CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Description
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85
CVEs mapped to this weakness (46,817)
page 271 of 2,341| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-35416 | Med | 0.43 | 6.1 | 0.03 | Dec 15, 2020 | Multiple cross-site scripting (XSS) vulnerabilities exist in PHPJabbers Appointment Scheduler 2.3, in the index.php admin login webpage (with different request parameters), allows remote attackers to inject arbitrary web script or HTML. | ||
| CVE-2020-26249 | Hig | 0.43 | 7.7 | 0.01 | Dec 9, 2020 | Red Discord Bot Dashboard is an easy-to-use interactive web dashboard to control your Redbot. In Red Discord Bot before version 0.1.7a an RCE exploit has been discovered. This exploit allows Discord users with specially crafted Server names and Usernames/Nicknames to inject code… | ||
| CVE-2020-28092 | Med | 0.43 | 6.1 | 0.03 | Nov 17, 2020 | PESCMS Team 2.3.2 has multiple reflected XSS via the id parameter:?g=Team&m=Task&a=my&status=3&id=,?g=Team&m=Task&a=my&status=0&id=,?g=Team&m=Task&a=my&status=1&id=,?g=Team&m=Task&a=my&status=10&id= | ||
| CVE-2020-13954 | Med | 0.43 | 6.1 | 0.41 | Nov 12, 2020 | By default, Apache CXF creates a /services page containing a listing of the available endpoint names and addresses. This webpage is vulnerable to a reflected Cross-Site Scripting (XSS) attack via the styleSheetPath, which allows a malicious actor to inject javascript into the… | ||
| CVE-2020-26211 | Hig | 0.43 | 7.7 | 0.01 | Nov 3, 2020 | In BookStack before version 0.30.4, a user with permissions to edit a page could insert JavaScript code through the use of `javascript:` URIs within a link or form which would run, within the context of the current page, when clicked or submitted. Additionally, a user with… | ||
| CVE-2020-15276 | Hig | 0.43 | 7.7 | 0.01 | Oct 30, 2020 | baserCMS before version 4.4.1 is vulnerable to Cross-Site Scripting. Arbitrary JavaScript may be executed by entering a crafted nickname in blog comments. The issue affects the blog comment component. It is fixed in version 4.4.1. | ||
| CVE-2020-7749 | Hig | 0.43 | 7.6 | 0.02 | Oct 20, 2020 | This affects all versions of package osm-static-maps. User input given to the package is passed directly to a template without escaping ({{{ ... }}}). As such, it is possible for an attacker to inject arbitrary HTML/JS code and depending on the context. It will be outputted as… | ||
| CVE-2020-13260 | Med | 0.43 | 6.1 | 0.02 | Sep 17, 2020 | A vulnerability in the web-based management interface of RAD SecFlow-1v through 2020-05-21 could allow an authenticated attacker to upload a JavaScript file, with a stored XSS payload, that will remain stored in the system as an OVPN file in… | ||
| CVE-2020-23839 | Med | 0.43 | 6.1 | 0.10 | Sep 1, 2020 | A Reflected Cross-Site Scripting (XSS) vulnerability in GetSimple CMS v3.3.16, in the admin/index.php login portal webpage, allows remote attackers to execute JavaScript code in the client's browser and harvest login credentials after a client clicks a link, enters credentials,… | ||
| CVE-2020-15159 | Hig | 0.43 | 7.6 | 0.02 | Aug 28, 2020 | baserCMS 4.3.6 and earlier is affected by Cross Site Scripting (XSS) and Remote Code Execution (RCE). This may be executed by logging in as a system administrator and uploading an executable script file such as a PHP file.The affected components are ThemeFilesController.php and… | ||
| CVE-2020-24609 | Med | 0.43 | 6.1 | 0.10 | Aug 25, 2020 | TechKshetra Info Solutions Pvt. Ltd Savsoft Quiz 5.5 and earlier has XSS which can result in an attacker injecting the XSS payload in the User Registration section and each time the admin visits the manage user section from the admin panel, the XSS triggers and the attacker can… | ||
