VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (22,695)

page 622 of 1,135
  • CVE-2025-13182LowNov 14, 2025
    risk 0.23cvss 3.5epss 0.00

    A vulnerability was identified in pojoin h3blog 1.0. The impacted element is an unknown function of the file /admin/cms/category/addtitle. The manipulation of the argument Title leads to cross site scripting. The attack can be initiated remotely. The exploit is publicly…

  • CVE-2025-13181LowNov 14, 2025
    risk 0.23cvss 3.5epss 0.00

    A vulnerability was determined in pojoin h3blog 1.0. The affected element is an unknown function of the file /admin/cms/material/add. Executing a manipulation of the argument Name can lead to cross site scripting. It is possible to launch the attack remotely. The exploit has…

  • CVE-2025-13180LowNov 14, 2025
    risk 0.23cvss 3.5epss 0.00

    A vulnerability was found in Bdtask/CodeCanyon Wholesale Inventory Control and Inventory Management System up to 20250320. Impacted is an unknown function of the file /edit_profile. Performing manipulation of the argument first_name/last_name results in basic cross site…

  • CVE-2025-13178LowNov 14, 2025
    risk 0.23cvss 3.5epss 0.00

    A flaw has been found in Bdtask/CodeCanyon SalesERP up to 20250728. This vulnerability affects unknown code of the file /edit_profile of the component User Profile Handler. This manipulation of the argument first_name/last_name causes basic cross site scripting. The attack is…

  • CVE-2025-64744LowNov 13, 2025
    risk 0.23cvss 3.5epss 0.00

    OpenObserve is a cloud-native observability platform. In versions up to and including 0.16.1, when creating or renaming an organization with HTML in the name, the markup is rendered inside the invitation email. This indicates that user-controlled input is inserted into the email…

  • CVE-2025-12546LowOct 31, 2025
    risk 0.23cvss 3.5epss 0.00

    A vulnerability was determined in LogicalDOC Community Edition up to 9.2.1. This affects an unknown part of the component API Key creation UI. This manipulation causes cross site scripting. Remote exploitation of the attack is possible. The exploit has been publicly disclosed…

  • CVE-2025-12269LowOct 27, 2025
    risk 0.23cvss 3.5epss 0.00

    A vulnerability was found in LearnHouse up to 98dfad76aad70711a8113f6c1fdabfccf10509ca. The affected element is an unknown function of the file /dash/org/settings/previews of the component Account Setting Page. The manipulation results in cross site scripting. It is possible to…

  • CVE-2025-12264LowOct 27, 2025
    risk 0.23cvss 3.5epss 0.00

    A security flaw has been discovered in Wisencode up to 20251012. Affected by this vulnerability is an unknown functionality of the file /support-ticket/create of the component Create Support Ticket Handler. The manipulation of the argument Message results in cross site…

  • CVE-2025-12251LowOct 27, 2025
    risk 0.23cvss 3.5epss 0.00

    A vulnerability has been found in OpenWGA 7.11.12 Build 737. This impacts an unknown function of the component Admin UI. The manipulation leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor…

  • CVE-2025-12227LowOct 27, 2025
    risk 0.23cvss 3.5epss 0.00

    A vulnerability was determined in projectworlds Gate Pass Management System 1.0. The affected element is an unknown function of the file /add-pass.php. Executing a manipulation can lead to cross site scripting. The attack can be executed remotely. The exploit has been publicly…

  • CVE-2025-12224LowOct 27, 2025
    risk 0.23cvss 3.5epss 0.00

    A flaw has been found in Iqbolshoh php-business-website up to 10677743a8dfc281f85291a27cf63a0bce043c24. This vulnerability affects unknown code of the file admin/contact.php. This manipulation of the argument twitter causes cross site scripting. The attack may be initiated…

  • CVE-2025-11946LowOct 19, 2025
    risk 0.23cvss 3.5epss 0.00

    A security flaw has been discovered in LogicalDOC Community Edition up to 9.2.1. This issue affects some unknown processing of the file /frontend.jsp of the component Add Contact Page. Performing manipulation of the argument First Name/Last Name/Company/Address/Phone/Mobile…

  • CVE-2025-11945LowOct 19, 2025
    risk 0.23cvss 3.5epss 0.00

    A vulnerability was identified in toeverything AFFiNE up to 0.24.1. This vulnerability affects unknown code of the component Avatar Upload Image Endpoint. Such manipulation leads to cross site scripting. The attack may be launched remotely. The exploit is publicly available and…

  • CVE-2025-11851LowOct 16, 2025
    risk 0.23cvss 3.5epss 0.00

    A vulnerability has been found in Apeman ID71 EN75.8.53.20. The affected element is an unknown function of the file /set_alias.cgi. Such manipulation of the argument alias leads to cross site scripting. The attack can be executed remotely. The exploit has been disclosed to the…

  • CVE-2025-11433LowOct 8, 2025
    risk 0.23cvss 3.5epss 0.00

    A security flaw has been discovered in itsourcecode Leave Management System 1.0. This impacts the function redirect of the file /module/employee/controller.php?action=reset of the component Query Parameter Handler. Performing a manipulation of the argument ID results in cross…

  • CVE-2025-11421LowOct 8, 2025
    risk 0.23cvss 3.5epss 0.00

    A flaw has been found in code-projects Voting System 1.0. The affected element is an unknown function of the file /admin/candidates_edit.php. This manipulation of the argument Firstname/Lastname/Platform causes cross site scripting. Remote exploitation of the attack is possible.…

  • CVE-2025-11332LowOct 6, 2025
    risk 0.23cvss 3.5epss 0.00

    A vulnerability was determined in CmsEasy up to 7.7.7. This affects an unknown function in the library lib/inc/view.php of the component URL Handler. Executing a manipulation of the argument PHP_SELF can lead to cross site scripting. The attack may be launched remotely. The…

  • CVE-2025-11308LowOct 5, 2025
    risk 0.23cvss 3.5epss 0.00

    A vulnerability was identified in Vanderlande Baggage 360 7.0.0. This issue affects some unknown processing of the file /api-addons/v1/messages. Such manipulation of the argument Message leads to cross site scripting. The attack may be performed from remote. The exploit is…

  • CVE-2025-11276LowOct 5, 2025
    risk 0.23cvss 3.5epss 0.00

    A security flaw has been discovered in Rebuild up to 4.1.3. Affected by this issue is some unknown functionality of the component Comment/Guestbook. Performing manipulation results in cross site scripting. It is possible to initiate the attack remotely. Upgrading to version…

  • CVE-2025-11137LowSep 29, 2025
    risk 0.23cvss 3.5epss 0.00

    A vulnerability has been found in Gstarsoft GstarCAD up to 9.4.0. This affects an unknown function of the component File Renaming Handler. The manipulation leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may…