VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (46,607)

page 51 of 2,331
  • CVE-2024-22397HigMar 14, 2024
    risk 0.54cvss 8.3epss 0.01

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in the SonicOS SSLVPN portal allows a remote authenticated attacker as a firewall 'admin' user to store and execute arbitrary JavaScript code.

  • CVE-2023-49077HigNov 30, 2023
    risk 0.54cvss 8.3epss 0.00

    Mailcow: dockerized is an open source groupware/email suite based on docker. A Cross-Site Scripting (XSS) vulnerability has been identified within the Quarantine UI of the system. This vulnerability poses a significant threat to administrators who utilize the Quarantine feature.…

  • CVE-2023-35796HigOct 10, 2023
    risk 0.54cvss 8.3epss 0.01

    A vulnerability has been identified in SINEMA Server V14 (All versions). The affected application improperly sanitizes certain SNMP configuration data retrieved from monitored devices. An attacker with access to a monitored device could perform a stored cross-site scripting…

  • CVE-2023-40047HigSep 27, 2023
    risk 0.54cvss 8.3epss 0.00

    In WS_FTP Server version prior to 8.8.2, a stored cross-site scripting (XSS) vulnerability exists in WS_FTP Server's Management module. An attacker with administrative privileges could import a SSL certificate with malicious attributes containing cross-site scripting…

  • CVE-2023-40045HigSep 27, 2023
    risk 0.54cvss 8.3epss 0.01

    In WS_FTP Server versions prior to 8.7.4 and 8.8.2, a reflected cross-site scripting (XSS) vulnerability exists in WS_FTP Server's Ad Hoc Transfer module.  An attacker could leverage this vulnerability to target WS_FTP Server users with a specialized payload which results…

  • CVE-2023-39266HigAug 29, 2023
    risk 0.54cvss 8.3epss 0.00

    A vulnerability in the ArubaOS-Switch web management interface could allow an unauthenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface provided certain configuration options are present. A successful exploit could…

  • CVE-2023-37496HigAug 1, 2023
    risk 0.54cvss 8.3epss 0.00

    HCL Verse is susceptible to a Stored Cross Site Scripting (XSS) vulnerability. An attacker could execute script in a victim's web browser to perform operations as the victim and/or steal the victim's cookies, session tokens, or other sensitive information.

  • CVE-2023-3466HigJul 19, 2023
    risk 0.54cvss 8.3epss 0.03

    Reflected Cross-Site Scripting (XSS)

  • CVE-2023-2507CriJul 15, 2023
    risk 0.54cvss 9.3epss 0.01

    CleverTap Cordova Plugin version 2.6.2 allows a remote attacker to execute JavaScript code in any application that is opened via a specially constructed deeplink by an attacker. This is possible because the plugin does not correctly validate the data coming from the deeplinks…

  • CVE-2023-3388HigJun 24, 2023
    risk 0.54cvss 7.2epss 0.84

    The Beautiful Cookie Consent Banner for WordPress is vulnerable to Stored Cross-Site Scripting via the 'nsc_bar_content_href' parameter in versions up to, and including, 2.10.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated…

  • CVE-2023-0992HigJun 9, 2023
    risk 0.54cvss 7.2epss 0.93

    The Shield Security plugin for WordPress is vulnerable to stored Cross-Site Scripting in versions up to, and including, 17.0.17 via the 'User-Agent' header. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a…

  • CVE-2023-28083HigMar 22, 2023
    risk 0.54cvss 8.3epss 0.00

    A remote Cross-site Scripting vulnerability was discovered in HPE Integrated Lights-Out 6 (iLO 6), Integrated Lights-Out 5 (iLO 5) and Integrated Lights-Out 4 (iLO 4). HPE has provided software updates to resolve this vulnerability in HPE Integrated Lights-Out.

  • CVE-2023-23383HigMar 14, 2023
    risk 0.54cvss 8.2epss 0.12

    Service Fabric Explorer Spoofing Vulnerability

  • CVE-2021-27788HigMar 10, 2023
    risk 0.54cvss 8.3epss 0.01

    HCL Verse is susceptible to a Cross Site Scripting (XSS) vulnerability.  By tricking a user into clicking a crafted URL, a remote unauthenticated attacker could execute script in a victim's web browser to perform operations as the victim and/or steal the victim's cookies,…

  • CVE-2022-3265HigNov 9, 2022
    risk 0.54cvss 7.3epss 0.86

    A cross-site scripting issue has been discovered in GitLab CE/EE affecting all versions prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2. It was possible to exploit a vulnerability in setting the labels colour feature which could lead to a stored XSS that allowed…

  • CVE-2022-40181HigOct 11, 2022
    risk 0.54cvss 8.3epss 0.01

    A vulnerability has been identified in Desigo PXM30-1 (All versions < V02.20.126.11-41), Desigo PXM30.E (All versions < V02.20.126.11-41), Desigo PXM40-1 (All versions < V02.20.126.11-41), Desigo PXM40.E (All versions < V02.20.126.11-41), Desigo PXM50-1 (All versions <…

  • CVE-2022-27546HigAug 29, 2022
    risk 0.54cvss 8.3epss 0.01

    HCL iNotes is susceptible to a Reflected Cross-site Scripting (XSS) vulnerability caused by improper validation of user-supplied input supplied with a form POST request. A remote attacker could exploit this vulnerability using a specially-crafted URL to execute script in a…

  • CVE-2022-29095HigJun 10, 2022
    risk 0.54cvss 8.3epss 0.01

    Dell SupportAssist Client Consumer versions (3.10.4 and prior) and Dell SupportAssist Client Commercial versions (3.1.1 and prior) contain a cross-site scripting vulnerability. A remote unauthenticated malicious user could potentially exploit this vulnerability under specific…

  • CVE-2021-44082HigMar 29, 2022
    risk 0.54cvss 8.3epss 0.03

    textpattern 4.8.7 is vulnerable to Cross Site Scripting (XSS) via /textpattern/index.php,Body. A remote and unauthenticated attacker can use XSS to trigger remote code execution by uploading a webshell. To do so they must first steal the CSRF token before submitting a file…

  • CVE-2021-27911HigAug 30, 2021
    risk 0.54cvss 8.3epss 0.01

    Mautic versions before 3.3.4/4.0.0 are vulnerable to an inline JS XSS attack through the contact's first or last name and triggered when viewing a contact's details page then clicking on the action drop down and hovering over the Campaigns button. Contact first and last name can…