VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (22,699)

page 602 of 1,135
  • CVE-2025-62798MedOct 28, 2025
    risk 0.28cvss 5.4epss 0.00

    Sharp is a content management framework built for Laravel as a package. Prior to 9.11.1, a Cross-Site Scripting (XSS) vulnerability was discovered in code16/sharp when rendering content using the SharpShowTextField component. In affected versions, expressions wrapped in {{ & }}…

  • CVE-2025-12335MedOct 28, 2025
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was determined in code-projects E-Commerce Website 1.0. Affected by this vulnerability is an unknown functionality of the file /pages/supplier_update.php. This manipulation of the argument supp_name/supp_address causes cross site scripting. The attack can be…

  • CVE-2025-12334MedOct 27, 2025
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was found in code-projects E-Commerce Website 1.0. Affected is an unknown function of the file /pages/product_add.php. The manipulation of the argument prod_name/prod_desc/prod_cost results in cross site scripting. It is possible to launch the attack remotely.…

  • CVE-2025-12333MedOct 27, 2025
    risk 0.28cvss 4.3epss 0.00

    A vulnerability has been found in code-projects E-Commerce Website 1.0. This impacts an unknown function of the file /pages/supplier_add.php. The manipulation of the argument supp_name/supp_address leads to cross site scripting. It is possible to initiate the attack remotely.…

  • CVE-2025-12302MedOct 27, 2025
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was detected in code-projects Simple Food Ordering System 1.0. The affected element is an unknown function of the file /editproduct.php. Performing manipulation of the argument pname/category/price results in cross site scripting. The attack may be initiated…

  • CVE-2025-12300MedOct 27, 2025
    risk 0.28cvss 4.3epss 0.00

    A weakness has been identified in code-projects Simple Food Ordering System 1.0. This issue affects some unknown processing of the file /addcategory.php. This manipulation of the argument cname causes cross site scripting. The attack can be initiated remotely. The exploit has…

  • CVE-2025-12299MedOct 27, 2025
    risk 0.28cvss 4.3epss 0.00

    A security flaw has been discovered in code-projects Simple Food Ordering System 1.0. This vulnerability affects unknown code of the file /addproduct.php. The manipulation of the argument pname/category/price results in cross site scripting. It is possible to launch the attack…

  • CVE-2025-12298MedOct 27, 2025
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was identified in code-projects Simple Food Ordering System 1.0. This affects an unknown part of the file /editcategory.php. The manipulation of the argument pname leads to cross site scripting. It is possible to initiate the attack remotely. The exploit is…

  • CVE-2025-12290MedOct 27, 2025
    risk 0.28cvss 4.3epss 0.00

    A vulnerability has been found in Sui Shang Information Technology Suishang Enterprise-Level B2B2C Multi-User Mall System 1.0. Affected by this issue is some unknown functionality of the file /i/359. The manipulation of the argument keywords leads to cross site scripting. The…

  • CVE-2025-12289MedOct 27, 2025
    risk 0.28cvss 4.3epss 0.00

    A flaw has been found in Sui Shang Information Technology Suishang Enterprise-Level B2B2C Multi-User Mall System 1.0. Affected by this vulnerability is an unknown functionality of the file /Point/index/activity_state/1/category_id/1001. Executing manipulation of the argument…

  • CVE-2025-12267MedOct 27, 2025
    risk 0.28cvss 4.3epss 0.00

    A flaw has been found in abhicodebox ModernShop 20250922. This issue affects some unknown processing of the file /search. Executing manipulation of the argument q can lead to cross site scripting. The attack may be performed from remote. The exploit has been published and may be…

  • CVE-2025-12246MedOct 27, 2025
    risk 0.28cvss 4.3epss 0.00

    A security flaw has been discovered in chatwoot up to 4.7.0. This issue affects some unknown processing of the file app/javascript/shared/components/IframeLoader.vue of the component Admin Interface. The manipulation of the argument Link results in cross site scripting. The…

  • CVE-2025-12244MedOct 27, 2025
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was determined in code-projects Simple E-Banking System 1.0. This affects an unknown part of the file /eBank/register.php. Executing manipulation of the argument Username can lead to cross site scripting. The attack may be launched remotely. The exploit has been…

  • CVE-2025-31994MedOct 13, 2025
    risk 0.28cvss 4.3epss 0.00

    HCL Unica Campaign 12.1.10 is vulnerable to Reflected Cross-Site Scripting (XSS) where an attacker injects malicious script into an HTTP request, which is then reflected unsafely in the server's immediate response to the victim's browser, executing the script as if it originated…

  • CVE-2025-11512MedOct 9, 2025
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was found in code-projects Voting System 1.0. Affected by this issue is some unknown functionality of the file /admin/voters_add.php. The manipulation of the argument Firstname/Lastname/Platform results in cross site scripting. The attack can be executed…

  • CVE-2025-11435MedOct 8, 2025
    risk 0.28cvss 4.3epss 0.00

    A security vulnerability has been detected in JhumanJ OpnForm up to 1.9.3. Affected by this vulnerability is an unknown functionality of the file /show/submissions. The manipulation leads to cross site scripting. The attack can be initiated remotely. The exploit has been…

  • CVE-2025-11390MedOct 7, 2025
    risk 0.28cvss 4.3epss 0.00

    A weakness has been identified in PHPGurukul Cyber Cafe Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /search.php of the component POST Parameter Handler. Executing a manipulation of the argument searchdata can lead to cross site…

  • CVE-2025-11306MedOct 5, 2025
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was found in qianfox FoxCMS up to 1.2. This affects an unknown part of the file /index.php/Search of the component Search Page. The manipulation of the argument keyword results in cross site scripting. The attack can be executed remotely. The exploit has been…

  • CVE-2025-11291MedOct 5, 2025
    risk 0.28cvss 4.3epss 0.00

    A security flaw has been discovered in ixmaps website2017 up to 0c71cffa0162186bc057a76766bc97e9f5a3a2d0. This impacts an unknown function of the file /map.php of the component HTTP GET Request Handler. Performing manipulation of the argument trid results in cross site…

  • CVE-2025-11278MedOct 5, 2025
    risk 0.28cvss 4.3epss 0.00

    A security vulnerability has been detected in AllStarLink Supermon up to 6.2. This vulnerability affects unknown code of the component AllMon2. The manipulation leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed publicly and may…