VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (46,607)

page 30 of 2,331
  • CVE-2025-49407HigAug 28, 2025
    risk 0.57cvss 8.8epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in favethemes Houzez allows Reflected XSS. This issue affects Houzez: from n/a through 4.1.1.

  • CVE-2025-55422HigAug 27, 2025
    risk 0.57cvss 8.8epss 0.00

    In FoxCMS 1.2.6, there is a reflected Cross Site Scripting (XSS) vulnerability in /index.php/plus.

  • CVE-2025-30036HigAug 27, 2025
    risk 0.57cvss epss 0.00

    Stored XSS vulnerability exists in the "Oddział" (Ward) module, in the death diagnosis description field, and allows the execution of arbitrary JavaScript code. This can lead to session hijacking of other users and potentially to privilege escalation up to full administrative…

  • CVE-2025-55409HigAug 25, 2025
    risk 0.57cvss 8.8epss 0.00

    FoxCMS 1.2.6, there is a Cross Site Scripting vulnerability in /index.php/article. This allows attackers to execute arbitrary code.

  • CVE-2025-55573HigAug 22, 2025
    risk 0.57cvss 8.8epss 0.00

    QuantumNous new-api v.0.8.5.2 is vulnerable to Cross Site Scripting (XSS).

  • CVE-2025-55420HigAug 21, 2025
    risk 0.57cvss 8.8epss 0.00

    A Reflected Cross Site Scripting (XSS) vulnerability was found in /index.php in FoxCMS v1.2.6. When a crafted script is sent via a GET request, it is reflected unsanitized into the HTML response. This permits execution of arbitrary JavaScript code when a logged-in user submits…

  • CVE-2025-51991HigAug 20, 2025
    risk 0.57cvss 8.8epss 0.04

    XWiki through version 17.3.0 is vulnerable to Server-Side Template Injection (SSTI) in the Administration interface, specifically within the HTTP Meta Info field of the Global Preferences Presentation section. An authenticated administrator can inject crafted Apache Velocity…

  • CVE-2025-57731HigAug 20, 2025
    risk 0.57cvss 8.7epss 0.00

    In JetBrains YouTrack before 2025.2.92387 stored XSS was possible via Mermaid diagram content

  • CVE-2025-7739HigAug 13, 2025
    risk 0.57cvss 8.7epss 0.00

    An issue has been discovered in GitLab CE/EE affecting all versions from 18.2 before 18.2.2 that, under certain conditions, could have allowed authenticated users to achieve stored cross-site scripting by injecting malicious HTML content in scoped label descriptions.

  • CVE-2025-7734HigAug 13, 2025
    risk 0.57cvss 8.7epss 0.00

    An issue has been discovered in GitLab CE/EE affecting all versions from 14.2 before 18.0.6, 18.1 before 18.1.4 and 18.2 before 18.2.2 that, under certain conditions, could have allowed a successful attacker to execute actions on behalf of users by injecting malicious content.

  • CVE-2025-6186HigAug 13, 2025
    risk 0.57cvss 8.7epss 0.00

    An issue has been discovered in GitLab CE/EE affecting all versions from 18.1 before 18.1.4, and 18.2 before 18.2.2 that could have allowed authenticated users to achieve account takeover by injecting malicious HTML into work item names.

  • CVE-2025-49557HigAug 12, 2025
    risk 0.57cvss 8.7epss 0.01

    Adobe Commerce versions 2.4.9-alpha1, 2.4.8-p1, 2.4.7-p6, 2.4.6-p11, 2.4.5-p13, 2.4.4-p14 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be exploited by a low-privileged attacker to inject malicious scripts into vulnerable form fields. A…

  • CVE-2020-9322HigAug 8, 2025
    risk 0.57cvss 8.8epss 0.00

    The /users endpoint in Statamic Core before 2.11.8 allows XSS to add an administrator user. This can be exploited via CSRF. Stored XSS can occur via a JavaScript payload in a username during account registration. Reflected XSS can occur via the /users PATH_INFO.

  • CVE-2025-51629HigAug 7, 2025
    risk 0.57cvss 8.8epss 0.00

    A cross-site scripting (XSS) vulnerability in the PdfViewer component of Agenzia Impresa Eccobook 2.81.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Temp parameter.

  • CVE-2025-50738CriJul 29, 2025
    risk 0.57cvss 9.8epss 0.02

    The Memos application, up to version v0.24.3, allows for the embedding of markdown images with arbitrary URLs. When a user views a memo containing such an image, their browser automatically fetches the image URL without explicit user consent or interaction beyond viewing the…

  • CVE-2025-46198HigJul 25, 2025
    risk 0.57cvss 8.8epss 0.01

    Cross Site Scripting vulnerability in grav v.1.7.48, v.1.7.47 and v.1.7.46 allows an attacker to execute arbitrary code via the onerror attribute of the img element

  • CVE-2025-52360HigJul 25, 2025
    risk 0.57cvss 8.8epss 0.00

    A Cross-Site Scripting (XSS) vulnerability exists in the OPAC search feature of Koha Library Management System v24.05. Unsanitized input entered in the search field is reflected in the search history interface, leading to the execution of arbitrary JavaScript in the browser…

  • CVE-2025-4700HigJul 23, 2025
    risk 0.57cvss 8.7epss 0.00

    An issue has been discovered in GitLab CE/EE affecting all versions from 15.10 before 18.0.5, 18.1 before 18.1.3, and 18.2 before 18.2.1 that, under specific circumstances, could have potentially allowed a successful attacker to trigger unintended content rendering leading to…

  • CVE-2025-53890CriJul 15, 2025
    risk 0.57cvss 9.8epss 0.01

    pyload is an open-source Download Manager written in pure Python. An unsafe JavaScript evaluation vulnerability in pyLoad’s CAPTCHA processing code allows unauthenticated remote attackers to execute arbitrary code in the client browser and potentially the backend server.…

  • CVE-2025-6948HigJul 10, 2025
    risk 0.57cvss 8.7epss 0.01

    An issue has been discovered in GitLab CE/EE affecting all versions from 17.11 before 17.11.6, 18.0 before 18.0.4, and 18.1 before 18.1.2 that, under certain conditions, could have allowed a successful attacker to execute actions on behalf of users by injecting malicious content.