| CVE-2020-15299 | Med | 0.43 | 6.1 | 0.47 | Jul 9, 2020 | A reflected Cross-Site Scripting (XSS) Vulnerability in the KingComposer plugin through 2.9.4 for WordPress allows remote attackers to trick a victim into submitting an install_online_preset AJAX request containing base64-encoded JavaScript (in the kc-online-preset-data POST… | ||
| CVE-2020-15599 | Med | 0.43 | 6.1 | 0.02 | Jul 7, 2020 | Victor CMS through 2019-02-28 allows XSS via the register.php user_firstname or user_lastname field. | ||
| CVE-2020-15364 | Med | 0.43 | 6.1 | 0.04 | Jun 28, 2020 | The Nexos theme through 1.7 for WordPress allows top-map/?search_location= reflected XSS. | ||
| CVE-2020-13228 | Med | 0.43 | 6.1 | 0.03 | Jun 2, 2020 | An issue was discovered in Sysax Multi Server 6.90. There is reflected XSS via the /scgi sid parameter. | ||
| CVE-2020-12256 | Med | 0.43 | 5.4 | 0.96 | May 18, 2020 | rConfig 3.9.4 is vulnerable to reflected XSS. The devicemgmnt.php file improperly validates user input. An attacker can exploit this by crafting arbitrary JavaScript in the deviceId GET parameter to devicemgmnt.php. | ||
| CVE-2020-12259 | Med | 0.43 | 5.4 | 0.96 | May 18, 2020 | rConfig 3.9.4 is vulnerable to reflected XSS. The configDevice.php file improperly validates user input. An attacker can exploit this vulnerability by crafting arbitrary JavaScript in the rid GET parameter of devicemgmnt.php. | ||
| CVE-2019-15083 | Med | 0.43 | 6.1 | 0.06 | May 14, 2020 | Default installations of Zoho ManageEngine ServiceDesk Plus 10.0 before 10500 are vulnerable to XSS injected by a workstation local administrator. Using the installed program names of the computer as a vector, the local administrator can execute code on the Manage Engine… | ||
| CVE-2020-12704 | Med | 0.43 | 6.1 | 0.01 | May 7, 2020 | UliCMS before 2020.2 has PageController stored XSS. | ||
| CVE-2012-3351 | Med | 0.43 | 6.1 | 0.03 | Feb 20, 2020 | Multiple cross-site scripting (XSS) vulnerabilities in LongTail Video JW Player through 5.10.2295 allow remote attackers to inject arbitrary web script or HTML via the (1) link, (2) logo.link, or (3) aboutlink parameter, or a nested URI scheme name for (4) javascript, (5)… |
- risk 0.43cvss 6.1epss 0.03
Multiple cross-site scripting (XSS) vulnerabilities exist in PHPJabbers Appointment Scheduler 2.3, in the index.php admin login webpage (with different request parameters), allows remote attackers to inject arbitrary web script or HTML.
- risk 0.43cvss 7.7epss 0.01
Red Discord Bot Dashboard is an easy-to-use interactive web dashboard to control your Redbot. In Red Discord Bot before version 0.1.7a an RCE exploit has been discovered. This exploit allows Discord users with specially crafted Server names and Usernames/Nicknames to inject code…
- risk 0.43cvss 6.1epss 0.03
PESCMS Team 2.3.2 has multiple reflected XSS via the id parameter:?g=Team&m=Task&a=my&status=3&id=,?g=Team&m=Task&a=my&status=0&id=,?g=Team&m=Task&a=my&status=1&id=,?g=Team&m=Task&a=my&status=10&id=
- risk 0.43cvss 6.1epss 0.41
By default, Apache CXF creates a /services page containing a listing of the available endpoint names and addresses. This webpage is vulnerable to a reflected Cross-Site Scripting (XSS) attack via the styleSheetPath, which allows a malicious actor to inject javascript into the…
- risk 0.43cvss 7.7epss 0.01
In BookStack before version 0.30.4, a user with permissions to edit a page could insert JavaScript code through the use of `javascript:` URIs within a link or form which would run, within the context of the current page, when clicked or submitted. Additionally, a user with…
- risk 0.43cvss 7.7epss 0.01
baserCMS before version 4.4.1 is vulnerable to Cross-Site Scripting. Arbitrary JavaScript may be executed by entering a crafted nickname in blog comments. The issue affects the blog comment component. It is fixed in version 4.4.1.
