CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Description
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85
CVEs mapped to this weakness (46,817)
page 276 of 2,341| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2018-17997 | Med | 0.43 | 6.1 | 0.04 | Mar 21, 2019 | LayerBB 1.1.1 allows XSS via the titles of conversations (PMs). | ||
| CVE-2019-9834 | Med | 0.43 | 6.1 | 0.05 | Mar 15, 2019 | The Netdata web application through 1.13.0 allows remote attackers to inject their own malicious HTML code into an imported snapshot, aka HTML Injection. Successful exploitation will allow attacker-supplied HTML to run in the context of the affected browser, potentially allowing… | ||
| CVE-2019-9593 | Med | 0.43 | 6.1 | 0.04 | Mar 6, 2019 | A reflected Cross-site scripting (XSS) vulnerability in ShoreTel Connect ONSITE 18.82.2000.0 allows remote attackers to inject arbitrary web script or HTML via the page parameter. | ||
| CVE-2019-9592 | Med | 0.43 | 6.1 | 0.05 | Mar 6, 2019 | A reflected Cross-site scripting (XSS) vulnerability in ShoreTel Connect ONSITE 19.45.1602.0 allows remote attackers to inject arbitrary web script or HTML via the url parameter. | ||
| CVE-2019-9591 | Med | 0.43 | 6.1 | 0.05 | Mar 6, 2019 | A reflected Cross-site scripting (XSS) vulnerability in ShoreTel Connect ONSITE before 19.49.1500.0 allows remote attackers to inject arbitrary web script or HTML via the brandUrl parameter. | ||
| CVE-2014-10078 | Med | 0.43 | 6.1 | 0.03 | Feb 23, 2019 | Vembu StoreGrid 4.4.x has XSS in interface/registercustomer/onlineregsuccess.php, interface/registerreseller/onlineregfailure.php, interface/registerclient/onlineregfailure.php, and interface/registercustomer/onlineregfailure.php. | ||
| CVE-2019-7400 | Med | 0.43 | 6.1 | 0.06 | Feb 5, 2019 | Rukovoditel before 2.4.1 allows XSS. | ||
| CVE-2018-19041 | Med | 0.43 | 6.1 | 0.03 | Jan 31, 2019 | The Media File Manager plugin 1.4.2 for WordPress allows XSS via the dir parameter of an mrelocator_getdir action to the wp-admin/admin-ajax.php URI. | ||
| CVE-2018-19782 | Med | 0.43 | 6.1 | 0.04 | Jan 30, 2019 | Multiple cross-site scripting (XSS) vulnerabilities in GET requests in FreshRSS 1.11.1 allow remote attackers to inject arbitrary web script or HTML via the (1) c parameter or (2) a parameter. | ||
| CVE-2019-1642 | Med | 0.43 | 6.1 | 0.04 | Jan 23, 2019 | A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of the affected software.… | ||
| CVE-2019-2413 | Med | 0.43 | 6.1 | 0.06 | Jan 16, 2019 | Vulnerability in the Oracle Reports Developer component of Oracle Fusion Middleware (subcomponent: Valid Session). The supported version that is affected is 12.2.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise… | ||
| CVE-2018-20326 | Med | 0.43 | 6.1 | 0.05 | Jan 2, 2019 | ChinaMobile PLC Wireless Router GPN2.4P21-C-CN devices with firmware W2001EN-00 have XSS via the cgi-bin/webproc?getpage=html/index.html var:subpage parameter. | ||
| CVE-2018-19799 | Med | 0.43 | 6.1 | 0.04 | Dec 26, 2018 | Dolibarr ERP/CRM through 8.0.3 has /exports/export.php?datatoexport= XSS. | ||
| CVE-2018-20485 | Med | 0.43 | 6.1 | 0.05 | Dec 26, 2018 | Zoho ManageEngine ADSelfService Plus 5.7 before build 5702 has XSS in the employee search feature. | ||
| CVE-2018-20484 | Med | 0.43 | 6.1 | 0.05 | Dec 26, 2018 | Zoho ManageEngine ADSelfService Plus 5.7 before build 5702 has XSS in the self-update layout implementation. | ||
| CVE-2018-19933 | Med | 0.43 | 6.1 | 0.03 | Dec 17, 2018 | Bolt CMS <3.6.2 allows XSS via text input click preview button as demonstrated by the Title field of a Configured and New Entry. | ||
| CVE-2018-19828 | Med | 0.43 | 6.1 | 0.02 | Dec 17, 2018 | Artica Integria IMS 5.0.83 has XSS via the search_string parameter. | ||
| CVE-2018-18774 | Med | 0.43 | 6.1 | 0.05 | Nov 20, 2018 | CentOS-WebPanel.com (aka CWP) CentOS Web Panel through 0.9.8.740 allows XSS via the admin/index.php module parameter. | ||
| CVE-2018-19136 | Med | 0.43 | 6.1 | 0.07 | Nov 9, 2018 | DomainMOD through 4.11.01 has XSS via the assets/edit/registrar-account.php raid parameter. | ||
| CVE-2018-18776 | Med | 0.43 | 6.1 | 0.02 | Nov 1, 2018 | Microstrategy Web, version 7, does not sufficiently encode user-controlled inputs, resulting in a Cross-Site Scripting (XSS) vulnerability via the admin/admin.asp ShowAll parameter. NOTE: this is a deprecated product. |
- risk 0.43cvss 6.1epss 0.04
LayerBB 1.1.1 allows XSS via the titles of conversations (PMs).
