CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Description
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85
CVEs mapped to this weakness (46,817)
page 279 of 2,341| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2018-10371 | Med | 0.43 | 6.1 | 0.06 | May 1, 2018 | An issue was discovered in the wunderfarm WF Cookie Consent plugin 1.1.3 for WordPress. A persistent cross-site scripting vulnerability has been identified in the web interface of the plugin that allows the execution of arbitrary HTML/script code to be executed in a victim's web… | ||
| CVE-2018-10311 | Med | 0.43 | 6.1 | 0.02 | Apr 24, 2018 | A vulnerability was discovered in WUZHI CMS 4.1.0. There is persistent XSS that allows remote attackers to inject arbitrary web script or HTML via the tag[pinyin] parameter to the /index.php?m=tags&f=index&v=add URI. | ||
| CVE-2018-10068 | Med | 0.43 | 6.1 | 0.04 | Apr 12, 2018 | The jDownloads extension before 3.2.59 for Joomla! has XSS. | ||
| CVE-2018-8772 | Med | 0.43 | 6.1 | 0.02 | Apr 10, 2018 | Coship RT3052 4.0.0.48 devices allow XSS via a crafted SSID field on the "Wireless Setting - Basic" screen. | ||
| CVE-2018-9857 | Med | 0.43 | 6.1 | 0.02 | Apr 9, 2018 | PHP Scripts Mall Match Clone Script 1.0.4 has XSS via the search field to searchbyid.php (aka the "View Search By Id" screen). | ||
| CVE-2018-9844 | Med | 0.43 | 6.1 | 0.04 | Apr 7, 2018 | The Iptanus WordPress File Upload plugin before 4.3.4 for WordPress mishandles Settings attributes, leading to XSS. | ||
| CVE-2018-9238 | Med | 0.43 | 6.1 | 0.02 | Apr 4, 2018 | proberv.php in Yahei-PHP Proberv 0.4.7 has XSS via the funName parameter. | ||
| CVE-2018-9235 | Med | 0.43 | 6.1 | 0.03 | Apr 4, 2018 | iScripts SonicBB 1.0 has Reflected Cross-Site Scripting via the query parameter to search.php. | ||
| CVE-2018-9173 | Med | 0.43 | 6.1 | 0.02 | Apr 2, 2018 | Cross-site scripting (XSS) vulnerability in admin/template/js/uploadify/uploadify.swf in GetSimple CMS 3.3.13 allows remote attackers to inject arbitrary web script or HTML, as demonstrated by the movieName parameter. | ||
| CVE-2018-7203 | Med | 0.43 | 6.1 | 0.02 | Mar 30, 2018 | Cross-site scripting (XSS) vulnerability in Twonky Server 7.0.11 through 8.5 allows remote attackers to inject arbitrary web script or HTML via the friendlyname parameter to rpc/set_all. | ||
| CVE-2018-7543 | Med | 0.43 | 6.1 | 0.03 | Mar 26, 2018 | Cross-site scripting (XSS) vulnerability in installer/build/view.step4.php of the SnapCreek Duplicator plugin 1.2.32 for WordPress allows remote attackers to inject arbitrary JavaScript or HTML via the json parameter. | ||
| CVE-2018-7707 | Med | 0.43 | 6.1 | 0.03 | Mar 15, 2018 | Cross-site scripting (XSS) vulnerability in SecurEnvoy SecurMail before 9.2.501 allows remote attackers to inject arbitrary web script or HTML via an HTML-formatted e-mail message. | ||
| CVE-2018-7703 | Med | 0.43 | 6.1 | 0.04 | Mar 15, 2018 | Cross-site scripting (XSS) vulnerability in SecurEnvoy SecurMail before 9.2.501 allows remote attackers to inject arbitrary web script or HTML via the mailboxid parameter to secmail/getmessage.exe. | ||
| CVE-2018-7653 | Med | 0.43 | 6.1 | 0.08 | Mar 4, 2018 | In YzmCMS 3.6, index.php has XSS via the a, c, or m parameter. | ||
| CVE-2018-6940 | — | Med | 0.43 | 6.1 | 0.03 | Feb 20, 2018 | A /shell?cmd= XSS issue exists in the HTTPD component of NAT32 v2.2 Build 22284 devices that can be exploited for Remote Code Execution in conjunction with CSRF. | |
| CVE-2017-16356 | Med | 0.43 | 6.1 | 0.02 | Feb 20, 2018 | Reflected XSS in Kubik-Rubik SIGE (aka Simple Image Gallery Extended) before 3.3.0 allows attackers to execute JavaScript in a victim's browser by having them visit a plugins/content/sige/plugin_sige/print.php link with a crafted img, name, or caption parameter. | ||
| CVE-2017-5798 | Med | 0.43 | 6.1 | 0.08 | Feb 15, 2018 | A Remote Code Execution vulnerability in HPE OpenCall Media Platform (OCMP) was found. The vulnerability impacts OCMP versions prior to 3.4.2 RP201 (for OCMP 3.x), all versions prior to 4.4.7 RP702 (for OCMP 4.x). | ||
| CVE-2018-6845 | Med | 0.43 | 6.1 | 0.03 | Feb 12, 2018 | PHP Scripts Mall Multi Language Olx Clone Script 2.0.6 has XSS via the Leave Comment field. | ||
| CVE-2018-5550 | Med | 0.43 | 6.1 | 0.37 | Feb 8, 2018 | Versions of Epson AirPrint released prior to January 19, 2018 contain a reflective cross-site scripting (XSS) vulnerability, which can allow untrusted users on the network to hijack a session cookie or perform other reflected XSS attacks on a currently logged-on user. | ||
| CVE-2017-5124 | Med | 0.43 | 6.1 | 0.05 | Feb 7, 2018 | Incorrect application of sandboxing in Blink in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted MHTML page. |
- risk 0.43cvss 6.1epss 0.06
An issue was discovered in the wunderfarm WF Cookie Consent plugin 1.1.3 for WordPress. A persistent cross-site scripting vulnerability has been identified in the web interface of the plugin that allows the execution of arbitrary HTML/script code to be executed in a victim's web…
- risk 0.43cvss 6.1epss 0.02
A vulnerability was discovered in WUZHI CMS 4.1.0. There is persistent XSS that allows remote attackers to inject arbitrary web script or HTML via the tag[pinyin] parameter to the /index.php?m=tags&f=index&v=add URI.
