CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Description
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85
CVEs mapped to this weakness (46,817)
page 274 of 2,341| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-16117 | Med | 0.43 | 6.1 | 0.05 | Sep 8, 2019 | Cross site scripting (XSS) in the photo-gallery (10Web Photo Gallery) plugin before 1.5.35 for WordPress exists via admin/models/Galleries.php. | ||
| CVE-2019-10677 | Med | 0.43 | 6.1 | 0.07 | Sep 5, 2019 | Multiple Cross-Site Scripting (XSS) issues in the web interface on DASAN Zhone ZNID GPON 2426A EU version S3.1.285 devices allow a remote attacker to execute arbitrary JavaScript via manipulation of an unsanitized GET parameter: /zhndnsdisplay.cmd (name), /wlsecrefresh.wl… | ||
| CVE-2019-15811 | Med | 0.43 | 6.1 | 0.07 | Aug 29, 2019 | In DomainMOD through 4.13, the parameter daterange in the file reporting/domains/cost-by-month.php has XSS. | ||
| CVE-2019-13236 | Med | 0.43 | 6.1 | 0.03 | Aug 27, 2019 | In system/workplace/ in Alkacon OpenCms 10.5.4 and 10.5.5, there are multiple Reflected and Stored XSS issues in the management interface. | ||
| CVE-2019-13235 | Med | 0.43 | 6.1 | 0.03 | Aug 27, 2019 | In the Alkacon OpenCms Apollo Template 10.5.4 and 10.5.5, there is XSS in the Login form. | ||
| CVE-2019-13234 | Med | 0.43 | 6.1 | 0.03 | Aug 27, 2019 | In the Alkacon OpenCms Apollo Template 10.5.4 and 10.5.5, there is XSS in the search engine. | ||
| CVE-2019-15501 | Med | 0.43 | 6.1 | 0.07 | Aug 26, 2019 | Reflected cross site scripting (XSS) in L-Soft LISTSERV before 16.5-2018a exists via the /scripts/wa.exe OK parameter. | ||
| CVE-2019-13346 | Med | 0.43 | 6.1 | 0.02 | Jul 17, 2019 | In MyT 1.5.1, the User[username] parameter has XSS. | ||
| CVE-2019-12962 | Med | 0.43 | 6.1 | 0.09 | Jun 25, 2019 | LiveZilla Server before 8.0.1.1 is vulnerable to XSS in mobile/index.php via the Accept-Language HTTP header. | ||
| CVE-2019-12905 | Med | 0.43 | 6.1 | 0.04 | Jun 20, 2019 | FileRun 2019.05.21 allows XSS via the filename to the ?module=fileman§ion=do&page=up URI. This issue has been fixed in FileRun 2019.06.01. | ||
| CVE-2019-6965 | Med | 0.43 | 6.1 | 0.03 | Jun 18, 2019 | An XSS issue was discovered in i-doit Open 1.12 via the src/tools/php/qr/qr.php url parameter. | ||
| CVE-2019-12801 | Med | 0.43 | 6.1 | 0.02 | Jun 17, 2019 | out/out.GroupMgr.php in SeedDMS 5.1.11 has Stored XSS by making a new group with a JavaScript payload as the "GROUP" Name. | ||
| CVE-2018-10700 | Med | 0.43 | 6.1 | 0.38 | Jun 7, 2019 | An issue was discovered on Moxa AWK-3121 1.19 devices. It provides functionality so that an administrator can change the name of the device. However, the same functionality allows an attacker to execute XSS by injecting an XSS payload. The POST parameter "iw_board_deviceName" is… | ||
| CVE-2019-9647 | Med | 0.43 | 6.1 | 0.02 | Jun 5, 2019 | Gila CMS 1.9.1 has XSS. | ||
| CVE-2019-12543 | Med | 0.43 | 6.1 | 0.06 | Jun 5, 2019 | An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the PurchaseRequest.do serviceRequestId parameter. | ||
| CVE-2019-12542 | Med | 0.43 | 6.1 | 0.06 | Jun 5, 2019 | An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the SearchN.do userConfigID parameter. | ||
| CVE-2019-12541 | Med | 0.43 | 6.1 | 0.06 | Jun 5, 2019 | An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the SolutionSearch.do searchText parameter. | ||
| CVE-2019-12538 | Med | 0.43 | 6.1 | 0.06 | Jun 5, 2019 | An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the SiteLookup.do search field. | ||
| CVE-2019-12461 | Med | 0.43 | 6.1 | 0.10 | May 30, 2019 | Web Port 1.19.1 allows XSS via the /log type parameter. | ||
| CVE-2019-12460 | Med | 0.43 | 6.1 | 0.04 | May 30, 2019 | Web Port 1.19.1 allows XSS via the /access/setup type parameter. |
- risk 0.43cvss 6.1epss 0.05
Cross site scripting (XSS) in the photo-gallery (10Web Photo Gallery) plugin before 1.5.35 for WordPress exists via admin/models/Galleries.php.
