VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (46,607)

page 50 of 2,331
  • CVE-2025-62459HigNov 20, 2025
    risk 0.54cvss 8.3epss 0.00

    Microsoft Defender Portal Spoofing Vulnerability

  • CVE-2025-65095CriNov 19, 2025
    risk 0.54cvss epss 0.00

    Lookyloo is a web interface that allows users to capture a website page and then display a tree of domains that call each other. Prior to version 1.35.1, there is potential cross-site scripting on index and tree page. This issue has been patched in version 1.35.1.

  • CVE-2025-36548HigJul 24, 2025
    risk 0.54cvss 8.3epss 0.01

    A cross-site scripting (xss) vulnerability exists in the LoginWordPress loginForm cancelUri parameter functionality of WWBN AVideo 14.4 and dev master commit 8a8954ff. A specially crafted HTTP request can lead to arbitrary Javascript execution. An attacker can get a user to…

  • CVE-2025-24981CriFeb 6, 2025
    risk 0.54cvss 9.3epss 0.01

    MDC is a tool to take regular Markdown and write documents interacting deeply with a Vue component. In affected versions unsafe parsing logic of the URL from markdown can lead to arbitrary JavaScript code due to a bypass to the existing guards around the `javascript:` protocol…

  • CVE-2025-22598HigJan 10, 2025
    risk 0.54cvss 8.3epss 0.00

    WeGIA is a web manager for charitable institutions. A Stored Cross-Site Scripting (XSS) vulnerability was identified in the cadastrarSocio.php endpoint of the WeGIA application. This vulnerability allows attackers to inject malicious scripts into the local_recepcao parameter.…

  • CVE-2025-22597HigJan 10, 2025
    risk 0.54cvss 8.3epss 0.00

    WeGIA is a web manager for charitable institutions. A Stored Cross-Site Scripting (XSS) vulnerability was identified in the CobrancaController.php endpoint of the WeGIA application. This vulnerability allows attackers to inject malicious scripts into the local_recepcao…

  • CVE-2024-51757CriNov 6, 2024
    risk 0.54cvss epss 0.01

    happy-dom is a JavaScript implementation of a web browser without its graphical user interface. Versions of happy-dom prior to 15.10.2 may execute code on the host via a script tag. This would execute code in the user context of happy-dom. Users are advised to upgrade to version…

  • CVE-2017-20192HigOct 16, 2024
    risk 0.54cvss 8.3epss 0.01

    The Formidable Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters submitted during form entries like 'after_html' in versions before 2.05.03 due to insufficient input sanitization and output escaping. This makes it possible for…

  • CVE-2024-7654HigSep 3, 2024
    risk 0.54cvss 8.3epss 0.00

    An ActiveMQ Discovery service was reachable by default from an OpenEdge Management installation when an OEE/OEM auto-discovery feature was activated.  Unauthorized access to the discovery service's UDP port allowed content injection into parts of the OEM web interface making it…

  • CVE-2024-38869HigAug 23, 2024
    risk 0.54cvss 8.3epss 0.01

    Zohocorp ManageEngine Endpoint Central affected by Incorrect authorization vulnerability in remote office deploy configurations.This issue affects Endpoint Central: before 11.3.2416.04 and before 11.3.2400.25.

  • CVE-2024-37383MedKEVJun 7, 2024
    risk 0.54cvss 6.1epss 0.73

    Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via SVG animate attributes.

  • CVE-2024-5420HigJun 4, 2024
    risk 0.54cvss epss 0.06

    Missing input validation in the SEH Computertechnik utnserver Pro, SEH Computertechnik utnserver ProMAX, SEH Computertechnik INU-100 web-interface allows stored Cross-Site Scripting (XSS)..This issue affects utnserver Pro, utnserver ProMAX, INU-100 version 20.1.22 and below.

  • CVE-2024-4749HigJun 4, 2024
    risk 0.54cvss 8.3epss 0.00

    The wp-eMember WordPress plugin before 10.3.9 does not sanitize and escape the "fieldId" parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting.

  • CVE-2024-3576HigMay 6, 2024
    risk 0.54cvss 8.3epss 0.00

    The NPort 5100A Series firmware version v1.6 and prior versions are affected by web server XSS vulnerability. The vulnerability is caused by not correctly neutralizing user-controllable input before placing it in output. Malicious users may use the vulnerability to get sensitive…

  • CVE-2024-3323HigApr 17, 2024
    risk 0.54cvss 8.3epss 0.00

    Cross Site Scripting in UI Request/Response Validation in TIBCO JasperReports Server 8.0.4 and 8.2.0 allows allows for the injection of malicious executable scripts into the code of a trusted application that may lead to stealing the user's active session cookie via sending…

  • CVE-2023-40290HigMar 27, 2024
    risk 0.54cvss 8.3epss 0.01

    An issue was discovered on Supermicro X11SSM-F, X11SAE-F, and X11SSE-F 1.66 devices. An attacker could exploit an XSS issue that affects Internet Explorer 11 on Windows.

  • CVE-2023-40288HigMar 27, 2024
    risk 0.54cvss 8.3epss 0.01

    An issue was discovered on Supermicro X11SSM-F, X11SAE-F, and X11SSE-F 1.66 devices. An attacker could exploit an XSS issue.

  • CVE-2023-40287HigMar 27, 2024
    risk 0.54cvss 8.3epss 0.01

    An issue was discovered on Supermicro X11SSM-F, X11SAE-F, and X11SSE-F 1.66 devices. An attacker could exploit an XSS issue.

  • CVE-2023-40286HigMar 27, 2024
    risk 0.54cvss 8.3epss 0.01

    An issue was discovered on Supermicro X11SSM-F, X11SAE-F, and X11SSE-F 1.66 devices. An attacker could exploit an XSS issue.

  • CVE-2023-40284HigMar 27, 2024
    risk 0.54cvss 8.3epss 0.01

    An issue was discovered on Supermicro X11SSM-F, X11SAE-F, and X11SSE-F 1.66 devices. An attacker could exploit an XSS issue.