VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (22,697)

page 615 of 1,135
  • CVE-2026-2722MedMar 7, 2026
    risk 0.24cvss 4.8epss 0.00

    The Stock Ticker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.26.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…

  • CVE-2026-2721MedMar 7, 2026
    risk 0.24cvss 4.8epss 0.00

    The MailArchiver plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 4.4.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…

  • CVE-2025-15022MedJan 5, 2026
    risk 0.24cvss epss 0.00

    Action captions in Vaadin accept HTML by default but were not sanitized, potentially allowing Cross-site Scripting (XSS) if caption content is derived from user input. In Vaadin Framework 7 and 8, the Action class is a general-purpose class that may be used by multiple…

  • CVE-2025-64758MedNov 17, 2025
    risk 0.24cvss 4.8epss 0.00

    @dependencytrack/frontend is a Single Page Application (SPA) used in Dependency-Track, an open source Component Analysis platform that allows organizations to identify and reduce risk in the software supply chain. Since version 4.12.0, Dependency-Track users with the…

  • CVE-2025-54476MedSep 30, 2025
    risk 0.24cvss epss 0.00

    Improper handling of input could lead to an XSS vector in the checkAttribute method of the input filter framework class.

  • CVE-2025-9910MedSep 11, 2025
    risk 0.24cvss 4.7epss 0.00

    Versions of the package jsondiffpatch before 0.7.2 are vulnerable to Cross-site Scripting (XSS) via HtmlFormatter::nodeBegin. An attacker can inject malicious scripts into HTML payloads that may lead to code execution if untrusted payloads were used as source for the diff, and…

  • CVE-2025-31483MedApr 3, 2025
    risk 0.24cvss epss 0.00

    Miniflux is a feed reader. Due to a weak Content Security Policy on the /proxy/* route, an attacker can bypass the CSP of the media proxy and execute cross-site scripting when opening external images in a new tab/window. To mitigate the vulnerability, the CSP for the media proxy…

  • CVE-2025-25287MedFeb 13, 2025
    risk 0.24cvss 4.7epss 0.00

    Lakeus is a simple skin made for MediaWiki. Starting in version 1.0.8 and prior to versions 1.3.1+REL1.39, 1.3.1+REL1.42, and 1.4.0, Lakeus is vulnerable to store cross-site scripting via malicious system messages, though editing the messages requires high privileges. Those with…

  • CVE-2025-23210MedFeb 3, 2025
    risk 0.24cvss epss 0.00

    phpoffice/phpspreadsheet is a pure PHP library for reading and writing spreadsheet files. Affected versions have been found to have a Bypass of the Cross-site Scripting (XSS) sanitizer using the javascript protocol and special characters. This issue has been addressed in…

  • CVE-2024-48461MedOct 29, 2024
    risk 0.24cvss 4.8epss 0.00

    Cross Site Scripting vulnerability in TeslaLogger Admin Panel before v.1.59.6 allows a remote attacker to execute arbitrary code via the New Journey field.

  • CVE-2024-45793MedSep 20, 2024
    risk 0.24cvss 4.8epss 0.00

    Confidant is a open source secret management service that provides user-friendly storage and access to secrets. The following endpoints are subject to a cross site scripting vulnerability: GET /v1/credentials, GET /v1/credentials/, GET /v1/archive/credentials/, GET…

  • CVE-2024-37879MedSep 20, 2024
    risk 0.24cvss 4.8epss 0.00

    Improper input validation in /admin/config/save in User-friendly SVN (USVN) before v1.0.12 and below allows administrators to execute arbitrary code via the fields "siteTitle", "siteIco" and "siteLogo".

  • CVE-2024-6288MedJun 28, 2024
    risk 0.24cvss 4.7epss 0.03

    The Conversios – Google Analytics 4 (GA4), Meta Pixel & more Via Google Tag Manager For WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘tiktok_user_id’ parameter in all versions up to, and including, 7.1.0 due to insufficient input…

  • CVE-2024-35621MedMay 28, 2024
    risk 0.24cvss 4.8epss 0.00

    A cross-site scripting (XSS) vulnerability in the Edit function of Formwork before 1.13.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Content field.

  • CVE-2024-4895MedMay 23, 2024
    risk 0.24cvss 4.7epss 0.03

    The wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the CSV import functionality in all versions up to, and including, 3.4.2.12 due to insufficient input sanitization and output…

  • CVE-2024-34349MedMay 14, 2024
    risk 0.24cvss 4.8epss 0.00

    Sylius is an open source eCommerce platform. Prior to 1.12.16 and 1.13.1, there is a possibility to execute javascript code in the Admin panel. In order to perform an XSS attack input a script into Name field in which of the resources: Taxons, Products, Product Options or…

  • CVE-2024-1720MedMar 7, 2024
    risk 0.24cvss 4.7epss 0.02

    The User Registration – Custom Registration Form, Login Form, and User Profile WordPress Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Display Name' parameter in all versions up to, and including, 3.1.4 due to insufficient input sanitization…

  • CVE-2023-31045MedApr 24, 2023
    risk 0.24cvss 4.8epss 0.00

    A stored Cross-site scripting (XSS) issue in Text Editors and Formats in Backdrop CMS before 1.24.2 allows remote attackers to inject arbitrary web script or HTML via the name parameter. When a user is editing any content type (e.g., page, post, or card) as an admin, the stored…

  • CVE-2017-16842MedNov 16, 2017
    risk 0.24cvss 4.8epss 0.00

    Cross-site scripting (XSS) vulnerability in admin/google_search_console/class-gsc-table.php in the Yoast SEO plugin before 5.8.0 for WordPress allows remote attackers to inject arbitrary web script or HTML.

  • CVE-2017-16758MedNov 9, 2017
    risk 0.24cvss 4.8epss 0.00

    Cross-site scripting (XSS) vulnerability in admin/partials/uif-access-token-display.php in the Ultimate Instagram Feed plugin before 1.3 for WordPress allows remote attackers to inject arbitrary web script or HTML via the "access_token" parameter.