CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Description
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85
CVEs mapped to this weakness (46,543)
page 3 of 2,328| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-53599 | Cri | 0.64 | 9.8 | 0.00 | Jul 4, 2025 | Whale browser for iOS before 3.9.1.4206 allow an attacker to execute malicious scripts in the browser via a crafted javascript scheme. | ||
| CVE-2025-24297 | Cri | 0.64 | 9.8 | 0.00 | Apr 15, 2025 | Due to lack of server-side input validation, attackers can inject malicious JavaScript code into users personal spaces of the web portal. | ||
| CVE-2024-57686 | Cri | 0.64 | 9.8 | 0.02 | Jan 10, 2025 | A Cross Site Scripting (XSS) vulnerability was found in /landrecordsys/admin/contactus.php in PHPGurukul Land Record System v1.0, which allows remote attackers to execute arbitrary code via the "pagetitle" parameter. | ||
| CVE-2024-53442 | Cri | 0.64 | 9.8 | 0.01 | Dec 5, 2024 | whapa v1.59 is vulnerable to Command Injection via a crafted filename to the HTML reports component. | ||
| CVE-2024-52770 | Cri | 0.64 | 9.8 | 0.01 | Nov 20, 2024 | An arbitrary file upload vulnerability in the component /admin/file_manage_control of DedeBIZ v6.3.0 allows attackers to execute arbitrary code via uploading a crafted file. | ||
| CVE-2024-51053 | Cri | 0.64 | 9.8 | 0.01 | Nov 18, 2024 | An arbitrary file upload vulnerability in the component /main/fileupload.php of AVSCMS v8.2.0 allows attackers to execute arbitrary code via uploading a crafted file. | ||
| CVE-2024-51135 | Cri | 0.64 | 9.8 | 0.01 | Nov 11, 2024 | An XML External Entity (XXE) vulnerability in the component DocumentBuilderFactory of powertac-server v1.9.0 allows attackers to access sensitive information or execute arbitrary code via supplying a crafted request containing malicious XML entities. | ||
| CVE-2024-42515 | Cri | 0.64 | 9.9 | 0.00 | Oct 31, 2024 | Glossarizer through 1.5.2 improperly tries to convert text into HTML. Even though the application itself escapes special characters (e.g., <>), the underlying library converts these encoded characters into legitimate HTML, thereby possibly causing stored XSS. Attackers can… | ||
| CVE-2024-44081 | Cri | 0.64 | 9.8 | 0.01 | Oct 29, 2024 | In Jitsi Meet before 2.0.9779, the functionality to share a video file was implemented in an insecure way, resulting in clients loading videos from an arbitrary URL if a message from another participant contains a URL encoded in the expected format. | ||
| CVE-2024-8696 | Cri | 0.64 | 9.8 | 0.01 | Sep 12, 2024 | A remote code execution (RCE) vulnerability via crafted extension publisher-url/additional-urls could be abused by a malicious extension in Docker Desktop before 4.34.2. | ||
| CVE-2024-8695 | Cri | 0.64 | 9.8 | 0.01 | Sep 12, 2024 | A remote code execution (RCE) vulnerability via crafted extension description/changelog could be abused by a malicious extension in Docker Desktop before 4.34.2. | ||
| CVE-2024-45265 | Cri | 0.64 | 9.8 | 0.01 | Aug 26, 2024 | A SQL injection vulnerability in the poll component in SkySystem Arfa-CMS before 5.1.3124 allows remote attackers to execute arbitrary SQL commands via the psid parameter. | ||
| CVE-2024-41476 | Cri | 0.64 | 9.8 | 0.01 | Aug 12, 2024 | AMTT Hotel Broadband Operation System (HiBOS) V3.0.3.151204 and before is vulnerable to SQL Injection via /manager/card/card_detail.php. | ||
| CVE-2024-40482 | Cri | 0.64 | 9.8 | 0.01 | Aug 12, 2024 | An Unrestricted file upload vulnerability was found in "/Membership/edit_member.php" of Kashipara Live Membership System v1.0, which allows attackers to execute arbitrary code via uploading a crafted PHP file. | ||
| CVE-2024-24594 | Cri | 0.64 | 9.9 | 0.01 | Feb 6, 2024 | A cross-site scripting (XSS) vulnerability in all versions of the web server component of Allegro AI’s ClearML platform allows a remote attacker to execute a JavaScript payload when a user views the Debug Samples tab in the web UI. | ||
| CVE-2023-45138 | Cri | 0.64 | 10.0 | 0.71 | Oct 12, 2023 | Change Request is an pplication allowing users to request changes on a wiki without publishing the changes directly. Starting in version 0.11 and prior to version 1.9.2, it's possible for a user without any specific right to perform script injection and remote code execution… | ||
| CVE-2023-2442 | Hig | 0.64 | 8.7 | 0.96 | Jun 7, 2023 | An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. A specially crafted merge request could lead to a stored XSS on the client side which allows attackers to perform arbitrary… | ||
| CVE-2023-29205 | Cri | 0.64 | 9.9 | 0.01 | Apr 15, 2023 | XWiki Commons are technical libraries common to several other top level XWiki projects. The HTML macro does not systematically perform a proper neutralization of script-related html tags. As a result, any user able to use the html macro in XWiki, is able to introduce an XSS… | ||
| CVE-2023-26750 | Cri | 0.64 | 9.8 | 0.02 | Apr 4, 2023 | SQL injection vulnerability found in Yii Framework Yii 2 Framework before v.2.0.47 allows the a remote attacker to execute arbitrary code via the runAction function. NOTE: the software maintainer's position is that the vulnerability is in third-party code, not in the framework. | ||
| CVE-2023-0050 | Hig | 0.64 | 8.7 | 0.92 | Mar 9, 2023 | An issue has been discovered in GitLab affecting all versions starting from 13.7 before 15.7.8, all versions starting from 15.8 before 15.8.4, all versions starting from 15.9 before 15.9.2. A specially crafted Kroki diagram could lead to a stored XSS on the client side which… |
- risk 0.64cvss 9.8epss 0.00
Whale browser for iOS before 3.9.1.4206 allow an attacker to execute malicious scripts in the browser via a crafted javascript scheme.
