VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (46,986)

page 315 of 2,350
  • CVE-2025-36436MedFeb 2, 2026
    risk 0.42cvss 6.4epss 0.00

    IBM Cloud Pak for Business Automation 25.0.0 through 25.0.0 Interim Fix 002, 24.0.1 through 24.0.1 Interim Fix 005, and 24.0.0 through 24.0.0 Interim Fix 007  is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary…

  • CVE-2023-54343MedFeb 1, 2026
    risk 0.42cvss 6.4epss 0.00

    QWE DL 2.0.1 mobile web application contains a persistent input validation vulnerability allowing remote attackers to inject malicious script code through path parameter manipulation. Attackers can exploit the vulnerability to execute persistent cross-site scripting attacks,…

  • CVE-2022-50952MedFeb 1, 2026
    risk 0.42cvss 6.4epss 0.00

    Banco Guayaquil 8.0.0 mobile iOS application contains a persistent cross-site scripting vulnerability in the TextBox Name Profile input. Attackers can inject malicious script code through a POST request that executes on application review without user interaction.

  • CVE-2022-50951MedFeb 1, 2026
    risk 0.42cvss 6.4epss 0.00

    WiFi File Transfer 1.0.8 contains a persistent cross-site scripting vulnerability that allows remote attackers to inject malicious script codes through file and folder names. Attackers can exploit the web server's input validation weakness to execute arbitrary JavaScript when…

  • CVE-2022-50941MedFeb 1, 2026
    risk 0.42cvss 6.4epss 0.00

    BootCommerce 3.2.1 contains persistent input validation vulnerabilities that allow remote attackers to inject malicious script code through guest order checkout input fields. Attackers can exploit unvalidated input parameters to execute arbitrary scripts, potentially leading to…

  • CVE-2022-50940MedFeb 1, 2026
    risk 0.42cvss 6.4epss 0.00

    Knap Advanced PHP Login 3.1.3 contains a persistent cross-site scripting vulnerability that allows remote attackers to inject malicious script code in the name parameter. Attackers can exploit the vulnerability to execute arbitrary scripts in users and activity log backend…

  • CVE-2022-50797MedFeb 1, 2026
    risk 0.42cvss 6.4epss 0.00

    Stripe Green Downloads Wordpress Plugin 2.03 contains a persistent cross-site scripting vulnerability allowing remote attackers to inject malicious scripts in button label fields. Attackers can exploit input parameters to execute arbitrary scripts, potentially leading to session…

  • CVE-2021-47919MedFeb 1, 2026
    risk 0.42cvss 6.4epss 0.00

    Simple CMS 2.1 contains a non-persistent cross-site scripting vulnerability in the preview.php file's id parameter. Attackers can inject malicious script code through a GET request to execute arbitrary scripts and potentially hijack user sessions or perform phishing attacks.

  • CVE-2021-47917MedFeb 1, 2026
    risk 0.42cvss 6.4epss 0.00

    Simple CMS 2.1 contains a persistent cross-site scripting vulnerability in user input parameters that allows remote attackers to inject malicious script code. Attackers can exploit the newUser and editUser modules to inject persistent scripts that execute on user list preview,…

  • CVE-2021-47914MedFeb 1, 2026
    risk 0.42cvss 6.4epss 0.00

    PHP Melody version 3.0 contains a persistent cross-site scripting vulnerability in the edit-video.php submitted parameter that allows remote attackers to inject malicious script code. Attackers can exploit this vulnerability to execute arbitrary JavaScript, potentially leading…

  • CVE-2021-47913MedFeb 1, 2026
    risk 0.42cvss 6.4epss 0.00

    PHP Melody 3.0 contains a persistent cross-site scripting vulnerability in the video editor that allows privileged users to inject malicious scripts. Attackers can exploit the WYSIWYG editor to execute persistent scripts, potentially leading to session hijacking and application…

  • CVE-2021-47912MedFeb 1, 2026
    risk 0.42cvss 6.4epss 0.00

    PHP Melody version 3.0 contains multiple non-persistent cross-site scripting vulnerabilities in categories, import, and user import files. Attackers can inject malicious scripts through unvalidated parameters to execute client-side attacks and potentially hijack user sessions.

  • CVE-2021-47908MedFeb 1, 2026
    risk 0.42cvss 6.4epss 0.00

    Ultimate POS 4.4 contains a persistent cross-site scripting vulnerability in the product name parameter that allows remote attackers to inject malicious scripts. Attackers can exploit the vulnerability through product add or edit functions to execute arbitrary JavaScript and…

  • CVE-2021-47885MedFeb 1, 2026
    risk 0.42cvss 6.4epss 0.00

    Multiple payment terminal versions contain non-persistent cross-site scripting vulnerabilities in billing and payment information input fields. Attackers can inject malicious script code through vulnerable parameters to manipulate client-side requests and potentially execute…

  • CVE-2021-47856MedFeb 1, 2026
    risk 0.42cvss 6.4epss 0.00

    Easy Cart Shopping Cart 2021 contains a non-persistent cross-site scripting vulnerability in the search module's keyword parameter. Remote attackers can inject malicious script code through the search input to compromise user sessions and manipulate application content.

  • CVE-2020-37022MedJan 30, 2026
    risk 0.42cvss 6.4epss 0.00

    OpenZ ERP 3.6.60 contains a persistent cross-site scripting vulnerability in the Employee module's name and description parameters. Attackers can inject malicious scripts through POST requests to , enabling session hijacking and manipulation of application modules.

  • CVE-2020-37019MedJan 30, 2026
    risk 0.42cvss 6.4epss 0.00

    Orchard Core RC1 contains a persistent cross-site scripting vulnerability that allows remote attackers to inject malicious scripts through blog post creation. Attackers can create blog posts with embedded JavaScript in the MarkdownBodyPart.Source parameter to execute arbitrary…

  • CVE-2020-37014MedJan 30, 2026
    risk 0.42cvss 6.4epss 0.00

    Tryton 5.4 contains a persistent cross-site scripting vulnerability in the user profile name input that allows remote attackers to inject malicious scripts. Attackers can exploit the vulnerability by inserting script payloads in the name field, which execute in the frontend and…

  • CVE-2020-37003MedJan 30, 2026
    risk 0.42cvss 6.4epss 0.00

    Sellacious eCommerce 4.6 contains a persistent cross-site scripting vulnerability in the Manage Your Addresses module that allows attackers to inject malicious scripts. Attackers can exploit multiple address input fields like full name, company, and address to execute persistent…

  • CVE-2020-36998MedJan 30, 2026
    risk 0.42cvss 6.4epss 0.00

    Forma.lms The E-Learning Suite 2.3.0.2 contains a persistent cross-site scripting vulnerability in multiple course and profile parameters. Attackers can inject malicious scripts in course code, name, description fields, and email parameter to execute arbitrary JavaScript without…