- risk 0.43cvss 7.6epss 0.02
This affects all versions of package osm-static-maps. User input given to the package is passed directly to a template without escaping ({{{ ... }}}). As such, it is possible for an attacker to inject arbitrary HTML/JS code and depending on the context. It will be outputted as…
- risk 0.43cvss 6.1epss 0.02
A vulnerability in the web-based management interface of RAD SecFlow-1v through 2020-05-21 could allow an authenticated attacker to upload a JavaScript file, with a stored XSS payload, that will remain stored in the system as an OVPN file in…
- risk 0.43cvss 6.1epss 0.10
A Reflected Cross-Site Scripting (XSS) vulnerability in GetSimple CMS v3.3.16, in the admin/index.php login portal webpage, allows remote attackers to execute JavaScript code in the client's browser and harvest login credentials after a client clicks a link, enters credentials,…
- risk 0.43cvss 7.6epss 0.02
baserCMS 4.3.6 and earlier is affected by Cross Site Scripting (XSS) and Remote Code Execution (RCE). This may be executed by logging in as a system administrator and uploading an executable script file such as a PHP file.The affected components are ThemeFilesController.php and…
- risk 0.43cvss 6.1epss 0.10
TechKshetra Info Solutions Pvt. Ltd Savsoft Quiz 5.5 and earlier has XSS which can result in an attacker injecting the XSS payload in the User Registration section and each time the admin visits the manage user section from the admin panel, the XSS triggers and the attacker can…
- risk 0.43cvss 6.1epss 0.47
A reflected Cross-Site Scripting (XSS) Vulnerability in the KingComposer plugin through 2.9.4 for WordPress allows remote attackers to trick a victim into submitting an install_online_preset AJAX request containing base64-encoded JavaScript (in the kc-online-preset-data POST…
- risk 0.43cvss 6.1epss 0.02
Victor CMS through 2019-02-28 allows XSS via the register.php user_firstname or user_lastname field.
- risk 0.43cvss 6.1epss 0.04
The Nexos theme through 1.7 for WordPress allows top-map/?search_location= reflected XSS.
- risk 0.43cvss 6.1epss 0.03
An issue was discovered in Sysax Multi Server 6.90. There is reflected XSS via the /scgi sid parameter.
- risk 0.43cvss 5.4epss 0.96
rConfig 3.9.4 is vulnerable to reflected XSS. The devicemgmnt.php file improperly validates user input. An attacker can exploit this by crafting arbitrary JavaScript in the deviceId GET parameter to devicemgmnt.php.
- risk 0.43cvss 5.4epss 0.96
rConfig 3.9.4 is vulnerable to reflected XSS. The configDevice.php file improperly validates user input. An attacker can exploit this vulnerability by crafting arbitrary JavaScript in the rid GET parameter of devicemgmnt.php.
- risk 0.43cvss 6.1epss 0.06
Default installations of Zoho ManageEngine ServiceDesk Plus 10.0 before 10500 are vulnerable to XSS injected by a workstation local administrator. Using the installed program names of the computer as a vector, the local administrator can execute code on the Manage Engine…
- risk 0.43cvss 6.1epss 0.01
UliCMS before 2020.2 has PageController stored XSS.
- risk 0.43cvss 6.1epss 0.03
Multiple cross-site scripting (XSS) vulnerabilities in LongTail Video JW Player through 5.10.2295 allow remote attackers to inject arbitrary web script or HTML via the (1) link, (2) logo.link, or (3) aboutlink parameter, or a nested URI scheme name for (4) javascript, (5)…