameter, or a nested URI scheme name for (4) javascript, (5)…