CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Description
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85
CVEs mapped to this weakness (46,607)
page 61 of 2,331| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-30563 | Hig | 0.53 | 8.2 | 0.00 | Jul 13, 2023 | A malicious file could be uploaded into a System Manager User Import Function resulting in a hijacked session. | ||
| CVE-2023-35335 | Hig | 0.53 | 8.2 | 0.01 | Jul 11, 2023 | Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | ||
| CVE-2023-33171 | Hig | 0.53 | 8.2 | 0.01 | Jul 11, 2023 | Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | ||
| CVE-2023-28800 | Hig | 0.53 | 8.1 | 0.01 | Jun 22, 2023 | When using local accounts for administration, the redirect url parameter was not encoded correctly, allowing for an XSS attack providing admin login. | ||
| CVE-2023-33991 | Hig | 0.53 | 8.2 | 0.00 | Jun 13, 2023 | SAP UI5 Variant Management - versions SAP_UI 750, SAP_UI 754, SAP_UI 755, SAP_UI 756, SAP_UI 757, UI_700 200, does not sufficiently encode user-controlled inputs on reading data from the server, resulting in Stored Cross-Site Scripting (Stored XSS) vulnerability. After… | ||
| CVE-2023-32686 | Hig | 0.53 | 8.1 | 0.00 | May 27, 2023 | Kiwi TCMS is an open source test management system for both manual and automated testing. Kiwi TCMS allows users to upload attachments to test plans, test cases, etc. Earlier versions of Kiwi TCMS had introduced upload validators in order to prevent potentially dangerous files… | ||
| CVE-2023-0835 | Hig | 0.53 | 8.2 | 0.01 | Apr 4, 2023 | markdown-pdf version 11.0.0 allows an external attacker to remotely obtain arbitrary local files. This is possible because the application does not validate the Markdown content entered by the user. | ||
| CVE-2023-27089 | Hig | 0.53 | 8.2 | 0.00 | Apr 4, 2023 | Cross Site Scripting vulnerability found in Ehuacui BBS allows attackers to cause a denial of service via a crafted payload in the login parameter. | ||
| CVE-2023-23467 | Hig | 0.53 | 8.1 | 0.00 | Feb 15, 2023 | Media CP Media Control Panel latest version. Reflected XSS possible through unspecified endpoint. | ||
| CVE-2023-21806 | Hig | 0.53 | 8.2 | 0.01 | Feb 14, 2023 | Power BI Report Server Spoofing Vulnerability | ||
| CVE-2023-0776 | Hig | 0.53 | 8.1 | 0.01 | Feb 11, 2023 | Baicells Nova 436Q, Nova 430E, Nova 430I, and Neutrino 430 LTE TDD eNodeB devices with firmware through QRTB 2.12.7 are vulnerable to remote shell code exploitation via HTTP command injections. Commands are executed using pre-login execution and executed with root permissions.… | ||
| CVE-2023-24508 | Hig | 0.53 | 8.1 | 0.02 | Jan 26, 2023 | Baicells Nova 227, Nova 233, and Nova 243 LTE TDD eNodeB and Nova 246 devices with firmware through RTS/RTD 3.6.6 are vulnerable to remote shell code exploitation via HTTP command injections. Commands are executed using pre-login execution and executed with root permissions. The… | ||
| CVE-2023-22491 | Hig | 0.53 | 8.1 | 0.01 | Jan 13, 2023 | Gatsby is a free and open source framework based on React that helps developers build websites and apps. The gatsby-transformer-remark plugin prior to versions 5.25.1 and 6.3.2 passes input through to the `gray-matter` npm package, which is vulnerable to JavaScript injection in… | ||
| CVE-2022-3033 | Hig | 0.53 | 8.1 | 0.01 | Dec 22, 2022 | If a Thunderbird user replied to a crafted HTML email containing a meta tag, with the meta tag having the http-equiv="refresh" attribute, and the content attribute specifying an URL, then Thunderbird started a network request to that URL,… | ||
| CVE-2022-39017 | Hig | 0.53 | 8.2 | 0.00 | Oct 31, 2022 | Improper input validation and output encoding in all comments fields, in M-Files Hubshare before 3.3.10.9 allows authenticated attackers to introduce cross-site scripting attacks via specially crafted comments. | ||
| CVE-2022-39016 | Hig | 0.53 | 8.2 | 0.01 | Oct 31, 2022 | Javascript injection in PDFtron in M-Files Hubshare before 3.3.10.9 allows authenticated attackers to perform an account takeover via a crafted PDF upload. | ||
| CVE-2022-27494 | Hig | 0.53 | 8.2 | 0.01 | Oct 21, 2022 | Aethon TUG Home Base Server versions prior to version 24 are affected by un unauthenticated attacker who can freely access hashed user credentials. | ||
| CVE-2022-1059 | Hig | 0.53 | 8.2 | 0.01 | Oct 21, 2022 | Aethon TUG Home Base Server versions prior to version 24 are affected by un unauthenticated attacker who can freely access hashed user credentials. | ||
| CVE-2022-30571 | Hig | 0.53 | 8.1 | 0.00 | Aug 2, 2022 | The iWay Service Manager Console component of TIBCO Software Inc.'s TIBCO iWay Service Manager contains easily exploitable Reflected Cross Site Scripting (XSS) vulnerabilities that allow a low privileged attacker with network access to execute scripts targeting the affected… | ||
| CVE-2022-22999 | Hig | 0.53 | 8.2 | 0.00 | Jul 25, 2022 | Western Digital My Cloud devices are vulnerable to a cross side scripting vulnerability that can allow a malicious user with elevated privileges access to drives being backed up to construct and inject JavaScript payloads into an authenticated user's browser. As a result, it may… |
- risk 0.53cvss 8.2epss 0.00
A malicious file could be uploaded into a System Manager User Import Function resulting in a hijacked session.
