CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Description
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85
CVEs mapped to this weakness (46,817)
page 278 of 2,341| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2018-15608 | Med | 0.43 | 6.1 | 0.02 | Aug 28, 2018 | Zoho ManageEngine ADManager Plus 6.5.7 allows HTML Injection on the "AD Delegation" "Help Desk Technicians" screen. | ||
| CVE-2018-15596 | Med | 0.43 | 6.1 | 0.02 | Aug 28, 2018 | An issue was discovered in inc/class_feedgeneration.php in MyBB 1.8.17. On the forum RSS Syndication page, one can generate a URL such as http://localhost/syndication.php?fid=&type=atom1.0&limit=15. The thread titles (within title elements of the generated XML documents) aren't… | ||
| CVE-2018-0715 | Med | 0.43 | 6.1 | 0.03 | Aug 27, 2018 | Cross-site scripting vulnerability in QNAP Photo Station versions 5.7.0 and earlier could allow remote attackers to inject Javascript code in the compromised application. | ||
| CVE-2018-15533 | Med | 0.43 | 6.1 | 0.03 | Aug 21, 2018 | A reflected cross-site scripting vulnerability exists in Geutebrueck re_porter 16 before 7.8.974.20 by appending a query string to /modifychannel/exec or /images/*.png on TCP port 12005. | ||
| CVE-2018-1000638 | — | Med | 0.43 | 6.1 | 0.02 | Aug 20, 2018 | MiniCMS version 1.1 contains a Cross Site Scripting (XSS) vulnerability in http://example.org/mc-admin/page.php?date={payload} that can result in code injection. | |
| CVE-2018-13849 | Med | 0.43 | 6.1 | 0.02 | Jul 10, 2018 | edit_requests.php in yTakkar Instagram-clone through 2018-04-23 has XSS via an onmouseover payload because of an inadequate XSS protection mechanism based on preg_replace. | ||
| CVE-2018-8738 | Med | 0.43 | 6.1 | 0.02 | Jul 5, 2018 | Airties 5444 1.0.0.18 and 5444TT 1.0.0.18 devices allow XSS. | ||
| CVE-2018-13134 | Med | 0.43 | 6.1 | 0.02 | Jul 4, 2018 | TP-Link Archer C1200 1.13 Build 2018/01/24 rel.52299 EU devices have XSS via the PATH_INFO to the /webpages/data URI. | ||
| CVE-2018-12905 | Med | 0.43 | 6.1 | 0.42 | Jun 27, 2018 | joyplus-cms 1.6.0 has XSS in admin_player.php, related to manager/index.php "system manage" and "add" actions. | ||
| CVE-2018-12705 | Med | 0.43 | 6.1 | 0.02 | Jun 24, 2018 | DIGISOL DG-BR4000NG devices have XSS via the SSID (it is validated only on the client side). | ||
| CVE-2018-12111 | Med | 0.43 | 6.1 | 0.02 | Jun 11, 2018 | Cross-site scripting (XSS) vulnerability in the Canon PrintMe EFI webinterface allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to the /wt3/mydocs.php URI. | ||
| CVE-2018-12090 | Med | 0.43 | 6.1 | 0.02 | Jun 11, 2018 | There is unauthenticated reflected cross-site scripting (XSS) in LAMS before 3.1 that allows a remote attacker to introduce arbitrary JavaScript via manipulation of an unsanitized GET parameter during a forgotPasswordChange.jsp?key= password change. | ||
| CVE-2018-11522 | Med | 0.43 | 6.1 | 0.04 | Jun 2, 2018 | Yosoro 1.0.4 has stored XSS. | ||
| CVE-2018-11628 | Med | 0.43 | 6.1 | 0.03 | Jun 1, 2018 | Data input into EMS Master Calendar before 8.0.0.201805210 via URL parameters is not properly sanitized, allowing malicious attackers to send a crafted URL for XSS. | ||
| CVE-2018-11443 | Med | 0.43 | 6.1 | 0.03 | May 25, 2018 | The parameter q is affected by Cross-site Scripting in jobcard-ongoing.php in EasyService Billing 1.0. | ||
| CVE-2018-11415 | Med | 0.43 | 6.1 | 0.08 | May 24, 2018 | SAP Internet Transaction Server (ITS) 6200.X.X has Reflected Cross Site Scripting (XSS) via certain wgate URIs. NOTE: the vendor has reportedly indicated that there will not be any further releases of this product. | ||
| CVE-2018-11404 | Med | 0.43 | 6.1 | 0.02 | May 24, 2018 | DomainMod v4.09.03 has XSS via the assets/edit/ssl-provider-account.php sslpaid parameter. | ||
| CVE-2018-11339 | Med | 0.43 | 6.1 | 0.04 | May 22, 2018 | An XSS issue was discovered in Frappe ERPNext v11.x.x-develop b1036e5 via a comment. | ||
| CVE-2018-5230 | Med | 0.43 | 6.1 | 0.38 | May 14, 2018 | The issue collector in Atlassian Jira before version 7.6.6, from version 7.7.0 before version 7.7.4, from version 7.8.0 before version 7.8.4 and from version 7.9.0 before version 7.9.2 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting… | ||
| CVE-2018-6361 | Med | 0.43 | 6.1 | 0.40 | May 11, 2018 | Easy Hosting Control Panel (EHCP) v0.37.12.b has XSS via the op parameter, as demonstrated by adding a backdoor FTP account. |
- risk 0.43cvss 6.1epss 0.02
Zoho ManageEngine ADManager Plus 6.5.7 allows HTML Injection on the "AD Delegation" "Help Desk Technicians" screen.
