CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Description
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85
CVEs mapped to this weakness (46,817)
page 272 of 2,341| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-5241 | Hig | 0.43 | 7.7 | 0.01 | Feb 13, 2020 | matestack-ui-core (RubyGem) before 0.7.4 is vulnerable to XSS/Script injection. This vulnerability is patched in version 0.7.4. | ||
| CVE-2013-2637 | Med | 0.43 | 6.1 | 0.04 | Feb 12, 2020 | A Cross-Site Scripting (XSS) Vulnerability exists in OTRS ITSM prior to 3.2.4, 3.1.8, and 3.0.7 and FAQ prior to 2.1.4 and 2.0.8 via changes, workorder items, and FAQ articles, which could let a remote malicious user execute arbitrary code. | ||
| CVE-2020-8839 | Med | 0.43 | 6.1 | 0.02 | Feb 12, 2020 | Stored XSS was discovered on CHIYU BF-430 232/485 TCP/IP Converter devices before 1.16.00, as demonstrated by the /if.cgi TF_submask field. | ||
| CVE-2013-1410 | Med | 0.43 | 6.1 | 0.01 | Feb 12, 2020 | Perforce P4web 2011.1 and 2012.1 has multiple XSS vulnerabilities | ||
| CVE-2012-2517 | Med | 0.43 | 6.1 | 0.02 | Feb 11, 2020 | Cross-site scripting (XSS) vulnerability in PrestaShop before 1.4.9 allows remote attackers to inject arbitrary web script or HTML via the index of the product[] parameter to ajax.php. | ||
| CVE-2012-2452 | Med | 0.43 | 6.1 | 0.02 | Feb 11, 2020 | Multiple cross-site scripting (XSS) vulnerabilities in pragmaMx 1.x before 1.12.2 allow remote attackers to inject arbitrary web script or HTML via the (1) name parameter to modules.php or (2) img_url to includes/wysiwyg/spaw/editor/plugins/imgpopup/img_popup.php. | ||
| CVE-2013-2684 | Med | 0.43 | 6.1 | 0.04 | Feb 6, 2020 | Cross-site Scripting (XSS) in Cisco Linksys E4200 1.0.05 Build 7 devices allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | ||
| CVE-2012-2593 | Med | 0.43 | 6.1 | 0.06 | Feb 6, 2020 | Cross-site scripting (XSS) vulnerability in the administrative interface in Atmail Webmail Server 6.4 allows remote attackers to inject arbitrary web script or HTML via the Date field of an email. | ||
| CVE-2013-7054 | Med | 0.43 | 6.1 | 0.04 | Feb 4, 2020 | D-Link DIR-100 4.03B07: cli.cgi XSS | ||
| CVE-2013-2623 | Med | 0.43 | 6.1 | 0.03 | Feb 3, 2020 | Cross-site Scripting (XSS) in Telaen before 1.3.1 allows remote attackers to inject arbitrary web script or HTML via the "f_email" parameter in index.php. | ||
| CVE-2013-4241 | Med | 0.43 | 6.1 | 0.04 | Jan 30, 2020 | Multiple cross-site scripting (XSS) vulnerabilities in the HMS Testimonials plugin before 2.0.11 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) name, (2) image, (3) url, or (4) testimonial parameter to the Testimonial form… | ||
| CVE-2013-2294 | Med | 0.43 | 6.1 | 0.04 | Jan 30, 2020 | Multiple cross-site scripting (XSS) vulnerabilities in ViewGit before 0.0.7 allow remote repository users to inject arbitrary web script or HTML via a (1) tag name to the Shortlog table in templates/shortlog.php or branch name to the (2) Shortlog table in templates/shortlog.php… | ||
| CVE-2013-3320 | Med | 0.43 | 6.1 | 0.02 | Jan 29, 2020 | Cross-site Scripting (XSS) vulnerability in NetApp OnCommand System Manager before 2.2 allows remote attackers to inject arbitrary web script or HTML via the 'full-name' and 'comment' fields. | ||
| CVE-2013-2714 | Med | 0.43 | 6.1 | 0.03 | Jan 28, 2020 | Cross-site Scripting (XSS) in WordPress podPress Plugin 8.8.10.13 could allow remote attackers to inject arbitrary web script or html via the 'playerID' parameter. | ||
| CVE-2012-6448 | Med | 0.43 | 6.1 | 0.02 | Jan 27, 2020 | Cross-site Scripting (XSS) in cPanel WebHost Manager (WHM) 11.34.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | ||
| CVE-2019-6146 | Med | 0.43 | 6.1 | 0.03 | Jan 22, 2020 | It has been reported that cross-site scripting (XSS) is possible in Forcepoint Web Security, version 8.x, via host header injection. CVSSv3.0: 5.3 (Medium) (/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N) | ||
| CVE-2011-4095 | Med | 0.43 | 6.1 | 0.02 | Jan 21, 2020 | Jara 1.6 has an XSS vulnerability | ||
| CVE-2011-4336 | Med | 0.43 | 6.1 | 0.08 | Jan 15, 2020 | Tiki Wiki CMS Groupware 7.0 has XSS via the GET "ajax" parameter to snarf_ajax.php. | ||
| CVE-2011-4595 | Med | 0.43 | 6.1 | 0.02 | Jan 10, 2020 | Pretty-Link WordPress plugin 1.5.2 has XSS | ||
| CVE-2019-18859 | Med | 0.43 | 6.1 | 0.02 | Jan 9, 2020 | Digi AnywhereUSB 14 allows XSS via a link for the Digi Page. |
- risk 0.43cvss 7.7epss 0.01
matestack-ui-core (RubyGem) before 0.7.4 is vulnerable to XSS/Script injection. This vulnerability is patched in version 0.7.4.
