VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (22,700)

page 581 of 1,135
  • CVE-2016-7650MedFeb 20, 2017
    risk 0.31cvss 4.7epss 0.00

    An issue was discovered in certain Apple products. iOS before 10.2 is affected. Safari before 10.0.2 is affected. The issue involves the "Safari Reader" component, which allows remote attackers to conduct UXSS attacks via a crafted web site.

  • CVE-2016-10112MedJan 4, 2017
    risk 0.31cvss 4.8epss 0.00

    Cross-site scripting (XSS) vulnerability in the WooCommerce plugin before 2.6.9 for WordPress allows remote authenticated administrators to inject arbitrary web script or HTML by providing crafted tax-rate table values in CSV format.

  • CVE-2016-1000121MedOct 27, 2016
    risk 0.31cvss 4.8epss 0.00

    XSS and SQLi in Huge IT Joomla Slider v1.0.9 extension

  • CVE-2016-5395MedSep 26, 2016
    risk 0.31cvss 4.8epss 0.00

    Cross-site scripting (XSS) vulnerability in the create user functionality in the policy admin tool in Apache Ranger before 0.6.1 allows remote authenticated administrators to inject arbitrary web script or HTML via vectors related to policies.

  • CVE-2016-5005MedJul 28, 2016
    risk 0.31cvss 4.8epss 0.01

    Cross-site scripting (XSS) vulnerability in Apache Archiva 1.3.9 and earlier allows remote authenticated administrators to inject arbitrary web script or HTML via the connector.sourceRepoId parameter to admin/addProxyConnector_commit.action.

  • CVE-2016-3971MedApr 18, 2016
    risk 0.31cvss 4.8epss 0.00

    Cross-site scripting (XSS) vulnerability in lucene_search.jsp in dotCMS before 3.5.1 allows remote attackers to inject arbitrary web script or HTML via the query parameter to c/portal/layout.

  • CVE-2015-8508MedJan 3, 2016
    risk 0.31cvss 4.7epss 0.00

    Cross-site scripting (XSS) vulnerability in showdependencygraph.cgi in Bugzilla 2.x, 3.x, and 4.x before 4.2.16, 4.3.x and 4.4.x before 4.4.11, and 4.5.x and 5.0.x before 5.0.2, when a local dot configuration is used, allows remote attackers to inject arbitrary web script or…

  • CVE-2015-5521MedJul 14, 2015
    risk 0.31cvss 4.8epss 0.00

    Cross-site scripting (XSS) vulnerability in BlackCat CMS 1.1.2 allows remote attackers to inject arbitrary web script or HTML via the name in a new group to backend/groups/index.php.

  • CVE-2010-3243MedOct 13, 2010
    risk 0.31cvss 4.3epss 0.38

    Cross-site scripting (XSS) vulnerability in the toStaticHTML function in Microsoft Internet Explorer 8, and the SafeHTML function in Microsoft Windows SharePoint Services 3.0 SP2 and Office SharePoint Server 2007 SP2, allows remote attackers to inject arbitrary web script or…

  • CVE-2004-1865MedMar 26, 2004
    risk 0.31cvss 4.8epss 0.00

    Cross-site scripting (XSS) vulnerability in the administration panel in bBlog 0.7.2 allows remote authenticated users with superuser privileges to inject arbitrary web script or HTML via a blog name ($blogname). NOTE: if administrators are normally allowed to add HTML by other…

  • CVE-2026-41250MedMay 11, 2026
    risk 0.30cvss 5.7epss 0.00

    Taiga is a project management platform for startups and agile developers. Prior 6.9.1, Taiga front is vulnerable to stored XSS. This vulnerability is fixed in 6.9.1.

  • CVE-2026-42086MedMay 4, 2026
    risk 0.30cvss 4.6epss 0.00

    OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to version 7.0.0, the Command Sender UI uses an unsafe eval() function on array-like command parameters, which allows a user-supplied payload to execute…

  • CVE-2026-7429MedApr 30, 2026
    risk 0.30cvss 4.6epss 0.00

    SSCMS v7.4.0 contains a reflected cross-site scripting vulnerability in the STL processing endpoint that allows attackers to execute arbitrary JavaScript by crafting malicious STL template payloads that are decrypted and returned without proper sanitization. Attackers can…

  • CVE-2026-33193MedApr 14, 2026
    risk 0.30cvss 4.6epss 0.00

    Docmost is open-source collaborative wiki and documentation software. Versions prior to 0.70.0 are vulnerable to a stored cross-site scripting (XSS) attack due to improper handling of MIME type spoofing (GHSL-2026-052). An attacker could exploit this flaw to inject malicious…

  • CVE-2026-20945MedApr 14, 2026
    risk 0.30cvss 4.6epss 0.00

    Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

  • CVE-2026-22154MedApr 14, 2026
    risk 0.30cvss 4.6epss 0.00

    An improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.3, FortiSOAR PaaS 7.5.0 through 7.5.2, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3 all versions, FortiSOAR on-premise 7.6.0…

  • CVE-2026-33653MedMar 26, 2026
    risk 0.30cvss 4.6epss 0.00

    Ulloady is a file uploader script with multi-file upload support. A Stored Cross-Site Scripting (XSS) vulnerability exists in versions prior to 3.1.2 due to improper sanitization of filenames during the file upload process. An attacker can upload a file with a malicious filename…

  • CVE-2025-9226MedJan 30, 2026
    risk 0.30cvss 4.6epss 0.00

    Zohocorp ManageEngine OpManager, NetFlow Analyzer, and OpUtils versions prior to 128582 are affected by a stored cross-site scripting vulnerability in the Subnet Details.

  • CVE-2023-53904MedDec 17, 2025
    risk 0.30cvss 4.6epss 0.00

    Xenforo 2.2.13 contains a stored cross-site scripting vulnerability that allows authenticated administrators to inject malicious scripts through the smilie category title parameter. Attackers can create a smilie category with a malicious script that will execute when the admin…

  • CVE-2025-11570MedOct 10, 2025
    risk 0.30cvss 4.6epss 0.00

    Versions of the package drupal-pattern-lab/unified-twig-extensions from 0.0.0 are vulnerable to Cross-site Scripting (XSS) due to insufficient filtering of data. **Note:** This is exploitable only if the code is executed outside of Drupal; the function is intended to be shared…