CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Description
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85
CVEs mapped to this weakness (22,700)
page 578 of 1,135| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2017-17988 | Med | 0.31 | 4.8 | 0.00 | Dec 30, 2017 | PHP Scripts Mall Muslim Matrimonial Script has XSS via the admin/event_add.php event_title parameter. | ||
| CVE-2017-17986 | Med | 0.31 | 4.8 | 0.00 | Dec 30, 2017 | PHP Scripts Mall Muslim Matrimonial Script has XSS via the admin/caste_view.php comm_id parameter. | ||
| CVE-2017-17985 | Med | 0.31 | 4.8 | 0.00 | Dec 30, 2017 | PHP Scripts Mall Muslim Matrimonial Script has XSS via the admin/state_view.php cou_id parameter. | ||
| CVE-2017-17984 | Med | 0.31 | 4.8 | 0.00 | Dec 30, 2017 | PHP Scripts Mall Muslim Matrimonial Script has XSS via the admin/event_edit.php edit_id parameter. | ||
| CVE-2017-17940 | Med | 0.31 | 4.8 | 0.00 | Dec 28, 2017 | PHP Scripts Mall Single Theater Booking has XSS via the title parameter to admin/sitesettings.php. | ||
| CVE-2017-17938 | Med | 0.31 | 4.8 | 0.00 | Dec 28, 2017 | PHP Scripts Mall Single Theater Booking has XSS via the admin/viewtheatre.php theatreid parameter. | ||
| CVE-2017-16768 | Med | 0.31 | 4.8 | 0.00 | Dec 27, 2017 | Cross-site scripting (XSS) vulnerability in User Policy editor in Synology MailPlus Server before 1.4.0-0415 allows remote authenticated users to inject arbitrary HTML via the name parameter. | ||
| CVE-2017-17929 | Med | 0.31 | 4.8 | 0.00 | Dec 27, 2017 | PHP Scripts Mall Professional Service Script has XSS via the admin/bannerview.php view parameter. | ||
| CVE-2017-17925 | Med | 0.31 | 4.8 | 0.00 | Dec 27, 2017 | PHP Scripts Mall Professional Service Script has XSS via the admin/general_settingupd.php website_title parameter. | ||
| CVE-2017-17909 | Med | 0.31 | 4.8 | 0.00 | Dec 27, 2017 | PHP Scripts Mall Responsive Realestate Script has XSS via the admin/general.php gplus parameter. | ||
| CVE-2017-17828 | Med | 0.31 | 4.8 | 0.00 | Dec 21, 2017 | Bus Booking Script has XSS via the results.php datepicker parameter or the admin/new_master.php spemail parameter. | ||
| CVE-2017-17825 | Med | 0.31 | 4.8 | 0.00 | Dec 21, 2017 | The Batch Manager component of Piwigo 2.9.2 is vulnerable to Persistent Cross Site Scripting via tags-* array parameters in an admin.php?page=batch_manager&mode=unit request. An attacker can exploit this to hijack a client's browser along with the data stored in it. | ||
| CVE-2017-17778 | — | Med | 0.31 | 4.8 | 0.00 | Dec 20, 2017 | Paid To Read Script 2.0.5 has XSS via the referrals.php tier parameter or the admin/userview.php uid parameter. | |
| CVE-2017-15890 | Med | 0.31 | 4.8 | 0.00 | Dec 15, 2017 | Cross-site scripting (XSS) vulnerability in Disclaimer in Synology MailPlus Server before 1.4.0-0415 allows remote authenticated users to inject arbitrary web script or HTML via the NAME parameter. | ||
| CVE-2017-16789 | Med | 0.31 | 4.8 | 0.00 | Dec 11, 2017 | Cross-site scripting (XSS) vulnerability in Integration Matters nJAMS 3 before 3.2.0 Hotfix 7, as used in TIBCO BusinessWorks Process Monitor through 3.0.1.3 and other products, allows remote authenticated administrators to inject arbitrary web script or HTML via the users… | ||
| CVE-2017-17383 | Med | 0.31 | 4.7 | 0.00 | Dec 6, 2017 | Jenkins through 2.93 allows remote authenticated administrators to conduct XSS attacks via a crafted tool name in a job configuration form, as demonstrated by the JDK tool in Jenkins core and the Ant tool in the Ant plugin, aka SECURITY-624. | ||
| CVE-2017-12345 | Med | 0.31 | 4.7 | 0.00 | Nov 30, 2017 | Multiple vulnerabilities in Cisco Data Center Network Manager (DCNM) Software could allow a remote attacker to inject arbitrary values into DCNM configuration parameters, redirect a user to a malicious website, inject malicious content into a DCNM client interface, or conduct a… | ||
| CVE-2017-13700 | Med | 0.31 | 4.8 | 0.00 | Nov 17, 2017 | An issue was discovered on MOXA EDS-G512E 5.1 build 16072215 devices. There is XSS in the administration interface. | ||
| CVE-2017-1000213 | Med | 0.31 | 4.8 | 0.00 | Nov 17, 2017 | WBCE v1.1.11 is vulnerable to reflected XSS via the "begriff" POST parameter in /admin/admintools/tool.php?tool=user_search | ||
| CVE-2017-15039 | Med | 0.31 | 4.8 | 0.00 | Nov 6, 2017 | Cross-site scripting (XSS) exists in Zurmo 3.2.1.57987acc3018 via a data: URL in the redirectUrl parameter to app/index.php/meetings/default/createMeeting. |
- risk 0.31cvss 4.8epss 0.00
PHP Scripts Mall Muslim Matrimonial Script has XSS via the admin/event_add.php event_title parameter.