- risk 0.43cvss 6.1epss 0.04
A Cross-Site Scripting (XSS) Vulnerability exists in OTRS ITSM prior to 3.2.4, 3.1.8, and 3.0.7 and FAQ prior to 2.1.4 and 2.0.8 via changes, workorder items, and FAQ articles, which could let a remote malicious user execute arbitrary code.
- risk 0.43cvss 6.1epss 0.02
Stored XSS was discovered on CHIYU BF-430 232/485 TCP/IP Converter devices before 1.16.00, as demonstrated by the /if.cgi TF_submask field.
- risk 0.43cvss 6.1epss 0.01
Perforce P4web 2011.1 and 2012.1 has multiple XSS vulnerabilities
- risk 0.43cvss 6.1epss 0.02
Cross-site scripting (XSS) vulnerability in PrestaShop before 1.4.9 allows remote attackers to inject arbitrary web script or HTML via the index of the product[] parameter to ajax.php.
- risk 0.43cvss 6.1epss 0.02
Multiple cross-site scripting (XSS) vulnerabilities in pragmaMx 1.x before 1.12.2 allow remote attackers to inject arbitrary web script or HTML via the (1) name parameter to modules.php or (2) img_url to includes/wysiwyg/spaw/editor/plugins/imgpopup/img_popup.php.
- risk 0.43cvss 6.1epss 0.04
Cross-site Scripting (XSS) in Cisco Linksys E4200 1.0.05 Build 7 devices allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
- risk 0.43cvss 6.1epss 0.06
Cross-site scripting (XSS) vulnerability in the administrative interface in Atmail Webmail Server 6.4 allows remote attackers to inject arbitrary web script or HTML via the Date field of an email.
- risk 0.43cvss 6.1epss 0.04
D-Link DIR-100 4.03B07: cli.cgi XSS
- risk 0.43cvss 6.1epss 0.03
Cross-site Scripting (XSS) in Telaen before 1.3.1 allows remote attackers to inject arbitrary web script or HTML via the "f_email" parameter in index.php.
- risk 0.43cvss 6.1epss 0.04
Multiple cross-site scripting (XSS) vulnerabilities in the HMS Testimonials plugin before 2.0.11 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) name, (2) image, (3) url, or (4) testimonial parameter to the Testimonial form…
- risk 0.43cvss 6.1epss 0.04
Multiple cross-site scripting (XSS) vulnerabilities in ViewGit before 0.0.7 allow remote repository users to inject arbitrary web script or HTML via a (1) tag name to the Shortlog table in templates/shortlog.php or branch name to the (2) Shortlog table in templates/shortlog.php…
- risk 0.43cvss 6.1epss 0.02
Cross-site Scripting (XSS) vulnerability in NetApp OnCommand System Manager before 2.2 allows remote attackers to inject arbitrary web script or HTML via the 'full-name' and 'comment' fields.
- risk 0.43cvss 6.1epss 0.03
Cross-site Scripting (XSS) in WordPress podPress Plugin 8.8.10.13 could allow remote attackers to inject arbitrary web script or html via the 'playerID' parameter.
- risk 0.43cvss 6.1epss 0.02
Cross-site Scripting (XSS) in cPanel WebHost Manager (WHM) 11.34.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
- risk 0.43cvss 6.1epss 0.03
It has been reported that cross-site scripting (XSS) is possible in Forcepoint Web Security, version 8.x, via host header injection. CVSSv3.0: 5.3 (Medium) (/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
- risk 0.43cvss 6.1epss 0.02
Jara 1.6 has an XSS vulnerability
- risk 0.43cvss 6.1epss 0.08
Tiki Wiki CMS Groupware 7.0 has XSS via the GET "ajax" parameter to snarf_ajax.php.
- risk 0.43cvss 6.1epss 0.02
Pretty-Link WordPress plugin 1.5.2 has XSS
- risk 0.43cvss 6.1epss 0.02
Digi AnywhereUSB 14 allows XSS via a link for the Digi Page.