- risk 0.64cvss 9.8epss 0.00
Due to lack of server-side input validation, attackers can inject malicious JavaScript code into users personal spaces of the web portal.
- risk 0.64cvss 9.8epss 0.02
A Cross Site Scripting (XSS) vulnerability was found in /landrecordsys/admin/contactus.php in PHPGurukul Land Record System v1.0, which allows remote attackers to execute arbitrary code via the "pagetitle" parameter.
- risk 0.64cvss 9.8epss 0.01
whapa v1.59 is vulnerable to Command Injection via a crafted filename to the HTML reports component.
- risk 0.64cvss 9.8epss 0.01
An arbitrary file upload vulnerability in the component /admin/file_manage_control of DedeBIZ v6.3.0 allows attackers to execute arbitrary code via uploading a crafted file.
- risk 0.64cvss 9.8epss 0.01
An arbitrary file upload vulnerability in the component /main/fileupload.php of AVSCMS v8.2.0 allows attackers to execute arbitrary code via uploading a crafted file.
- risk 0.64cvss 9.8epss 0.01
An XML External Entity (XXE) vulnerability in the component DocumentBuilderFactory of powertac-server v1.9.0 allows attackers to access sensitive information or execute arbitrary code via supplying a crafted request containing malicious XML entities.
- risk 0.64cvss 9.9epss 0.00
Glossarizer through 1.5.2 improperly tries to convert text into HTML. Even though the application itself escapes special characters (e.g., <>), the underlying library converts these encoded characters into legitimate HTML, thereby possibly causing stored XSS. Attackers can…
- risk 0.64cvss 9.8epss 0.01
In Jitsi Meet before 2.0.9779, the functionality to share a video file was implemented in an insecure way, resulting in clients loading videos from an arbitrary URL if a message from another participant contains a URL encoded in the expected format.
- risk 0.64cvss 9.8epss 0.01
A remote code execution (RCE) vulnerability via crafted extension publisher-url/additional-urls could be abused by a malicious extension in Docker Desktop before 4.34.2.
- risk 0.64cvss 9.8epss 0.01
A remote code execution (RCE) vulnerability via crafted extension description/changelog could be abused by a malicious extension in Docker Desktop before 4.34.2.
- risk 0.64cvss 9.8epss 0.01
A SQL injection vulnerability in the poll component in SkySystem Arfa-CMS before 5.1.3124 allows remote attackers to execute arbitrary SQL commands via the psid parameter.
- risk 0.64cvss 9.8epss 0.01
AMTT Hotel Broadband Operation System (HiBOS) V3.0.3.151204 and before is vulnerable to SQL Injection via /manager/card/card_detail.php.
- risk 0.64cvss 9.8epss 0.01
An Unrestricted file upload vulnerability was found in "/Membership/edit_member.php" of Kashipara Live Membership System v1.0, which allows attackers to execute arbitrary code via uploading a crafted PHP file.
- risk 0.64cvss 9.9epss 0.01
A cross-site scripting (XSS) vulnerability in all versions of the web server component of Allegro AI’s ClearML platform allows a remote attacker to execute a JavaScript payload when a user views the Debug Samples tab in the web UI.
- risk 0.64cvss 10.0epss 0.71
Change Request is an pplication allowing users to request changes on a wiki without publishing the changes directly. Starting in version 0.11 and prior to version 1.9.2, it's possible for a user without any specific right to perform script injection and remote code execution…
- risk 0.64cvss 8.7epss 0.96
An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. A specially crafted merge request could lead to a stored XSS on the client side which allows attackers to perform arbitrary…
- risk 0.64cvss 9.9epss 0.01
XWiki Commons are technical libraries common to several other top level XWiki projects. The HTML macro does not systematically perform a proper neutralization of script-related html tags. As a result, any user able to use the html macro in XWiki, is able to introduce an XSS…
- risk 0.64cvss 9.8epss 0.02
SQL injection vulnerability found in Yii Framework Yii 2 Framework before v.2.0.47 allows the a remote attacker to execute arbitrary code via the runAction function. NOTE: the software maintainer's position is that the vulnerability is in third-party code, not in the framework.
- risk 0.64cvss 8.7epss 0.92
An issue has been discovered in GitLab affecting all versions starting from 13.7 before 15.7.8, all versions starting from 15.8 before 15.8.4, all versions starting from 15.9 before 15.9.2. A specially crafted Kroki diagram could lead to a stored XSS on the client side which…