- risk 0.53cvss 8.2epss 0.01
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
- risk 0.53cvss 8.2epss 0.01
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
- risk 0.53cvss 8.1epss 0.01
When using local accounts for administration, the redirect url parameter was not encoded correctly, allowing for an XSS attack providing admin login.
- risk 0.53cvss 8.2epss 0.00
SAP UI5 Variant Management - versions SAP_UI 750, SAP_UI 754, SAP_UI 755, SAP_UI 756, SAP_UI 757, UI_700 200, does not sufficiently encode user-controlled inputs on reading data from the server, resulting in Stored Cross-Site Scripting (Stored XSS) vulnerability. After…
- risk 0.53cvss 8.1epss 0.00
Kiwi TCMS is an open source test management system for both manual and automated testing. Kiwi TCMS allows users to upload attachments to test plans, test cases, etc. Earlier versions of Kiwi TCMS had introduced upload validators in order to prevent potentially dangerous files…
- risk 0.53cvss 8.2epss 0.01
markdown-pdf version 11.0.0 allows an external attacker to remotely obtain arbitrary local files. This is possible because the application does not validate the Markdown content entered by the user.
- risk 0.53cvss 8.2epss 0.00
Cross Site Scripting vulnerability found in Ehuacui BBS allows attackers to cause a denial of service via a crafted payload in the login parameter.
- risk 0.53cvss 8.1epss 0.00
Media CP Media Control Panel latest version. Reflected XSS possible through unspecified endpoint.
- risk 0.53cvss 8.2epss 0.01
Power BI Report Server Spoofing Vulnerability
- risk 0.53cvss 8.1epss 0.01
Baicells Nova 436Q, Nova 430E, Nova 430I, and Neutrino 430 LTE TDD eNodeB devices with firmware through QRTB 2.12.7 are vulnerable to remote shell code exploitation via HTTP command injections. Commands are executed using pre-login execution and executed with root permissions.…
- risk 0.53cvss 8.1epss 0.02
Baicells Nova 227, Nova 233, and Nova 243 LTE TDD eNodeB and Nova 246 devices with firmware through RTS/RTD 3.6.6 are vulnerable to remote shell code exploitation via HTTP command injections. Commands are executed using pre-login execution and executed with root permissions. The…
- risk 0.53cvss 8.1epss 0.01
Gatsby is a free and open source framework based on React that helps developers build websites and apps. The gatsby-transformer-remark plugin prior to versions 5.25.1 and 6.3.2 passes input through to the `gray-matter` npm package, which is vulnerable to JavaScript injection in…
- risk 0.53cvss 8.1epss 0.01
If a Thunderbird user replied to a crafted HTML email containing a meta tag, with the meta tag having the http-equiv="refresh" attribute, and the content attribute specifying an URL, then Thunderbird started a network request to that URL,…
- risk 0.53cvss 8.2epss 0.00
Improper input validation and output encoding in all comments fields, in M-Files Hubshare before 3.3.10.9 allows authenticated attackers to introduce cross-site scripting attacks via specially crafted comments.
- risk 0.53cvss 8.2epss 0.01
Javascript injection in PDFtron in M-Files Hubshare before 3.3.10.9 allows authenticated attackers to perform an account takeover via a crafted PDF upload.
- risk 0.53cvss 8.2epss 0.01
Aethon TUG Home Base Server versions prior to version 24 are affected by un unauthenticated attacker who can freely access hashed user credentials.
- risk 0.53cvss 8.2epss 0.01
Aethon TUG Home Base Server versions prior to version 24 are affected by un unauthenticated attacker who can freely access hashed user credentials.
- risk 0.53cvss 8.1epss 0.00
The iWay Service Manager Console component of TIBCO Software Inc.'s TIBCO iWay Service Manager contains easily exploitable Reflected Cross Site Scripting (XSS) vulnerabilities that allow a low privileged attacker with network access to execute scripts targeting the affected…
- risk 0.53cvss 8.2epss 0.00
Western Digital My Cloud devices are vulnerable to a cross side scripting vulnerability that can allow a malicious user with elevated privileges access to drives being backed up to construct and inject JavaScript payloads into an authenticated user's browser. As a result, it may…