VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (46,607)

page 52 of 2,331
  • CVE-2021-23854HigJun 9, 2021
    risk 0.54cvss 8.3epss 0.01

    An error in the handling of a page parameter in Bosch IP cameras may lead to a reflected cross site scripting (XSS) in the web-based interface. This issue only affects versions 7.7x and 7.6x. All other versions are not affected.

  • CVE-2021-23848HigJun 9, 2021
    risk 0.54cvss 8.3epss 0.01

    An error in the URL handler Bosch IP cameras may lead to a reflected cross site scripting (XSS) in the web-based interface. An attacker with knowledge of the camera address can send a crafted link to a user, which will execute javascript code in the context of the user.

  • CVE-2021-22978HigFeb 12, 2021
    risk 0.54cvss 8.3epss 0.01

    On BIG-IP version 16.0.x before 16.0.1, 15.1.x before 15.1.1, 14.1.x before 14.1.3.1, 13.1.x before 13.1.3.5, and all 12.1.x and 11.6.x versions, undisclosed endpoints in iControl REST allow for a reflected XSS attack, which could lead to a complete compromise of BIG-IP if the…

  • CVE-2020-27176HigOct 16, 2020
    risk 0.54cvss 8.3epss 0.02

    Mutation XSS exists in Mark Text through 0.16.2 that leads to Remote Code Execution. NOTE: this might be considered a duplicate of CVE-2020-26870; however, it can also be considered an issue in the design of the "source code mode" feature, which parses HTML even though HTML…

  • CVE-2019-11982HigJun 5, 2019
    risk 0.54cvss 8.3epss 0.02

    A remote cross site scripting vulnerability was identified in HPE Integrated Lights-Out 4 (iLO 4) earlier than v2.61b for Gen9 servers and Integrated Lights-Out 5 (iLO 5) for Gen10 Servers earlier than version v1.39.

  • CVE-2019-3709HigApr 17, 2019
    risk 0.54cvss 8.3epss 0.02

    IsilonSD Management Server 1.1.0 contains a cross-site scripting vulnerability while registering vCenter servers. A remote attacker can trick an admin user to potentially exploit this vulnerability to execute malicious HTML or JavaScript code in the context of the admin user.

  • CVE-2019-3708HigApr 17, 2019
    risk 0.54cvss 8.3epss 0.02

    IsilonSD Management Server 1.1.0 contains a cross-site scripting vulnerability while uploading an OVA file. A remote attacker can trick an admin user to potentially exploit this vulnerability to execute malicious HTML or JavaScript code in the context of the admin user.

  • CVE-2018-15613HigSep 21, 2018
    risk 0.54cvss 8.3epss 0.01

    A cross-site scripting (XSS) vulnerability in the Runtime Config component of Avaya Aura Orchestration Designer could result in malicious content being returned to the user. Affected versions of Avaya Aura Orchestration Designer include all versions up to 7.2.1.

  • CVE-2026-59316HigAug 27, 2026
    risk 0.53cvss 8.2epss 0.00

    Spring Authorization Server's default consent page renders user-controlled values without HTML entity encoding. When using the DefaultConsentPage, an attacker can craft an OAuth2 authorization request containing a malicious value that is stored server-side and later rendered…

  • CVE-2026-53579CriAug 27, 2026
    risk 0.53cvss epss 0.00

    Trilium is an open-source hierarchical note-taking application. In versions up to and including 0.103.0, the default-on "Safe import" filter sanitizes HTML only for text notes and excludes the book note type, whose content is stored without sanitization and later rendered as…

  • CVE-2026-53578CriAug 27, 2026
    risk 0.53cvss epss 0.00

    Trilium is an open-source hierarchical note-taking application. In versions up to and including 0.103.0, the default-on "Safe import" filter sanitizes HTML only for text notes and excludes the mindMap note type, whose JSON content is stored without sanitization, allowing an…

  • CVE-2026-48996CriAug 27, 2026
    risk 0.53cvss epss 0.00

    Trilium is an open-source hierarchical note-taking application. In versions up to and including 0.103.0, the default-on "Safe import" filter does not sanitize note titles, and the GeoMap note view interpolates a marker note's title into raw HTML that is rendered as innerHTML,…

  • CVE-2026-47877HigAug 27, 2026
    risk 0.53cvss 8.2epss 0.00

    Spring Security Authorization Server's default consent page renders user-controlled values without HTML entity encoding. Spring Security 7.1.0 Spring Security 7.0.0 - 7.0.6

  • CVE-2026-75048HigAug 17, 2026
    risk 0.53cvss 8.2epss 0.00

    In JetBrains YouTrack before 2026.2.18068 stored XSS via the fenced code-block language label was possible

  • CVE-2026-48081HigAug 6, 2026
    risk 0.53cvss 8.1epss 0.00

    OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.2, a TENANT_ADMIN can store `javascript:` URLs in the tenant `links` configuration (`website`, `imprint`, `privacyStatement`). These values are…

  • CVE-2026-71285HigAug 5, 2026
    risk 0.53cvss 8.1epss 0.00

    Uptime Kuma's Matomo analytics integration (server/analytics/matomo-analytics.js) injects the admin-configurable Matomo value as a bare, unquoted JavaScript expression inside a block rendered on every public status page. A siteId value such as , once saved by an…

  • CVE-2026-15928HigJul 27, 2026
    risk 0.53cvss epss 0.00

    XMLRPC-C Library versions 1.07 through 1.67.01 are vulnerable to a reflected cross-site scripting (XSS) vulnerability in the error page component.

  • CVE-2026-17496HigJul 26, 2026
    risk 0.53cvss 8.1epss 0.00

    NoteGen before 0.32.0 renders AI chat responses with markdown-it configured with html:true and injects the result into the DOM via dangerouslySetInnerHTML in chat-preview, without HTML sanitization and with CSP set to null. Attacker-controlled content that reaches the model…

  • CVE-2026-47995HigJul 14, 2026
    risk 0.53cvss 8.1epss 0.00

    Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page…

  • CVE-2026-58500HigJul 13, 2026
    risk 0.53cvss 8.2epss 0.00

    MCP Appium is an MCP server that provides AI assistants with tools to automate mobile app testing on Android and iOS. In versions prior to 1.85.10, the createLocatorGeneratorUI function interpolates attacker-controlled element attributes — text, content-desc, resource-id, and…