CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Description
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85
CVEs mapped to this weakness (46,817)
page 273 of 2,341| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2012-1915 | Med | 0.43 | 6.1 | 0.02 | Jan 9, 2020 | EllisLab CodeIgniter 2.1.2 allows remote attackers to bypass the xss_clean() Filter and perform XSS attacks. | ||
| CVE-2012-1261 | Med | 0.43 | 6.1 | 0.02 | Jan 9, 2020 | Cross-site scripting (XSS) vulnerability in cgi-bin/scrut_fa_exclusions.cgi in Plixer International Scrutinizer NetFlow and sFlow Analyzer 8.6.2.16204 and other versions before 9.0.1.19899 allows remote attackers to inject arbitrary web script or HTML via the standalone… | ||
| CVE-2012-1260 | Med | 0.43 | 6.1 | 0.02 | Jan 9, 2020 | Cross-site scripting (XSS) vulnerability in cgi-bin/userprefs.cgi in Plixer International Scrutinizer NetFlow & sFlow Analyzer 8.6.2.16204, and possibly other versions before 9.0.1.19899, allows remote attackers to inject arbitrary web script or HTML via the newUser parameter.… | ||
| CVE-2020-5191 | Med | 0.43 | 6.1 | 0.06 | Jan 6, 2020 | PHPGurukul Hospital Management System in PHP v4.0 suffers from multiple Persistent XSS vulnerabilities. | ||
| CVE-2019-10227 | Med | 0.43 | 6.1 | 0.01 | Dec 31, 2019 | openITCOCKPIT before 3.7.1 has reflected XSS in the 404-not-found component. | ||
| CVE-2019-9554 | Med | 0.43 | 6.1 | 0.04 | Dec 31, 2019 | In the 3.1.12 Pro version of Craft CMS, XSS has been discovered in the header insertion field when adding source code at an s/admin/entries/news/new URI. | ||
| CVE-2019-9553 | Med | 0.43 | 6.1 | 0.02 | Dec 31, 2019 | Bolt 3.6.4 has XSS via the slug, teaser, or title parameter to editcontent/pages, a related issue to CVE-2017-11128 and CVE-2018-19933. | ||
| CVE-2014-6420 | Med | 0.43 | 6.1 | 0.02 | Dec 27, 2019 | Cross-site scripting (XSS) vulnerability in Livefyre LiveComments 3.0 allows remote attackers to inject arbitrary web script or HTML via the name of an uploaded picture. | ||
| CVE-2013-4692 | Med | 0.43 | 6.1 | 0.02 | Dec 27, 2019 | Xorbin Analog Flash Clock 1.0 extension for Joomia has XSS | ||
| CVE-2013-4664 | Med | 0.43 | 6.1 | 0.02 | Dec 27, 2019 | SPBAS Business Automation Software 2012 has XSS. | ||
| CVE-2019-8690 | Med | 0.43 | 6.1 | 0.05 | Dec 18, 2019 | A logic issue existed in the handling of document loads. This issue was addressed with improved state management. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, Safari 12.1.2, iTunes for Windows 12.9.6, iCloud for Windows 7.13, iCloud for Windows 10.6.… | ||
| CVE-2019-8649 | Med | 0.43 | 6.1 | 0.05 | Dec 18, 2019 | A logic issue existed in the handling of synchronous page loads. This issue was addressed with improved state management. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, Safari 12.1.2, iTunes for Windows 12.9.6, iCloud for Windows 7.13, iCloud for Windows 10.6.… | ||
| CVE-2012-2237 | Med | 0.43 | 6.1 | 0.03 | Dec 17, 2019 | Multiple cross-site scripting (XSS) vulnerabilities in Mahara 1.4.x before 1.4.3 and 1.5.x before 1.5.2 allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) javascript innerHTML as used when generating login forms, (2) links or (3) resources… | ||
| CVE-2013-5978 | Med | 0.43 | 6.1 | 0.04 | Dec 11, 2019 | Multiple cross-site scripting (XSS) vulnerabilities in products.php in the Cart66 Lite plugin before 1.5.1.15 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) Product name or (2) Price description fields via a request to wp-admin/admin.php.… | ||
| CVE-2012-5193 | Med | 0.43 | 6.1 | 0.02 | Nov 13, 2019 | Multiple cross-site scripting (XSS) vulnerabilities in Bitweaver 2.8.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the path info to (1) stats/index.php or (2) newsletters/edition.php or the (3) username parameter to users/remind_password.php,… | ||
| CVE-2012-4384 | Med | 0.43 | 6.1 | 0.02 | Nov 13, 2019 | letodms has multiple XSS issues: Reflected XSS in Login Page, Stored XSS in Document Owner/User name, Stored XSS in Calendar | ||
| CVE-2019-17504 | Med | 0.43 | 6.1 | 0.03 | Oct 11, 2019 | An issue was discovered in Kirona Dynamic Resource Scheduling (DRS) 5.5.3.5. A reflected Cross-site scripting (XSS) vulnerability allows remote attackers to inject arbitrary web script via the /osm/report/ password parameter. | ||
| CVE-2019-12562 | Med | 0.43 | 6.1 | 0.06 | Sep 26, 2019 | Stored Cross-Site Scripting in DotNetNuke (DNN) Version before 9.4.0 allows remote attackers to store and embed the malicious script into the admin notification page. The exploit could be used to perfom any action with admin privileges such as managing content, adding users,… | ||
| CVE-2019-8368 | Med | 0.43 | 6.1 | 0.46 | Sep 16, 2019 | OpenEMR v5.0.1-6 allows XSS. | ||
| CVE-2019-16118 | Med | 0.43 | 6.1 | 0.05 | Sep 8, 2019 | Cross site scripting (XSS) in the photo-gallery (10Web Photo Gallery) plugin before 1.5.35 for WordPress exists via admin/controllers/Options.php. |
- risk 0.43cvss 6.1epss 0.02
EllisLab CodeIgniter 2.1.2 allows remote attackers to bypass the xss_clean() Filter and perform XSS attacks.