- risk 0.31cvss 4.8epss 0.00
PHP Scripts Mall Muslim Matrimonial Script has XSS via the admin/caste_view.php comm_id parameter.
- risk 0.31cvss 4.8epss 0.00
PHP Scripts Mall Muslim Matrimonial Script has XSS via the admin/state_view.php cou_id parameter.
- risk 0.31cvss 4.8epss 0.00
PHP Scripts Mall Muslim Matrimonial Script has XSS via the admin/event_edit.php edit_id parameter.
- risk 0.31cvss 4.8epss 0.00
PHP Scripts Mall Single Theater Booking has XSS via the title parameter to admin/sitesettings.php.
- risk 0.31cvss 4.8epss 0.00
PHP Scripts Mall Single Theater Booking has XSS via the admin/viewtheatre.php theatreid parameter.
- risk 0.31cvss 4.8epss 0.00
Cross-site scripting (XSS) vulnerability in User Policy editor in Synology MailPlus Server before 1.4.0-0415 allows remote authenticated users to inject arbitrary HTML via the name parameter.
- risk 0.31cvss 4.8epss 0.00
PHP Scripts Mall Professional Service Script has XSS via the admin/bannerview.php view parameter.
- risk 0.31cvss 4.8epss 0.00
PHP Scripts Mall Professional Service Script has XSS via the admin/general_settingupd.php website_title parameter.
- risk 0.31cvss 4.8epss 0.00
PHP Scripts Mall Responsive Realestate Script has XSS via the admin/general.php gplus parameter.
- risk 0.31cvss 4.8epss 0.00
Bus Booking Script has XSS via the results.php datepicker parameter or the admin/new_master.php spemail parameter.
- risk 0.31cvss 4.8epss 0.00
The Batch Manager component of Piwigo 2.9.2 is vulnerable to Persistent Cross Site Scripting via tags-* array parameters in an admin.php?page=batch_manager&mode=unit request. An attacker can exploit this to hijack a client's browser along with the data stored in it.
- risk 0.31cvss 4.8epss 0.00
Paid To Read Script 2.0.5 has XSS via the referrals.php tier parameter or the admin/userview.php uid parameter.
- risk 0.31cvss 4.8epss 0.00
Cross-site scripting (XSS) vulnerability in Disclaimer in Synology MailPlus Server before 1.4.0-0415 allows remote authenticated users to inject arbitrary web script or HTML via the NAME parameter.
- risk 0.31cvss 4.8epss 0.00
Cross-site scripting (XSS) vulnerability in Integration Matters nJAMS 3 before 3.2.0 Hotfix 7, as used in TIBCO BusinessWorks Process Monitor through 3.0.1.3 and other products, allows remote authenticated administrators to inject arbitrary web script or HTML via the users…
- risk 0.31cvss 4.7epss 0.00
Jenkins through 2.93 allows remote authenticated administrators to conduct XSS attacks via a crafted tool name in a job configuration form, as demonstrated by the JDK tool in Jenkins core and the Ant tool in the Ant plugin, aka SECURITY-624.
- risk 0.31cvss 4.7epss 0.00
Multiple vulnerabilities in Cisco Data Center Network Manager (DCNM) Software could allow a remote attacker to inject arbitrary values into DCNM configuration parameters, redirect a user to a malicious website, inject malicious content into a DCNM client interface, or conduct a…
- risk 0.31cvss 4.8epss 0.00
An issue was discovered on MOXA EDS-G512E 5.1 build 16072215 devices. There is XSS in the administration interface.
- risk 0.31cvss 4.8epss 0.00
WBCE v1.1.11 is vulnerable to reflected XSS via the "begriff" POST parameter in /admin/admintools/tool.php?tool=user_search
- risk 0.31cvss 4.8epss 0.00
Cross-site scripting (XSS) exists in Zurmo 3.2.1.57987acc3018 via a data: URL in the redirectUrl parameter to app/index.php/meetings/default/createMeeting.