- risk 0.43cvss 6.1epss 0.02
An issue was discovered in inc/class_feedgeneration.php in MyBB 1.8.17. On the forum RSS Syndication page, one can generate a URL such as http://localhost/syndication.php?fid=&type=atom1.0&limit=15. The thread titles (within title elements of the generated XML documents) aren't…
- risk 0.43cvss 6.1epss 0.03
Cross-site scripting vulnerability in QNAP Photo Station versions 5.7.0 and earlier could allow remote attackers to inject Javascript code in the compromised application.
- risk 0.43cvss 6.1epss 0.03
A reflected cross-site scripting vulnerability exists in Geutebrueck re_porter 16 before 7.8.974.20 by appending a query string to /modifychannel/exec or /images/*.png on TCP port 12005.
- risk 0.43cvss 6.1epss 0.02
MiniCMS version 1.1 contains a Cross Site Scripting (XSS) vulnerability in http://example.org/mc-admin/page.php?date={payload} that can result in code injection.
- risk 0.43cvss 6.1epss 0.02
edit_requests.php in yTakkar Instagram-clone through 2018-04-23 has XSS via an onmouseover payload because of an inadequate XSS protection mechanism based on preg_replace.
- risk 0.43cvss 6.1epss 0.02
Airties 5444 1.0.0.18 and 5444TT 1.0.0.18 devices allow XSS.
- risk 0.43cvss 6.1epss 0.02
TP-Link Archer C1200 1.13 Build 2018/01/24 rel.52299 EU devices have XSS via the PATH_INFO to the /webpages/data URI.
- risk 0.43cvss 6.1epss 0.42
joyplus-cms 1.6.0 has XSS in admin_player.php, related to manager/index.php "system manage" and "add" actions.
- risk 0.43cvss 6.1epss 0.02
DIGISOL DG-BR4000NG devices have XSS via the SSID (it is validated only on the client side).
- risk 0.43cvss 6.1epss 0.02
Cross-site scripting (XSS) vulnerability in the Canon PrintMe EFI webinterface allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to the /wt3/mydocs.php URI.
- risk 0.43cvss 6.1epss 0.02
There is unauthenticated reflected cross-site scripting (XSS) in LAMS before 3.1 that allows a remote attacker to introduce arbitrary JavaScript via manipulation of an unsanitized GET parameter during a forgotPasswordChange.jsp?key= password change.
- risk 0.43cvss 6.1epss 0.04
Yosoro 1.0.4 has stored XSS.
- risk 0.43cvss 6.1epss 0.03
Data input into EMS Master Calendar before 8.0.0.201805210 via URL parameters is not properly sanitized, allowing malicious attackers to send a crafted URL for XSS.
- risk 0.43cvss 6.1epss 0.03
The parameter q is affected by Cross-site Scripting in jobcard-ongoing.php in EasyService Billing 1.0.
- risk 0.43cvss 6.1epss 0.08
SAP Internet Transaction Server (ITS) 6200.X.X has Reflected Cross Site Scripting (XSS) via certain wgate URIs. NOTE: the vendor has reportedly indicated that there will not be any further releases of this product.
- risk 0.43cvss 6.1epss 0.02
DomainMod v4.09.03 has XSS via the assets/edit/ssl-provider-account.php sslpaid parameter.
- risk 0.43cvss 6.1epss 0.04
An XSS issue was discovered in Frappe ERPNext v11.x.x-develop b1036e5 via a comment.
- risk 0.43cvss 6.1epss 0.38
The issue collector in Atlassian Jira before version 7.6.6, from version 7.7.0 before version 7.7.4, from version 7.8.0 before version 7.8.4 and from version 7.9.0 before version 7.9.2 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting…
- risk 0.43cvss 6.1epss 0.40
Easy Hosting Control Panel (EHCP) v0.37.12.b has XSS via the op parameter, as demonstrated by adding a backdoor FTP account.