VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (46,543)

page 4 of 2,328
  • CVE-2022-40434CriDec 19, 2022
    risk 0.64cvss 9.8epss 0.01

    Softr v2.0 was discovered to be vulnerable to HTML injection via the Name field of the Account page.

  • CVE-2022-41391CriOct 13, 2022
    risk 0.64cvss 9.8epss 0.01

    OcoMon v4.0 was discovered to contain a SQL injection vulnerability via the cod parameter at showImg.php.

  • CVE-2022-32533CriJul 6, 2022
    risk 0.64cvss 9.8epss 0.04

    Apache Jetspeed-2 does not sufficiently filter untrusted user input by default leading to a number of issues including XSS, CSRF, XXE, and SSRF. Setting the configuration option "xss.filter.post = true" may mitigate these issues. NOTE: Apache Jetspeed is a dormant project of…

  • CVE-2022-32269CriJun 3, 2022
    risk 0.64cvss 9.8epss 0.03

    In Real Player 20.0.8.310, the G2 Control allows injection of unsafe javascript: URIs in local HTTP error pages (displayed by Internet Explorer core). This leads to arbitrary code execution.

  • CVE-2022-26255CriMar 28, 2022
    risk 0.64cvss 9.8epss 0.02

    Clash for Windows v0.19.8 was discovered to allow arbitrary code execution via a crafted payload injected into the Proxies name column.

  • CVE-2022-0748CriMar 17, 2022
    risk 0.64cvss 9.8epss 0.02

    The package post-loader from 0.0.0 are vulnerable to Arbitrary Code Execution which uses a markdown parser in an unsafe way so that any javascript code inside the markdown input files gets evaluated and executed.

  • CVE-2021-42940CriFeb 11, 2022
    risk 0.64cvss 9.9epss 0.01

    A Cross Site Scripting (XSS) vulnerability exists in Projeqtor 9.3.1 via /projeqtor/tool/saveAttachment.php, which allows an attacker to upload a SVG file containing malicious JavaScript code.

  • CVE-2021-43439CriDec 20, 2021
    risk 0.64cvss 9.8epss 0.03

    RCE in Add Review Function in iResturant 1.0 Allows remote attacker to execute commands remotely

  • CVE-2020-3580MedKEVOct 21, 2020
    risk 0.64cvss 6.1epss 0.86

    Multiple vulnerabilities in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the web…

  • CVE-2019-19212CriMar 16, 2020
    risk 0.64cvss 9.8epss 0.04

    Dolibarr ERP/CRM 3.0 through 10.0.3 allows XSS via the qty parameter to product/fournisseurs.php (product price screen).

  • CVE-2019-0219CriJan 14, 2020
    risk 0.64cvss 9.8epss 0.08

    A website running in the InAppBrowser webview on Android could execute arbitrary JavaScript in the main application's webview using a specially crafted gap-iab: URI.

  • CVE-2019-13478CriJul 9, 2019
    risk 0.64cvss 9.8epss 0.03

    The Yoast SEO plugin before 11.6-RC5 for WordPress does not properly restrict unfiltered HTML in term descriptions.

  • CVE-2019-3926CriApr 30, 2019
    risk 0.64cvss 9.8epss 0.07

    Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 are vulnerable to command injection via SNMP OID iso.3.6.1.4.1.3212.100.3.2.14.1. A remote, unauthenticated attacker can use this vulnerability to execute operating system commands as root.

  • CVE-2019-3925CriApr 30, 2019
    risk 0.64cvss 9.8epss 0.07

    Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 are vulnerable to command injection via SNMP OID iso.3.6.1.4.1.3212.100.3.2.9.3. A remote, unauthenticated attacker can use this vulnerability to execute operating system commands as root.

  • CVE-2017-17836CriJan 23, 2019
    risk 0.64cvss 9.8epss 0.03

    In Apache Airflow 1.8.2 and earlier, an experimental Airflow feature displayed authenticated cookies, as well as passwords to databases used by Airflow. An attacker who has limited access to airflow, whether it be via XSS or by leaving a machine unlocked can exfiltrate all…

  • CVE-2018-19222CriNov 12, 2018
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in LAOBANCMS 2.0. It allows a /install/mysql_hy.php?riqi=0&i=0 attack to reset the admin password, even if install.txt exists.

  • CVE-2018-9079CriSep 28, 2018
    risk 0.64cvss 9.8epss 0.01

    For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, adversaries can craft URLs to modify the Document Object Model (DOM) of the page. In addition, adversaries can inject HTML script tags and HTML tags with JavaScript handlers to execute arbitrary…

  • CVE-2018-10369CriAug 15, 2018
    risk 0.64cvss 9.8epss 0.02

    A Cross-site scripting (XSS) vulnerability was discovered on Intelbras Win 240 V1.1.0 devices. An attacker can change the Admin Password without a Login.

  • CVE-2018-0403CriJul 18, 2018
    risk 0.64cvss 9.8epss 0.02

    Multiple vulnerabilities in the web-based management interface of Cisco Unified Contact Center Express (Unified CCX) could allow an unauthenticated, remote attacker to retrieve a cleartext password. Cisco Bug IDs: CSCvg71040.

  • CVE-2017-8898CriMay 11, 2017
    risk 0.64cvss 9.8epss 0.02

    Invision Power Services (IPS) Community Suite 4.1.19.2 and earlier has stored XSS in the Announcements, allowing privilege escalation from an Invision Power Board moderator to an admin. An attack uses the announce_content parameter in an index.php?/modcp/announcements/&action=cre…