VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (46,543)

page 3 of 2,328
  • CVE-2025-53599CriJul 4, 2025
    risk 0.64cvss 9.8epss 0.00

    Whale browser for iOS before 3.9.1.4206 allow an attacker to execute malicious scripts in the browser via a crafted javascript scheme.

  • CVE-2025-24297CriApr 15, 2025
    risk 0.64cvss 9.8epss 0.00

    Due to lack of server-side input validation, attackers can inject malicious JavaScript code into users personal spaces of the web portal.

  • CVE-2024-57686CriJan 10, 2025
    risk 0.64cvss 9.8epss 0.02

    A Cross Site Scripting (XSS) vulnerability was found in /landrecordsys/admin/contactus.php in PHPGurukul Land Record System v1.0, which allows remote attackers to execute arbitrary code via the "pagetitle" parameter.

  • CVE-2024-53442CriDec 5, 2024
    risk 0.64cvss 9.8epss 0.01

    whapa v1.59 is vulnerable to Command Injection via a crafted filename to the HTML reports component.

  • CVE-2024-52770CriNov 20, 2024
    risk 0.64cvss 9.8epss 0.01

    An arbitrary file upload vulnerability in the component /admin/file_manage_control of DedeBIZ v6.3.0 allows attackers to execute arbitrary code via uploading a crafted file.

  • CVE-2024-51053CriNov 18, 2024
    risk 0.64cvss 9.8epss 0.01

    An arbitrary file upload vulnerability in the component /main/fileupload.php of AVSCMS v8.2.0 allows attackers to execute arbitrary code via uploading a crafted file.

  • CVE-2024-51135CriNov 11, 2024
    risk 0.64cvss 9.8epss 0.01

    An XML External Entity (XXE) vulnerability in the component DocumentBuilderFactory of powertac-server v1.9.0 allows attackers to access sensitive information or execute arbitrary code via supplying a crafted request containing malicious XML entities.

  • CVE-2024-42515CriOct 31, 2024
    risk 0.64cvss 9.9epss 0.00

    Glossarizer through 1.5.2 improperly tries to convert text into HTML. Even though the application itself escapes special characters (e.g., <>), the underlying library converts these encoded characters into legitimate HTML, thereby possibly causing stored XSS. Attackers can…

  • CVE-2024-44081CriOct 29, 2024
    risk 0.64cvss 9.8epss 0.01

    In Jitsi Meet before 2.0.9779, the functionality to share a video file was implemented in an insecure way, resulting in clients loading videos from an arbitrary URL if a message from another participant contains a URL encoded in the expected format.

  • CVE-2024-8696CriSep 12, 2024
    risk 0.64cvss 9.8epss 0.01

    A remote code execution (RCE) vulnerability via crafted extension publisher-url/additional-urls could be abused by a malicious extension in Docker Desktop before 4.34.2.

  • CVE-2024-8695CriSep 12, 2024
    risk 0.64cvss 9.8epss 0.01

    A remote code execution (RCE) vulnerability via crafted extension description/changelog could be abused by a malicious extension in Docker Desktop before 4.34.2.

  • CVE-2024-45265CriAug 26, 2024
    risk 0.64cvss 9.8epss 0.01

    A SQL injection vulnerability in the poll component in SkySystem Arfa-CMS before 5.1.3124 allows remote attackers to execute arbitrary SQL commands via the psid parameter.

  • CVE-2024-41476CriAug 12, 2024
    risk 0.64cvss 9.8epss 0.01

    AMTT Hotel Broadband Operation System (HiBOS) V3.0.3.151204 and before is vulnerable to SQL Injection via /manager/card/card_detail.php.

  • CVE-2024-40482CriAug 12, 2024
    risk 0.64cvss 9.8epss 0.01

    An Unrestricted file upload vulnerability was found in "/Membership/edit_member.php" of Kashipara Live Membership System v1.0, which allows attackers to execute arbitrary code via uploading a crafted PHP file.

  • CVE-2024-24594CriFeb 6, 2024
    risk 0.64cvss 9.9epss 0.01

    A cross-site scripting (XSS) vulnerability in all versions of the web server component of Allegro AI’s ClearML platform allows a remote attacker to execute a JavaScript payload when a user views the Debug Samples tab in the web UI.

  • CVE-2023-45138CriOct 12, 2023
    risk 0.64cvss 10.0epss 0.71

    Change Request is an pplication allowing users to request changes on a wiki without publishing the changes directly. Starting in version 0.11 and prior to version 1.9.2, it's possible for a user without any specific right to perform script injection and remote code execution…

  • CVE-2023-2442HigJun 7, 2023
    risk 0.64cvss 8.7epss 0.96

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. A specially crafted merge request could lead to a stored XSS on the client side which allows attackers to perform arbitrary…

  • CVE-2023-29205CriApr 15, 2023
    risk 0.64cvss 9.9epss 0.01

    XWiki Commons are technical libraries common to several other top level XWiki projects. The HTML macro does not systematically perform a proper neutralization of script-related html tags. As a result, any user able to use the html macro in XWiki, is able to introduce an XSS…

  • CVE-2023-26750CriApr 4, 2023
    risk 0.64cvss 9.8epss 0.02

    SQL injection vulnerability found in Yii Framework Yii 2 Framework before v.2.0.47 allows the a remote attacker to execute arbitrary code via the runAction function. NOTE: the software maintainer's position is that the vulnerability is in third-party code, not in the framework.

  • CVE-2023-0050HigMar 9, 2023
    risk 0.64cvss 8.7epss 0.92

    An issue has been discovered in GitLab affecting all versions starting from 13.7 before 15.7.8, all versions starting from 15.8 before 15.8.4, all versions starting from 15.9 before 15.9.2. A specially crafted Kroki diagram could lead to a stored XSS on the client side which…