- risk 0.43cvss 6.1epss 0.04
The jDownloads extension before 3.2.59 for Joomla! has XSS.
- risk 0.43cvss 6.1epss 0.02
Coship RT3052 4.0.0.48 devices allow XSS via a crafted SSID field on the "Wireless Setting - Basic" screen.
- risk 0.43cvss 6.1epss 0.02
PHP Scripts Mall Match Clone Script 1.0.4 has XSS via the search field to searchbyid.php (aka the "View Search By Id" screen).
- risk 0.43cvss 6.1epss 0.04
The Iptanus WordPress File Upload plugin before 4.3.4 for WordPress mishandles Settings attributes, leading to XSS.
- risk 0.43cvss 6.1epss 0.02
proberv.php in Yahei-PHP Proberv 0.4.7 has XSS via the funName parameter.
- risk 0.43cvss 6.1epss 0.03
iScripts SonicBB 1.0 has Reflected Cross-Site Scripting via the query parameter to search.php.
- risk 0.43cvss 6.1epss 0.02
Cross-site scripting (XSS) vulnerability in admin/template/js/uploadify/uploadify.swf in GetSimple CMS 3.3.13 allows remote attackers to inject arbitrary web script or HTML, as demonstrated by the movieName parameter.
- risk 0.43cvss 6.1epss 0.02
Cross-site scripting (XSS) vulnerability in Twonky Server 7.0.11 through 8.5 allows remote attackers to inject arbitrary web script or HTML via the friendlyname parameter to rpc/set_all.
- risk 0.43cvss 6.1epss 0.03
Cross-site scripting (XSS) vulnerability in installer/build/view.step4.php of the SnapCreek Duplicator plugin 1.2.32 for WordPress allows remote attackers to inject arbitrary JavaScript or HTML via the json parameter.
- risk 0.43cvss 6.1epss 0.03
Cross-site scripting (XSS) vulnerability in SecurEnvoy SecurMail before 9.2.501 allows remote attackers to inject arbitrary web script or HTML via an HTML-formatted e-mail message.
- risk 0.43cvss 6.1epss 0.04
Cross-site scripting (XSS) vulnerability in SecurEnvoy SecurMail before 9.2.501 allows remote attackers to inject arbitrary web script or HTML via the mailboxid parameter to secmail/getmessage.exe.
- risk 0.43cvss 6.1epss 0.08
In YzmCMS 3.6, index.php has XSS via the a, c, or m parameter.
- risk 0.43cvss 6.1epss 0.03
A /shell?cmd= XSS issue exists in the HTTPD component of NAT32 v2.2 Build 22284 devices that can be exploited for Remote Code Execution in conjunction with CSRF.
- risk 0.43cvss 6.1epss 0.02
Reflected XSS in Kubik-Rubik SIGE (aka Simple Image Gallery Extended) before 3.3.0 allows attackers to execute JavaScript in a victim's browser by having them visit a plugins/content/sige/plugin_sige/print.php link with a crafted img, name, or caption parameter.
- risk 0.43cvss 6.1epss 0.08
A Remote Code Execution vulnerability in HPE OpenCall Media Platform (OCMP) was found. The vulnerability impacts OCMP versions prior to 3.4.2 RP201 (for OCMP 3.x), all versions prior to 4.4.7 RP702 (for OCMP 4.x).
- risk 0.43cvss 6.1epss 0.03
PHP Scripts Mall Multi Language Olx Clone Script 2.0.6 has XSS via the Leave Comment field.
- risk 0.43cvss 6.1epss 0.37
Versions of Epson AirPrint released prior to January 19, 2018 contain a reflective cross-site scripting (XSS) vulnerability, which can allow untrusted users on the network to hijack a session cookie or perform other reflected XSS attacks on a currently logged-on user.
- risk 0.43cvss 6.1epss 0.05
Incorrect application of sandboxing in Blink in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted MHTML page.