VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (22,697)

page 618 of 1,135
  • CVE-2026-5568LowApr 5, 2026
    risk 0.23cvss 3.5epss 0.00

    A vulnerability has been found in Akaunting up to 3.1.21. This issue affects some unknown processing of the component Invoice/Billing. The manipulation of the argument notes leads to cross site scripting. The attack is possible to be carried out remotely. The exploit has been…

  • CVE-2026-5468LowApr 3, 2026
    risk 0.23cvss 3.5epss 0.00

    A security flaw has been discovered in Casdoor 2.356.0. This affects the function dangerouslySetInnerHTML. Performing a manipulation of the argument formCss/formCssMobile/formSideHtml results in cross site scripting. The attack can be initiated remotely. The exploit has been…

  • CVE-2026-5332LowApr 2, 2026
    risk 0.23cvss 3.5epss 0.00

    A vulnerability was identified in Xiaopi Panel 1.0.0. This vulnerability affects unknown code of the file /demo.php of the component WAF Firewall. The manipulation of the argument param leads to cross site scripting. Remote exploitation of the attack is possible. The exploit is…

  • CVE-2026-5325LowApr 2, 2026
    risk 0.23cvss 3.5epss 0.00

    A vulnerability was determined in SourceCodester Simple Customer Relationship Management System 1.0. This issue affects some unknown processing of the file /create-ticket.php of the component Create Ticket. This manipulation of the argument Description causes cross site…

  • CVE-2026-5254LowApr 1, 2026
    risk 0.23cvss 3.5epss 0.00

    A security vulnerability has been detected in welovemedia FFmate up to 2.0.15. Affected by this issue is some unknown functionality of the file /ui/app/components/AppJsonTreeView.vue of the component Webhook Handler. The manipulation leads to cross site scripting. The attack may…

  • CVE-2026-5253LowApr 1, 2026
    risk 0.23cvss 3.5epss 0.00

    A weakness has been identified in bufanyun HotGo 1.0/2.0. Affected by this vulnerability is an unknown functionality of the file /web/src/layout/components/Header/MessageList.vue of the component editNotice Endpoint. Executing a manipulation can lead to cross site scripting. The…

  • CVE-2026-5252LowApr 1, 2026
    risk 0.23cvss 3.5epss 0.00

    A security flaw has been discovered in z-9527 admin 1.0/2.0. Affected is an unknown function of the file /server/routes/message.js of the component Message Create Endpoint. Performing a manipulation results in cross site scripting. The attack can be initiated remotely. The…

  • CVE-2026-5249LowApr 1, 2026
    risk 0.23cvss 3.5epss 0.00

    A vulnerability was found in gougucms 4.08.18. This impacts an unknown function of the file \gougucms-master\app\admin\view\user\record.html of the component Record Endpoint. Performing a manipulation of the argument value.content results in cross site scripting. It is possible…

  • CVE-2026-4995LowMar 28, 2026
    risk 0.23cvss 3.5epss 0.00

    A vulnerability was determined in wandb OpenUI up to 1.0. Affected by this vulnerability is an unknown functionality of the file frontend/public/annotator/index.html of the component Window Message Event Handler. This manipulation causes cross site scripting. The attack can be…

  • CVE-2026-4991LowMar 27, 2026
    risk 0.23cvss 3.5epss 0.00

    A vulnerability was detected in QDOCS Smart School Management System up to 7.2. The impacted element is an unknown function of the file /admin/enquiry of the component Admission Enquiry Module. Performing a manipulation of the argument Note results in cross site scripting. The…

  • CVE-2026-4973LowMar 27, 2026
    risk 0.23cvss 3.5epss 0.00

    A vulnerability was detected in SourceCodester Online Quiz System up to 1.0. Affected by this vulnerability is an unknown functionality of the file endpoint/add-question.php. Performing a manipulation of the argument quiz_question results in cross site scripting. It is possible…

  • CVE-2026-4969LowMar 27, 2026
    risk 0.23cvss 3.5epss 0.00

    A vulnerability was identified in code-projects Social Networking Site 1.0. The impacted element is an unknown function of the file /home.php of the component Alert Handler. The manipulation of the argument content leads to cross site scripting. Remote exploitation of the attack…

  • CVE-2026-4835LowMar 26, 2026
    risk 0.23cvss 3.5epss 0.00

    A security vulnerability has been detected in code-projects Accounting System 1.0. Impacted is an unknown function of the file /my_account/add_costumer.php of the component Web Application Interface. Such manipulation of the argument costumer_name leads to cross site scripting.…

  • CVE-2026-4626LowMar 24, 2026
    risk 0.23cvss 3.5epss 0.00

    A vulnerability has been found in projectworlds Lawyer Management System 1.0. This impacts an unknown function of the file /lawyer_booking.php. The manipulation of the argument Description leads to cross site scripting. The attack may be initiated remotely. The exploit has been…

  • CVE-2026-4596LowMar 23, 2026
    risk 0.23cvss 3.5epss 0.00

    A vulnerability was identified in projectworlds Lawyer Management System 1.0. This issue affects some unknown processing of the file /lawyers.php. The manipulation of the argument first_Name leads to cross site scripting. The attack may be initiated remotely. The exploit is…

  • CVE-2026-4495LowMar 20, 2026
    risk 0.23cvss 3.5epss 0.00

    A security flaw has been discovered in atjiu pybbs 6.0.0. This impacts the function create of the file src/main/java/co/yiiu/pybbs/controller/api/CommentApiController.java. The manipulation results in cross site scripting. It is possible to launch the attack remotely. The…

  • CVE-2026-4494LowMar 20, 2026
    risk 0.23cvss 3.5epss 0.00

    A vulnerability was identified in atjiu pybbs 6.0.0. This affects the function create of the file src/main/java/co/yiiu/pybbs/controller/api/TopicApiController.java. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. The exploit is…

  • CVE-2026-4355LowMar 18, 2026
    risk 0.23cvss 3.5epss 0.00

    A vulnerability was detected in Portabilis i-Educar 2.11. This impacts an unknown function of the file /intranet/educar_servidor_curso_lst.php of the component Endpoint. Performing a manipulation of the argument Name results in cross site scripting. The attack may be initiated…

  • CVE-2026-4354LowMar 18, 2026
    risk 0.23cvss 3.5epss 0.00

    A vulnerability was identified in TRENDnet TEW-824DRU 1.010B01/1.04B01. The impacted element is the function sub_420A78 of the file apply_sec.cgi of the component Web Interface. Such manipulation of the argument Language leads to cross site scripting. It is possible to launch…

  • CVE-2026-4186LowMar 16, 2026
    risk 0.23cvss 3.5epss 0.00

    A vulnerability was determined in UEditor up to 1.4.3.2. This issue affects some unknown processing of the file php/controller.php?action=uploadimage of the component JSONP Callback Handler. This manipulation of the argument callback causes cross site scripting. The attack can…