- risk 0.43cvss 6.1epss 0.05
The Netdata web application through 1.13.0 allows remote attackers to inject their own malicious HTML code into an imported snapshot, aka HTML Injection. Successful exploitation will allow attacker-supplied HTML to run in the context of the affected browser, potentially allowing…
- risk 0.43cvss 6.1epss 0.04
A reflected Cross-site scripting (XSS) vulnerability in ShoreTel Connect ONSITE 18.82.2000.0 allows remote attackers to inject arbitrary web script or HTML via the page parameter.
- risk 0.43cvss 6.1epss 0.05
A reflected Cross-site scripting (XSS) vulnerability in ShoreTel Connect ONSITE 19.45.1602.0 allows remote attackers to inject arbitrary web script or HTML via the url parameter.
- risk 0.43cvss 6.1epss 0.05
A reflected Cross-site scripting (XSS) vulnerability in ShoreTel Connect ONSITE before 19.49.1500.0 allows remote attackers to inject arbitrary web script or HTML via the brandUrl parameter.
- risk 0.43cvss 6.1epss 0.03
Vembu StoreGrid 4.4.x has XSS in interface/registercustomer/onlineregsuccess.php, interface/registerreseller/onlineregfailure.php, interface/registerclient/onlineregfailure.php, and interface/registercustomer/onlineregfailure.php.
- risk 0.43cvss 6.1epss 0.06
Rukovoditel before 2.4.1 allows XSS.
- risk 0.43cvss 6.1epss 0.03
The Media File Manager plugin 1.4.2 for WordPress allows XSS via the dir parameter of an mrelocator_getdir action to the wp-admin/admin-ajax.php URI.
- risk 0.43cvss 6.1epss 0.04
Multiple cross-site scripting (XSS) vulnerabilities in GET requests in FreshRSS 1.11.1 allow remote attackers to inject arbitrary web script or HTML via the (1) c parameter or (2) a parameter.
- risk 0.43cvss 6.1epss 0.04
A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of the affected software.…
- risk 0.43cvss 6.1epss 0.06
Vulnerability in the Oracle Reports Developer component of Oracle Fusion Middleware (subcomponent: Valid Session). The supported version that is affected is 12.2.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise…
- risk 0.43cvss 6.1epss 0.05
ChinaMobile PLC Wireless Router GPN2.4P21-C-CN devices with firmware W2001EN-00 have XSS via the cgi-bin/webproc?getpage=html/index.html var:subpage parameter.
- risk 0.43cvss 6.1epss 0.04
Dolibarr ERP/CRM through 8.0.3 has /exports/export.php?datatoexport= XSS.
- risk 0.43cvss 6.1epss 0.05
Zoho ManageEngine ADSelfService Plus 5.7 before build 5702 has XSS in the employee search feature.
- risk 0.43cvss 6.1epss 0.05
Zoho ManageEngine ADSelfService Plus 5.7 before build 5702 has XSS in the self-update layout implementation.
- risk 0.43cvss 6.1epss 0.03
Bolt CMS <3.6.2 allows XSS via text input click preview button as demonstrated by the Title field of a Configured and New Entry.
- risk 0.43cvss 6.1epss 0.02
Artica Integria IMS 5.0.83 has XSS via the search_string parameter.
- risk 0.43cvss 6.1epss 0.05
CentOS-WebPanel.com (aka CWP) CentOS Web Panel through 0.9.8.740 allows XSS via the admin/index.php module parameter.
- risk 0.43cvss 6.1epss 0.07
DomainMOD through 4.11.01 has XSS via the assets/edit/registrar-account.php raid parameter.
- risk 0.43cvss 6.1epss 0.02
Microstrategy Web, version 7, does not sufficiently encode user-controlled inputs, resulting in a Cross-Site Scripting (XSS) vulnerability via the admin/admin.asp ShowAll parameter. NOTE: this is a deprecated product.