VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (46,817)

page 272 of 2,341
  • CVE-2020-5241HigFeb 13, 2020
    risk 0.43cvss 7.7epss 0.01

    matestack-ui-core (RubyGem) before 0.7.4 is vulnerable to XSS/Script injection. This vulnerability is patched in version 0.7.4.

  • CVE-2013-2637MedFeb 12, 2020
    risk 0.43cvss 6.1epss 0.04

    A Cross-Site Scripting (XSS) Vulnerability exists in OTRS ITSM prior to 3.2.4, 3.1.8, and 3.0.7 and FAQ prior to 2.1.4 and 2.0.8 via changes, workorder items, and FAQ articles, which could let a remote malicious user execute arbitrary code.

  • CVE-2020-8839MedFeb 12, 2020
    risk 0.43cvss 6.1epss 0.02

    Stored XSS was discovered on CHIYU BF-430 232/485 TCP/IP Converter devices before 1.16.00, as demonstrated by the /if.cgi TF_submask field.

  • CVE-2013-1410MedFeb 12, 2020
    risk 0.43cvss 6.1epss 0.01

    Perforce P4web 2011.1 and 2012.1 has multiple XSS vulnerabilities

  • CVE-2012-2517MedFeb 11, 2020
    risk 0.43cvss 6.1epss 0.02

    Cross-site scripting (XSS) vulnerability in PrestaShop before 1.4.9 allows remote attackers to inject arbitrary web script or HTML via the index of the product[] parameter to ajax.php.

  • CVE-2012-2452MedFeb 11, 2020
    risk 0.43cvss 6.1epss 0.02

    Multiple cross-site scripting (XSS) vulnerabilities in pragmaMx 1.x before 1.12.2 allow remote attackers to inject arbitrary web script or HTML via the (1) name parameter to modules.php or (2) img_url to includes/wysiwyg/spaw/editor/plugins/imgpopup/img_popup.php.

  • CVE-2013-2684MedFeb 6, 2020
    risk 0.43cvss 6.1epss 0.04

    Cross-site Scripting (XSS) in Cisco Linksys E4200 1.0.05 Build 7 devices allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2012-2593MedFeb 6, 2020
    risk 0.43cvss 6.1epss 0.06

    Cross-site scripting (XSS) vulnerability in the administrative interface in Atmail Webmail Server 6.4 allows remote attackers to inject arbitrary web script or HTML via the Date field of an email.

  • CVE-2013-7054MedFeb 4, 2020
    risk 0.43cvss 6.1epss 0.04

    D-Link DIR-100 4.03B07: cli.cgi XSS

  • CVE-2013-2623MedFeb 3, 2020
    risk 0.43cvss 6.1epss 0.03

    Cross-site Scripting (XSS) in Telaen before 1.3.1 allows remote attackers to inject arbitrary web script or HTML via the "f_email" parameter in index.php.

  • CVE-2013-4241MedJan 30, 2020
    risk 0.43cvss 6.1epss 0.04

    Multiple cross-site scripting (XSS) vulnerabilities in the HMS Testimonials plugin before 2.0.11 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) name, (2) image, (3) url, or (4) testimonial parameter to the Testimonial form…

  • CVE-2013-2294MedJan 30, 2020
    risk 0.43cvss 6.1epss 0.04

    Multiple cross-site scripting (XSS) vulnerabilities in ViewGit before 0.0.7 allow remote repository users to inject arbitrary web script or HTML via a (1) tag name to the Shortlog table in templates/shortlog.php or branch name to the (2) Shortlog table in templates/shortlog.php…

  • CVE-2013-3320MedJan 29, 2020
    risk 0.43cvss 6.1epss 0.02

    Cross-site Scripting (XSS) vulnerability in NetApp OnCommand System Manager before 2.2 allows remote attackers to inject arbitrary web script or HTML via the 'full-name' and 'comment' fields.

  • CVE-2013-2714MedJan 28, 2020
    risk 0.43cvss 6.1epss 0.03

    Cross-site Scripting (XSS) in WordPress podPress Plugin 8.8.10.13 could allow remote attackers to inject arbitrary web script or html via the 'playerID' parameter.

  • CVE-2012-6448MedJan 27, 2020
    risk 0.43cvss 6.1epss 0.02

    Cross-site Scripting (XSS) in cPanel WebHost Manager (WHM) 11.34.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2019-6146MedJan 22, 2020
    risk 0.43cvss 6.1epss 0.03

    It has been reported that cross-site scripting (XSS) is possible in Forcepoint Web Security, version 8.x, via host header injection. CVSSv3.0: 5.3 (Medium) (/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)

  • CVE-2011-4095MedJan 21, 2020
    risk 0.43cvss 6.1epss 0.02

    Jara 1.6 has an XSS vulnerability

  • CVE-2011-4336MedJan 15, 2020
    risk 0.43cvss 6.1epss 0.08

    Tiki Wiki CMS Groupware 7.0 has XSS via the GET "ajax" parameter to snarf_ajax.php.

  • CVE-2011-4595MedJan 10, 2020
    risk 0.43cvss 6.1epss 0.02

    Pretty-Link WordPress plugin 1.5.2 has XSS

  • CVE-2019-18859MedJan 9, 2020
    risk 0.43cvss 6.1epss 0.02

    Digi AnywhereUSB 14 allows XSS via a link for the Digi Page.