VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (46,607)

page 36 of 2,331
  • CVE-2024-2835HigMay 20, 2024
    risk 0.57cvss 8.7epss 0.00

    A Stored Cross-Site Scripting (XSS) vulnerability has been identified in OpenText ArcSight Enterprise Security Manager and ArcSight Platform. The vulnerability could be remotely exploited.

  • CVE-2024-34058HigMay 17, 2024
    risk 0.57cvss 8.8epss 0.01

    The WebTop package for NethServer 7 and 8 allows stored XSS (for example, via the Subject field if an e-mail message).

  • CVE-2023-42034HigMay 3, 2024
    risk 0.57cvss 8.8epss 0.01

    Visualware MyConnection Server doRTAAccessCTConfig Cross-Site Scripting Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of Visualware MyConnection Server. Minimal user interaction is required to…

  • CVE-2023-47626HigApr 15, 2024
    risk 0.57cvss 8.8epss 0.00

    iTop is an IT service management platform. When displaying/editing the user's personal tokens, XSS attacks are possible. This vulnerability is fixed in 3.1.1.

  • CVE-2024-2279HigApr 12, 2024
    risk 0.57cvss 8.7epss 0.01

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.7 to 16.8.6 all versions starting from 16.9 before 16.9.4, all versions starting from 16.10 before 16.10.2. Using the autocomplete for issues references feature a crafted payload may lead to a…

  • CVE-2024-2834HigApr 8, 2024
    risk 0.57cvss 8.7epss 0.01

    A Stored Cross-Site Scripting (XSS) vulnerability has been identified in OpenText ArcSight Management Center and ArcSight Platform. The vulnerability could be remotely exploited.

  • CVE-2024-29890HigMar 29, 2024
    risk 0.57cvss 8.8epss 0.01

    DataLens is a business intelligence and data visualization system. A specifically crafted request allowed the creation of a special chart type with the ability to pass custom javascript code that would later be executed in an unprotected sandbox on subsequent requests to that…

  • CVE-2023-6371HigMar 28, 2024
    risk 0.57cvss 8.7epss 0.00

    An issue has been discovered in GitLab CE/EE affecting all versions before 16.8.5, all versions starting from 16.9 before 16.9.3, all versions starting from 16.10 before 16.10.1. A wiki page with a crafted payload may lead to a Stored XSS, allowing attackers to perform arbitrary…

  • CVE-2024-28715HigMar 19, 2024
    risk 0.57cvss 8.8epss 0.01

    Cross Site Scripting vulnerability in DOraCMS v.2.18 and before allows a remote attacker to execute arbitrary code via the markdown0 function in the /app/public/apidoc/oas3/wrap-components/markdown.jsx endpoint.

  • CVE-2024-28671HigMar 13, 2024
    risk 0.57cvss 8.8epss 0.01

    DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /dede/stepselect_main.php.

  • CVE-2024-2247HigMar 13, 2024
    risk 0.57cvss 8.8epss 0.00

    JFrog Artifactory versions below 7.77.7, 7.82.1, are vulnerable to DOM-based cross-site scripting due to improper handling of the import override mechanism.

  • CVE-2024-28160HigMar 6, 2024
    risk 0.57cvss 8.8epss 0.01

    Jenkins iceScrum Plugin 1.1.6 and earlier does not sanitize iceScrum project URLs on build views, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to configure jobs.

  • CVE-2024-26483HigFeb 22, 2024
    risk 0.57cvss 8.8epss 0.01

    An arbitrary file upload vulnerability in the Profile Image module of Kirby CMS v4.1.0 allows attackers to execute arbitrary code via a crafted PDF file.

  • CVE-2023-5378HigJan 29, 2024
    risk 0.57cvss 8.8epss 0.01

    Improper Input Validation vulnerability in MegaBIP and already unsupported SmodBIP software allows for Stored XSS.This issue affects SmodBIP in all versions and MegaBIP in versions up to 4.36.2. MegaBIP 5.08 was tested and is not vulnerable. A precise range of vulnerable…

  • CVE-2024-21620HigJan 25, 2024
    risk 0.57cvss 8.8epss 0.01

    An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in J-Web of Juniper Networks Junos OS on SRX Series and EX Series allows an attacker to construct a URL that when visited by another user enables the attacker to execute…

  • CVE-2023-51063HigJan 13, 2024
    risk 0.57cvss 8.8epss 0.00

    QStar Archive Solutions Release RELEASE_3-0 Build 7 Patch 0 was discovered to contain a DOM Based Reflected Cross Site Scripting (XSS) vulnerability within the component qnme-ajax?method=tree_level.

  • CVE-2023-5880HigJan 3, 2024
    risk 0.57cvss 8.8epss 0.01

    When the Genie Company Aladdin Connect garage door opener (Retrofit-Kit Model ALDCM) is placed into configuration mode the web servers “Garage Door Control Module Setup” page is vulnerable to XSS via a broadcast SSID name containing malicious code with client side Java…

  • CVE-2023-44286HigDec 14, 2023
    risk 0.57cvss 8.8epss 0.01

    Dell PowerProtect DD , versions prior to 7.13.0.10, LTS 7.7.5.25, LTS 7.10.1.15, 6.2.1.110 contain a DOM-based Cross-Site Scripting vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to the injection of malicious HTML or…

  • CVE-2023-6790HigDec 13, 2023
    risk 0.57cvss 8.8epss 0.01

    A DOM-Based cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS software enables a remote attacker to execute a JavaScript payload in the context of an administrator’s browser when they view a specifically crafted link to the PAN-OS web interface.

  • CVE-2023-47322HigDec 13, 2023
    risk 0.57cvss 8.8epss 0.00

    The "userModify" feature of Silverpeas Core 6.3.1 is vulnerable to Cross Site Request Forgery (CSRF) leading to privilege escalation. If an administrator goes to a malicious URL while being authenticated to the Silverpeas application, the CSRF with execute making the attacker an…