- risk 0.43cvss 6.1epss 0.02
Cross-site scripting (XSS) vulnerability in cgi-bin/scrut_fa_exclusions.cgi in Plixer International Scrutinizer NetFlow and sFlow Analyzer 8.6.2.16204 and other versions before 9.0.1.19899 allows remote attackers to inject arbitrary web script or HTML via the standalone…
- risk 0.43cvss 6.1epss 0.02
Cross-site scripting (XSS) vulnerability in cgi-bin/userprefs.cgi in Plixer International Scrutinizer NetFlow & sFlow Analyzer 8.6.2.16204, and possibly other versions before 9.0.1.19899, allows remote attackers to inject arbitrary web script or HTML via the newUser parameter.…
- risk 0.43cvss 6.1epss 0.06
PHPGurukul Hospital Management System in PHP v4.0 suffers from multiple Persistent XSS vulnerabilities.
- risk 0.43cvss 6.1epss 0.01
openITCOCKPIT before 3.7.1 has reflected XSS in the 404-not-found component.
- risk 0.43cvss 6.1epss 0.04
In the 3.1.12 Pro version of Craft CMS, XSS has been discovered in the header insertion field when adding source code at an s/admin/entries/news/new URI.
- risk 0.43cvss 6.1epss 0.02
Bolt 3.6.4 has XSS via the slug, teaser, or title parameter to editcontent/pages, a related issue to CVE-2017-11128 and CVE-2018-19933.
- risk 0.43cvss 6.1epss 0.02
Cross-site scripting (XSS) vulnerability in Livefyre LiveComments 3.0 allows remote attackers to inject arbitrary web script or HTML via the name of an uploaded picture.
- risk 0.43cvss 6.1epss 0.02
Xorbin Analog Flash Clock 1.0 extension for Joomia has XSS
- risk 0.43cvss 6.1epss 0.02
SPBAS Business Automation Software 2012 has XSS.
- risk 0.43cvss 6.1epss 0.05
A logic issue existed in the handling of document loads. This issue was addressed with improved state management. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, Safari 12.1.2, iTunes for Windows 12.9.6, iCloud for Windows 7.13, iCloud for Windows 10.6.…
- risk 0.43cvss 6.1epss 0.05
A logic issue existed in the handling of synchronous page loads. This issue was addressed with improved state management. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, Safari 12.1.2, iTunes for Windows 12.9.6, iCloud for Windows 7.13, iCloud for Windows 10.6.…
- risk 0.43cvss 6.1epss 0.03
Multiple cross-site scripting (XSS) vulnerabilities in Mahara 1.4.x before 1.4.3 and 1.5.x before 1.5.2 allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) javascript innerHTML as used when generating login forms, (2) links or (3) resources…
- risk 0.43cvss 6.1epss 0.04
Multiple cross-site scripting (XSS) vulnerabilities in products.php in the Cart66 Lite plugin before 1.5.1.15 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) Product name or (2) Price description fields via a request to wp-admin/admin.php.…
- risk 0.43cvss 6.1epss 0.02
Multiple cross-site scripting (XSS) vulnerabilities in Bitweaver 2.8.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the path info to (1) stats/index.php or (2) newsletters/edition.php or the (3) username parameter to users/remind_password.php,…
- risk 0.43cvss 6.1epss 0.02
letodms has multiple XSS issues: Reflected XSS in Login Page, Stored XSS in Document Owner/User name, Stored XSS in Calendar
- risk 0.43cvss 6.1epss 0.03
An issue was discovered in Kirona Dynamic Resource Scheduling (DRS) 5.5.3.5. A reflected Cross-site scripting (XSS) vulnerability allows remote attackers to inject arbitrary web script via the /osm/report/ password parameter.
- risk 0.43cvss 6.1epss 0.06
Stored Cross-Site Scripting in DotNetNuke (DNN) Version before 9.4.0 allows remote attackers to store and embed the malicious script into the admin notification page. The exploit could be used to perfom any action with admin privileges such as managing content, adding users,…
- risk 0.43cvss 6.1epss 0.46
OpenEMR v5.0.1-6 allows XSS.
- risk 0.43cvss 6.1epss 0.05
Cross site scripting (XSS) in the photo-gallery (10Web Photo Gallery) plugin before 1.5.35 for WordPress exists via admin/controllers/Options.php.