VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (46,607)

page 54 of 2,331
  • CVE-2026-26105HigMar 10, 2026
    risk 0.53cvss 8.1epss 0.01

    Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.

  • CVE-2026-29191CriMar 7, 2026
    risk 0.53cvss 9.3epss 0.00

    ZITADEL is an open source identity management platform. From version 4.0.0 to 4.11.1, a vulnerability in Zitadel's login V2 interface was discovered that allowed a possible account takeover via XSS in /saml-post Endpoint. This issue has been patched in version 4.12.0.

  • CVE-2026-28272HigFeb 27, 2026
    risk 0.53cvss 8.1epss 0.00

    Kiteworks is a private data network (PDN). Prior to version 9.2.0, a vulnerability in Kiteworks Email Protection Gateway allows authenticated administrators to inject malicious scripts through a configuration interface. The stored script executes when users interact with the…

  • CVE-2026-27614CriFeb 25, 2026
    risk 0.53cvss 9.3epss 0.00

    Bugsink is a self-hosted error tracking tool. In versions prior to 2.0.13, an unauthenticated attacker who can submit events to a Bugsink project can store arbitrary JavaScript in an event. The payload executes only if a user explicitly views the affected Stacktrace in the web…

  • CVE-2026-25896CriFeb 20, 2026
    risk 0.53cvss 9.3epss 0.00

    fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based libraries and no callback. From 4.1.3to before 5.3.5, a dot (.) in a DOCTYPE entity name is treated as a regex wildcard during entity replacement, allowing an…

  • CVE-2026-26723HigFeb 20, 2026
    risk 0.53cvss 8.2epss 0.00

    Cross Site Scripting vulnerability in Key Systems Inc Global Facilities Management Software v. 20230721a allows a remote attacker to execute arbitrary code via the function parameter.

  • CVE-2025-13002HigFeb 12, 2026
    risk 0.53cvss 8.2epss 0.00

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Farktor Software E-Commerce Services Inc. E-Commerce Package allows Cross-Site Scripting (XSS). This issue affects E-Commerce Package: through 27112025.

  • CVE-2026-25847HigFeb 9, 2026
    risk 0.53cvss 8.2epss 0.00

    In JetBrains PyCharm before 2025.3.2 a DOM-based XSS on Jupyter viewer page was possible

  • CVE-2026-1953HigFeb 5, 2026
    risk 0.53cvss epss 0.00

    Nukegraphic CMS v3.1.2 contains a stored cross-site scripting (XSS) vulnerability in the user profile edit functionality at /ngc-cms/user-edit-profile.php. The application fails to properly sanitize user input in the name field before storing it in the database and rendering it…

  • CVE-2026-0535HigJan 22, 2026
    risk 0.53cvss 8.1epss 0.01

    A maliciously crafted HTML payload, stored in a component’s description and clicked by a user, can trigger a Stored Cross-site Scripting (XSS) vulnerability in the Autodesk Fusion desktop application. A malicious actor may leverage this vulnerability to read local files or…

  • CVE-2026-0534HigJan 22, 2026
    risk 0.53cvss 8.1epss 0.00

    A maliciously crafted HTML payload, stored in a part’s attribute and clicked by a user, can trigger a Stored Cross-site Scripting (XSS) vulnerability in the Autodesk Fusion desktop application. A malicious actor may leverage this vulnerability to read local files or execute…

  • CVE-2026-0533HigJan 22, 2026
    risk 0.53cvss 8.1epss 0.01

    A maliciously crafted HTML payload in a design name, when displayed during the delete confirmation dialog and clicked by a user, can trigger a Stored Cross-site Scripting (XSS) vulnerability in the Autodesk Fusion desktop application. A malicious actor may leverage this…

  • CVE-2025-67823HigJan 15, 2026
    risk 0.53cvss 8.2epss 0.00

    A vulnerability in the Multimedia Email component of Mitel MiContact Center Business through 10.2.0.10 and Mitel CX through 1.1.0.1 could allow an unauthenticated attacker to conduct a Cross-Site Scripting (XSS) attack due to insufficient input validation. A successful exploit…

  • CVE-2025-66376HigKEVJan 5, 2026
    risk 0.53cvss 7.2epss 0.19

    Zimbra Collaboration (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 allows Classic UI stored XSS via Cascading Style Sheets (CSS) @import directives in an HTML e-mail message.

  • CVE-2025-66444HigDec 24, 2025
    risk 0.53cvss 8.2epss 0.00

    Cross-site Scripting vulnerability in Hitachi Infrastructure Analytics Advisor (Data Center Analytics component) and Hitachi Ops Center Analyzer (Hitachi Ops Center Analyzer detail view component).This issue affects Hitachi Infrastructure Analytics Advisor:; Hitachi Ops Center…

  • CVE-2025-64677HigDec 18, 2025
    risk 0.53cvss 8.2epss 0.01

    Improper neutralization of input during web page generation ('cross-site scripting') in Office Out-of-Box Experience allows an unauthorized attacker to perform spoofing over a network.

  • CVE-2025-14202HigDec 18, 2025
    risk 0.53cvss epss 0.00

    A vulnerability in the file upload at bookmark + asset rendering pipeline allows an attacker to upload a malicious SVG file with JavaScript content. When an authenticated admin user views the SVG file with embedded JavaScript code of shared bookmark, JavaScript executes in the…

  • CVE-2025-68147HigDec 17, 2025
    risk 0.53cvss 8.1epss 0.00

    Open Source Point of Sale (opensourcepos) is a web based point of sale application written in PHP using CodeIgniter framework. Starting in version 3.4.0 and prior to version 3.4.2, a Stored Cross-Site Scripting (XSS) vulnerability exists in the "Return Policy" configuration…

  • CVE-2025-13614HigDec 5, 2025
    risk 0.53cvss 8.1epss 0.00

    The Cool Tag Cloud plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'cool_tag_cloud' shortcode in all versions up to, and including, 2.29 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it…

  • CVE-2025-13639HigDec 2, 2025
    risk 0.53cvss 8.1epss 0.00

    Inappropriate implementation in WebRTC in Google Chrome prior to 143.0.7499.41 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: Low)