VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (22,697)

page 617 of 1,135
  • CVE-2026-7110LowApr 27, 2026
    risk 0.23cvss 3.5epss 0.00

    A flaw has been found in code-projects Invoice System in Laravel 1.0. Affected is an unknown function of the file /item. Executing a manipulation of the argument item name/description can lead to cross site scripting. It is possible to launch the attack remotely. The exploit has…

  • CVE-2026-6990LowApr 25, 2026
    risk 0.23cvss 3.5epss 0.00

    A vulnerability was found in projeto-siga siga 11.0.3.18. The affected element is an unknown function of the file /sigawf/app/responsavel/novo. Performing a manipulation of the argument Nome/Descrição results in cross site scripting. The attack can be initiated remotely. The…

  • CVE-2026-4512LowApr 23, 2026
    risk 0.23cvss 3.5epss 0.00

    The reCaptcha by WebDesignBy WordPress plugin before 2.0 does not sanitize or escape the Site Key setting before outputting it in a JavaScript string context via the grecaptcha_js() function. This allows administrators on multisite installations (who do not have the…

  • CVE-2026-6745LowApr 21, 2026
    risk 0.23cvss 3.5epss 0.00

    A vulnerability was determined in Bagisto up to 2.3.15. Affected by this vulnerability is an unknown functionality of the component Custom Scripts Handler. This manipulation causes cross site scripting. Remote exploitation of the attack is possible. The exploit has been publicly…

  • CVE-2026-6743LowApr 21, 2026
    risk 0.23cvss 3.5epss 0.00

    A vulnerability has been found in WebSystems WebTOTUM 2026. This impacts an unknown function of the component Calendar. The manipulation leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading…

  • CVE-2026-6648LowApr 20, 2026
    risk 0.23cvss 3.5epss 0.00

    A vulnerability was found in Qibo CMS 1.0. Affected by this vulnerability is an unknown functionality of the component Internal Message Module. Performing a manipulation results in cross site scripting. The attack can be initiated remotely. The exploit has been made public and…

  • CVE-2026-6633LowApr 20, 2026
    risk 0.23cvss 3.5epss 0.00

    A security flaw has been discovered in Yifang CMS up to 2.0.5. The impacted element is the function store of the file plugins/yifang_backend_account/logic/admin/L_rbac_admin.php of the component Extended Management Module. The manipulation of the argument Account results in…

  • CVE-2026-6619LowApr 20, 2026
    risk 0.23cvss 3.5epss 0.00

    A vulnerability has been found in langgenius dify up to 1.13.3. Impacted is the function openInNewTab of the file web/app/components/base/image-uploader/image-preview.tsx of the component ImagePreview. The manipulation of the argument filename leads to cross site scripting. The…

  • CVE-2024-7083LowApr 20, 2026
    risk 0.23cvss 3.5epss 0.00

    The Email Encoder WordPress plugin before 2.3.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in…

  • CVE-2026-6600LowApr 20, 2026
    risk 0.23cvss 3.5epss 0.00

    A flaw has been found in langflow-ai langflow up to 1.8.3. This affects an unknown function of the file src/frontend/src/modals/IOModal/components/chatView/chatMessage/components/edit-message.tsx of the component Frontend React Component Rendering. Executing a manipulation can…

  • CVE-2026-6593LowApr 20, 2026
    risk 0.23cvss 3.5epss 0.00

    A vulnerability was found in ComfyUI up to 0.13.0. Affected by this issue is some unknown functionality of the file server.py of the component View Endpoint. Performing a manipulation results in cross site scripting. The attack is possible to be carried out remotely. The exploit…

  • CVE-2026-6592LowApr 20, 2026
    risk 0.23cvss 3.5epss 0.00

    A vulnerability has been found in ComfyUI up to 0.13.0. Affected by this vulnerability is the function getuserdata of the file app/user_manager.py of the component userdata Endpoint. Such manipulation leads to cross site scripting. The attack can be executed remotely. The…

  • CVE-2026-6493LowApr 17, 2026
    risk 0.23cvss 3.5epss 0.00

    A flaw has been found in lukevella rallly up to 4.7.4. This affects an unknown function of the file apps/web/src/app/[locale]/(auth)/reset-password/components/reset-password-form.tsx of the component Reset Password Handler. Executing a manipulation of the argument redirectTo can…

  • CVE-2026-6486LowApr 17, 2026
    risk 0.23cvss 3.5epss 0.00

    A vulnerability was detected in classroombookings up to 2.17.0. This impacts the function read of the file crbs-core/application/views/layout.php of the component User Display Name Handler. The manipulation of the argument displayname results in cross site scripting. The attack…

  • CVE-2025-15632LowApr 13, 2026
    risk 0.23cvss 3.5epss 0.00

    A vulnerability has been found in 1Panel-dev MaxKB up to 2.4.2. Impacted is an unknown function of the file ui/src/chat.ts of the component MdPreview. Such manipulation leads to cross site scripting. The attack can be executed remotely. The exploit has been disclosed to the…

  • CVE-2026-6162LowApr 13, 2026
    risk 0.23cvss 3.5epss 0.00

    A vulnerability has been found in PHPGurukul Company Visitor Management System 2.0. This impacts an unknown function of the file /bwdates-reports-details.php. The manipulation of the argument fromdate leads to cross site scripting. The attack is possible to be carried out…

  • CVE-2026-6107LowApr 12, 2026
    risk 0.23cvss 3.5epss 0.00

    A flaw has been found in 1Panel-dev MaxKB up to 2.6.1. This issue affects some unknown processing of the file apps/common/middleware/chat_headers_middleware.py of the component ChatHeadersMiddleware. This manipulation of the argument Name causes cross site scripting. Remote…

  • CVE-2026-6106LowApr 11, 2026
    risk 0.23cvss 3.5epss 0.00

    A vulnerability was detected in 1Panel-dev MaxKB up to 2.2.1. This vulnerability affects the function StaticHeadersMiddleware of the file apps/common/middleware/static_headers_middleware.py of the component Public Chat Interface. The manipulation of the argument Name results in…

  • CVE-2026-5810LowApr 8, 2026
    risk 0.23cvss 3.5epss 0.00

    A flaw has been found in SourceCodester Sales and Inventory System 1.0. Affected is an unknown function of the file /delete.php of the component GET Parameter Handler. This manipulation of the argument ID causes cross site scripting. Remote exploitation of the attack is…

  • CVE-2026-5806LowApr 8, 2026
    risk 0.23cvss 3.5epss 0.00

    A security vulnerability has been detected in code-projects Easy Blog Site 1.0. This affects an unknown function of the file /posts/update.php. The manipulation of the argument postTitle leads to cross site scripting. The attack may be initiated remotely. The exploit has been…