VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (46,607)

page 56 of 2,331
  • CVE-2025-47977HigJun 10, 2025
    risk 0.53cvss 8.2epss 0.01

    Improper neutralization of input during web page generation ('cross-site scripting') in Nuance Digital Engagement Platform allows an unauthorized attacker to perform spoofing over a network.

  • CVE-2025-23192HigJun 10, 2025
    risk 0.53cvss 8.2epss 0.00

    SAP BusinessObjects Business Intelligence (BI Workspace) allows an unauthenticated attacker to craft and store malicious script within a workspace. When the victim accesses the workspace, the script will execute in their browser enabling the attacker to potentially access…

  • CVE-2024-57783HigJun 2, 2025
    risk 0.53cvss 8.1epss 0.00

    The desktop application in Dot through 0.9.3 allows XSS and resultant command execution because user input and LLM output are appended to the DOM with innerHTML (in render.js), and because the Electron window can access Node.js APIs.

  • CVE-2025-4123HigMay 22, 2025
    risk 0.53cvss 7.6epss 0.97

    A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redirect. This allows attackers to redirect users to a website that hosts a frontend plugin that will execute arbitrary JavaScript. This vulnerability does not…

  • CVE-2025-22249HigMay 13, 2025
    risk 0.53cvss 8.2epss 0.00

    VMware Aria automation contains a DOM based Cross-Site Scripting (XSS) vulnerability. A malicious actor may exploit this issue to steal the access token of a logged in user of VMware Aria automation appliance by tricking the user into clicking a malicious crafted payload URL.

  • CVE-2025-0984HigMay 6, 2025
    risk 0.53cvss 8.2epss 0.00

    Unrestricted Upload of File with Dangerous Type, Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Netoloji Software E-Flow allows Accessing Functionality Not Properly Constrained by ACLs, Stored XSS, File Content…

  • CVE-2025-22636HigApr 17, 2025
    risk 0.53cvss 8.2epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vicente Ruiz Gálvez VR-Frases vr-frases allows Reflected XSS.This issue affects VR-Frases: from n/a through <= 4.0.1.

  • CVE-2025-2160HigApr 14, 2025
    risk 0.53cvss 8.1epss 0.00

    Pega Platform versions 8.4.3 to Infinity 24.2.1 are affected by an XSS issue with Mashup

  • CVE-2025-22466HigApr 8, 2025
    risk 0.53cvss 8.2epss 0.01

    Reflected XSS in Ivanti Endpoint Manager before version 2024 SU1 or before version 2022 SU7 allows a remote unauthenticated attacker to obtain admin privileges. User interaction is required.

  • CVE-2025-30223CriMar 31, 2025
    risk 0.53cvss 9.3epss 0.01

    Beego is an open-source web framework for the Go programming language. Prior to 2.3.6, a Cross-Site Scripting (XSS) vulnerability exists in Beego's RenderForm() function due to improper HTML escaping of user-controlled data. This vulnerability allows attackers to inject…

  • CVE-2025-2609HigMar 21, 2025
    risk 0.53cvss 8.2epss 0.01

    Improper neutralization of input during web page generation vulnerability in MagnusSolution MagnusBilling login logging allows unauthenticated users to store HTML content in the viewable log component accessible at /mbilling/index.php/logUsers/read" cross-site scripting This…

  • CVE-2025-27500HigMar 3, 2025
    risk 0.53cvss 8.2epss 0.00

    OpenZiti is a free and open source project focused on bringing zero trust to any application. An endpoint(/api/upload) on the admin panel can be accessed without any form of authentication. This endpoint accepts an HTTP POST to upload a file which is then stored on the node and…

  • CVE-2024-57030HigJan 17, 2025
    risk 0.53cvss 8.1epss 0.01

    Wegia < 3.2.0 is vulnerable to Cross Site Scripting (XSS) in /geral/documentos_funcionario.php via the id parameter.

  • CVE-2024-7085HigJan 15, 2025
    risk 0.53cvss epss 0.00

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in OpenText™ Solutions Business Manager (SBM) allows Stored XSS.  The vulnerability could result in the exposure of private information to an unauthorized actor. This…

  • CVE-2024-56174HigDec 18, 2024
    risk 0.53cvss 8.1epss 0.00

    In Optimizely Configured Commerce before 5.2.2408, malicious payloads can be stored and subsequently executed in users' browsers under specific conditions: XSS from client-side template injection in search history.

  • CVE-2024-54037HigDec 10, 2024
    risk 0.53cvss 8.1epss 0.01

    Adobe Connect versions 12.6, 11.4.7 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be exploited by an attacker to execute arbitrary code in the context of the victim's browser session. By manipulating a DOM element through a crafted…

  • CVE-2024-11182MedKEVNov 15, 2024
    risk 0.53cvss 6.1epss 0.18

    An XSS issue was discovered in MDaemon Email Server before version 24.5.1c. An attacker can send an HTML e-mail message with JavaScript in an img tag. This could allow a remote attacker to load arbitrary JavaScript code in the context of a webmail user's browser window.

  • CVE-2024-46482HigOct 22, 2024
    risk 0.53cvss 8.2epss 0.00

    An arbitrary file upload vulnerability in the Ticket Generation function of Ladybird Web Solution Faveo-Helpdesk v2.0.3 allows attackers to execute arbitrary code via uploading a crafted .html or .svg file.

  • CVE-2024-45116HigOct 10, 2024
    risk 0.53cvss 8.1epss 0.01

    Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by a Cross-Site Scripting (XSS) vulnerability that could be exploited to execute arbitrary code. If an admin attacker can trick a user into clicking a specially crafted link or submitting a…

  • CVE-2024-40510HigSep 27, 2024
    risk 0.53cvss 8.2epss 0.01

    Cross Site Scripting vulnerability in openPetra v.2023.02 allows a remote attacker to obtain sensitive information via the serverMCommon.asmx function.