VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (46,817)

page 273 of 2,341
  • CVE-2012-1915MedJan 9, 2020
    risk 0.43cvss 6.1epss 0.02

    EllisLab CodeIgniter 2.1.2 allows remote attackers to bypass the xss_clean() Filter and perform XSS attacks.

  • CVE-2012-1261MedJan 9, 2020
    risk 0.43cvss 6.1epss 0.02

    Cross-site scripting (XSS) vulnerability in cgi-bin/scrut_fa_exclusions.cgi in Plixer International Scrutinizer NetFlow and sFlow Analyzer 8.6.2.16204 and other versions before 9.0.1.19899 allows remote attackers to inject arbitrary web script or HTML via the standalone…

  • CVE-2012-1260MedJan 9, 2020
    risk 0.43cvss 6.1epss 0.02

    Cross-site scripting (XSS) vulnerability in cgi-bin/userprefs.cgi in Plixer International Scrutinizer NetFlow & sFlow Analyzer 8.6.2.16204, and possibly other versions before 9.0.1.19899, allows remote attackers to inject arbitrary web script or HTML via the newUser parameter.…

  • CVE-2020-5191MedJan 6, 2020
    risk 0.43cvss 6.1epss 0.06

    PHPGurukul Hospital Management System in PHP v4.0 suffers from multiple Persistent XSS vulnerabilities.

  • CVE-2019-10227MedDec 31, 2019
    risk 0.43cvss 6.1epss 0.01

    openITCOCKPIT before 3.7.1 has reflected XSS in the 404-not-found component.

  • CVE-2019-9554MedDec 31, 2019
    risk 0.43cvss 6.1epss 0.04

    In the 3.1.12 Pro version of Craft CMS, XSS has been discovered in the header insertion field when adding source code at an s/admin/entries/news/new URI.

  • CVE-2019-9553MedDec 31, 2019
    risk 0.43cvss 6.1epss 0.02

    Bolt 3.6.4 has XSS via the slug, teaser, or title parameter to editcontent/pages, a related issue to CVE-2017-11128 and CVE-2018-19933.

  • CVE-2014-6420MedDec 27, 2019
    risk 0.43cvss 6.1epss 0.02

    Cross-site scripting (XSS) vulnerability in Livefyre LiveComments 3.0 allows remote attackers to inject arbitrary web script or HTML via the name of an uploaded picture.

  • CVE-2013-4692MedDec 27, 2019
    risk 0.43cvss 6.1epss 0.02

    Xorbin Analog Flash Clock 1.0 extension for Joomia has XSS

  • CVE-2013-4664MedDec 27, 2019
    risk 0.43cvss 6.1epss 0.02

    SPBAS Business Automation Software 2012 has XSS.

  • CVE-2019-8690MedDec 18, 2019
    risk 0.43cvss 6.1epss 0.05

    A logic issue existed in the handling of document loads. This issue was addressed with improved state management. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, Safari 12.1.2, iTunes for Windows 12.9.6, iCloud for Windows 7.13, iCloud for Windows 10.6.…

  • CVE-2019-8649MedDec 18, 2019
    risk 0.43cvss 6.1epss 0.05

    A logic issue existed in the handling of synchronous page loads. This issue was addressed with improved state management. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, Safari 12.1.2, iTunes for Windows 12.9.6, iCloud for Windows 7.13, iCloud for Windows 10.6.…

  • CVE-2012-2237MedDec 17, 2019
    risk 0.43cvss 6.1epss 0.03

    Multiple cross-site scripting (XSS) vulnerabilities in Mahara 1.4.x before 1.4.3 and 1.5.x before 1.5.2 allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) javascript innerHTML as used when generating login forms, (2) links or (3) resources…

  • CVE-2013-5978MedDec 11, 2019
    risk 0.43cvss 6.1epss 0.04

    Multiple cross-site scripting (XSS) vulnerabilities in products.php in the Cart66 Lite plugin before 1.5.1.15 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) Product name or (2) Price description fields via a request to wp-admin/admin.php.…

  • CVE-2012-5193MedNov 13, 2019
    risk 0.43cvss 6.1epss 0.02

    Multiple cross-site scripting (XSS) vulnerabilities in Bitweaver 2.8.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the path info to (1) stats/index.php or (2) newsletters/edition.php or the (3) username parameter to users/remind_password.php,…

  • CVE-2012-4384MedNov 13, 2019
    risk 0.43cvss 6.1epss 0.02

    letodms has multiple XSS issues: Reflected XSS in Login Page, Stored XSS in Document Owner/User name, Stored XSS in Calendar

  • CVE-2019-17504MedOct 11, 2019
    risk 0.43cvss 6.1epss 0.03

    An issue was discovered in Kirona Dynamic Resource Scheduling (DRS) 5.5.3.5. A reflected Cross-site scripting (XSS) vulnerability allows remote attackers to inject arbitrary web script via the /osm/report/ password parameter.

  • CVE-2019-12562MedSep 26, 2019
    risk 0.43cvss 6.1epss 0.06

    Stored Cross-Site Scripting in DotNetNuke (DNN) Version before 9.4.0 allows remote attackers to store and embed the malicious script into the admin notification page. The exploit could be used to perfom any action with admin privileges such as managing content, adding users,…

  • CVE-2019-8368MedSep 16, 2019
    risk 0.43cvss 6.1epss 0.46

    OpenEMR v5.0.1-6 allows XSS.

  • CVE-2019-16118MedSep 8, 2019
    risk 0.43cvss 6.1epss 0.05

    Cross site scripting (XSS) in the photo-gallery (10Web Photo Gallery) plugin before 1.5.35 for WordPress exists via admin/controllers/Options.php.