- risk 0.43cvss 6.1epss 0.07
Multiple Cross-Site Scripting (XSS) issues in the web interface on DASAN Zhone ZNID GPON 2426A EU version S3.1.285 devices allow a remote attacker to execute arbitrary JavaScript via manipulation of an unsanitized GET parameter: /zhndnsdisplay.cmd (name), /wlsecrefresh.wl…
- risk 0.43cvss 6.1epss 0.07
In DomainMOD through 4.13, the parameter daterange in the file reporting/domains/cost-by-month.php has XSS.
- risk 0.43cvss 6.1epss 0.03
In system/workplace/ in Alkacon OpenCms 10.5.4 and 10.5.5, there are multiple Reflected and Stored XSS issues in the management interface.
- risk 0.43cvss 6.1epss 0.03
In the Alkacon OpenCms Apollo Template 10.5.4 and 10.5.5, there is XSS in the Login form.
- risk 0.43cvss 6.1epss 0.03
In the Alkacon OpenCms Apollo Template 10.5.4 and 10.5.5, there is XSS in the search engine.
- risk 0.43cvss 6.1epss 0.07
Reflected cross site scripting (XSS) in L-Soft LISTSERV before 16.5-2018a exists via the /scripts/wa.exe OK parameter.
- risk 0.43cvss 6.1epss 0.02
In MyT 1.5.1, the User[username] parameter has XSS.
- risk 0.43cvss 6.1epss 0.09
LiveZilla Server before 8.0.1.1 is vulnerable to XSS in mobile/index.php via the Accept-Language HTTP header.
- risk 0.43cvss 6.1epss 0.04
FileRun 2019.05.21 allows XSS via the filename to the ?module=fileman§ion=do&page=up URI. This issue has been fixed in FileRun 2019.06.01.
- risk 0.43cvss 6.1epss 0.03
An XSS issue was discovered in i-doit Open 1.12 via the src/tools/php/qr/qr.php url parameter.
- risk 0.43cvss 6.1epss 0.02
out/out.GroupMgr.php in SeedDMS 5.1.11 has Stored XSS by making a new group with a JavaScript payload as the "GROUP" Name.
- risk 0.43cvss 6.1epss 0.38
An issue was discovered on Moxa AWK-3121 1.19 devices. It provides functionality so that an administrator can change the name of the device. However, the same functionality allows an attacker to execute XSS by injecting an XSS payload. The POST parameter "iw_board_deviceName" is…
- risk 0.43cvss 6.1epss 0.02
Gila CMS 1.9.1 has XSS.
- risk 0.43cvss 6.1epss 0.06
An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the PurchaseRequest.do serviceRequestId parameter.
- risk 0.43cvss 6.1epss 0.06
An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the SearchN.do userConfigID parameter.
- risk 0.43cvss 6.1epss 0.06
An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the SolutionSearch.do searchText parameter.
- risk 0.43cvss 6.1epss 0.06
An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the SiteLookup.do search field.
- risk 0.43cvss 6.1epss 0.10
Web Port 1.19.1 allows XSS via the /log type parameter.
- risk 0.43cvss 6.1epss 0.04
Web Port 1.19.1 allows XSS via the /access/setup type parameter.