VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (46,817)

page 279 of 2,341
  • CVE-2018-10371MedMay 1, 2018
    risk 0.43cvss 6.1epss 0.06

    An issue was discovered in the wunderfarm WF Cookie Consent plugin 1.1.3 for WordPress. A persistent cross-site scripting vulnerability has been identified in the web interface of the plugin that allows the execution of arbitrary HTML/script code to be executed in a victim's web…

  • CVE-2018-10311MedApr 24, 2018
    risk 0.43cvss 6.1epss 0.02

    A vulnerability was discovered in WUZHI CMS 4.1.0. There is persistent XSS that allows remote attackers to inject arbitrary web script or HTML via the tag[pinyin] parameter to the /index.php?m=tags&f=index&v=add URI.

  • CVE-2018-10068MedApr 12, 2018
    risk 0.43cvss 6.1epss 0.04

    The jDownloads extension before 3.2.59 for Joomla! has XSS.

  • CVE-2018-8772MedApr 10, 2018
    risk 0.43cvss 6.1epss 0.02

    Coship RT3052 4.0.0.48 devices allow XSS via a crafted SSID field on the "Wireless Setting - Basic" screen.

  • CVE-2018-9857MedApr 9, 2018
    risk 0.43cvss 6.1epss 0.02

    PHP Scripts Mall Match Clone Script 1.0.4 has XSS via the search field to searchbyid.php (aka the "View Search By Id" screen).

  • CVE-2018-9844MedApr 7, 2018
    risk 0.43cvss 6.1epss 0.04

    The Iptanus WordPress File Upload plugin before 4.3.4 for WordPress mishandles Settings attributes, leading to XSS.

  • CVE-2018-9238MedApr 4, 2018
    risk 0.43cvss 6.1epss 0.02

    proberv.php in Yahei-PHP Proberv 0.4.7 has XSS via the funName parameter.

  • CVE-2018-9235MedApr 4, 2018
    risk 0.43cvss 6.1epss 0.03

    iScripts SonicBB 1.0 has Reflected Cross-Site Scripting via the query parameter to search.php.

  • CVE-2018-9173MedApr 2, 2018
    risk 0.43cvss 6.1epss 0.02

    Cross-site scripting (XSS) vulnerability in admin/template/js/uploadify/uploadify.swf in GetSimple CMS 3.3.13 allows remote attackers to inject arbitrary web script or HTML, as demonstrated by the movieName parameter.

  • CVE-2018-7203MedMar 30, 2018
    risk 0.43cvss 6.1epss 0.02

    Cross-site scripting (XSS) vulnerability in Twonky Server 7.0.11 through 8.5 allows remote attackers to inject arbitrary web script or HTML via the friendlyname parameter to rpc/set_all.

  • CVE-2018-7543MedMar 26, 2018
    risk 0.43cvss 6.1epss 0.03

    Cross-site scripting (XSS) vulnerability in installer/build/view.step4.php of the SnapCreek Duplicator plugin 1.2.32 for WordPress allows remote attackers to inject arbitrary JavaScript or HTML via the json parameter.

  • CVE-2018-7707MedMar 15, 2018
    risk 0.43cvss 6.1epss 0.03

    Cross-site scripting (XSS) vulnerability in SecurEnvoy SecurMail before 9.2.501 allows remote attackers to inject arbitrary web script or HTML via an HTML-formatted e-mail message.

  • CVE-2018-7703MedMar 15, 2018
    risk 0.43cvss 6.1epss 0.04

    Cross-site scripting (XSS) vulnerability in SecurEnvoy SecurMail before 9.2.501 allows remote attackers to inject arbitrary web script or HTML via the mailboxid parameter to secmail/getmessage.exe.

  • CVE-2018-7653MedMar 4, 2018
    risk 0.43cvss 6.1epss 0.08

    In YzmCMS 3.6, index.php has XSS via the a, c, or m parameter.

  • CVE-2018-6940MedFeb 20, 2018
    risk 0.43cvss 6.1epss 0.03

    A /shell?cmd= XSS issue exists in the HTTPD component of NAT32 v2.2 Build 22284 devices that can be exploited for Remote Code Execution in conjunction with CSRF.

  • CVE-2017-16356MedFeb 20, 2018
    risk 0.43cvss 6.1epss 0.02

    Reflected XSS in Kubik-Rubik SIGE (aka Simple Image Gallery Extended) before 3.3.0 allows attackers to execute JavaScript in a victim's browser by having them visit a plugins/content/sige/plugin_sige/print.php link with a crafted img, name, or caption parameter.

  • CVE-2017-5798MedFeb 15, 2018
    risk 0.43cvss 6.1epss 0.08

    A Remote Code Execution vulnerability in HPE OpenCall Media Platform (OCMP) was found. The vulnerability impacts OCMP versions prior to 3.4.2 RP201 (for OCMP 3.x), all versions prior to 4.4.7 RP702 (for OCMP 4.x).

  • CVE-2018-6845MedFeb 12, 2018
    risk 0.43cvss 6.1epss 0.03

    PHP Scripts Mall Multi Language Olx Clone Script 2.0.6 has XSS via the Leave Comment field.

  • CVE-2018-5550MedFeb 8, 2018
    risk 0.43cvss 6.1epss 0.37

    Versions of Epson AirPrint released prior to January 19, 2018 contain a reflective cross-site scripting (XSS) vulnerability, which can allow untrusted users on the network to hijack a session cookie or perform other reflected XSS attacks on a currently logged-on user.

  • CVE-2017-5124MedFeb 7, 2018
    risk 0.43cvss 6.1epss 0.05

    Incorrect application of sandboxing in Blink in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted MHTML page.