VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (22,695)

page 624 of 1,135
  • CVE-2025-10332LowSep 13, 2025
    risk 0.23cvss 3.5epss 0.00

    A vulnerability was found in cdevroe unmark up to 1.9.3. Impacted is an unknown function of the file application/views/marks/info.php. Performing manipulation of the argument Title results in cross site scripting. The attack is possible to be carried out remotely. The exploit…

  • CVE-2025-10331LowSep 13, 2025
    risk 0.23cvss 3.5epss 0.00

    A vulnerability has been found in cdevroe unmark up to 1.9.3. This issue affects some unknown processing of the file /application/controllers/Marks.php. Such manipulation of the argument Title leads to cross site scripting. The attack can be executed remotely. The exploit has…

  • CVE-2025-10255LowSep 11, 2025
    risk 0.23cvss 3.5epss 0.00

    A vulnerability was determined in Ascensio System SIA OnlyOffice up to 12.7.0. Impacted is an unknown function of the file /Products/Projects/Messages.aspx of the component Comment Handler. Executing manipulation can lead to cross site scripting. The attack may be launched…

  • CVE-2025-10254LowSep 11, 2025
    risk 0.23cvss 3.5epss 0.00

    A vulnerability was found in Ascensio System SIA OnlyOffice up to 12.7.0. This issue affects some unknown processing of the file /Products/Projects/Messages.aspx of the component SVG Image Handler. Performing manipulation results in cross site scripting. The attack may be…

  • CVE-2025-10253LowSep 11, 2025
    risk 0.23cvss 3.5epss 0.00

    A vulnerability has been found in openDCIM 23.04. This vulnerability affects unknown code of the file /scripts/uploadifive.php of the component SVG File Handler. Such manipulation of the argument Filedata leads to cross site scripting. The attack can be launched remotely. The…

  • CVE-2025-10246LowSep 11, 2025
    risk 0.23cvss 3.5epss 0.00

    A weakness has been identified in lokibhardwaj PHP-Code-For-Unlimited-File-Upload up to 124fe96324915490c81eaf7db3234b0b4e4bab3c. This affects an unknown part of the file /f.php. This manipulation of the argument h causes cross site scripting. Remote exploitation of the attack…

  • CVE-2025-10117LowSep 9, 2025
    risk 0.23cvss 3.5epss 0.00

    A weakness has been identified in SourceCodester Simple To-Do List System 1.0. Impacted is an unknown function of the file /fetch_tasks.php of the component Add New Task. Executing manipulation with the input can lead to cross site scripting. The…

  • CVE-2025-10088LowSep 8, 2025
    risk 0.23cvss 3.5epss 0.00

    A vulnerability was detected in SourceCodester Time Tracker 1.0. The affected element is an unknown function of the file /index.html. Performing manipulation of the argument project-name results in cross site scripting. The attack may be initiated remotely. The exploit is now…

  • CVE-2025-10075LowSep 8, 2025
    risk 0.23cvss 3.5epss 0.00

    A security flaw has been discovered in SourceCodester Online Polling System 1.0. The impacted element is an unknown function of the file /manage-profile.php. The manipulation of the argument firstname results in cross site scripting. The attack can be launched remotely. The…

  • CVE-2025-10074LowSep 8, 2025
    risk 0.23cvss 3.5epss 0.00

    A vulnerability was identified in Portabilis i-Educar up to 2.10. The affected element is an unknown function of the file /usuarios/tipos/. The manipulation of the argument Tipos de Usuário/Descrição leads to cross site scripting. The attack can be initiated remotely. The…

  • CVE-2025-10029LowSep 6, 2025
    risk 0.23cvss 3.5epss 0.00

    A security flaw has been discovered in itsourcecode POS Point of Sale System 1.0. This vulnerability affects unknown code of the file /inventory/main/vendors/datatables/unit_testing/templates/complex_header_2.php. Performing manipulation of the argument scripts results in cross…

  • CVE-2025-10028LowSep 6, 2025
    risk 0.23cvss 3.5epss 0.00

    A vulnerability was identified in itsourcecode POS Point of Sale System 1.0. This affects an unknown part of the file /inventory/main/vendors/datatables/unit_testing/templates/6776.php. Such manipulation of the argument scripts leads to cross site scripting. The attack can be…

  • CVE-2025-10027LowSep 5, 2025
    risk 0.23cvss 3.5epss 0.00

    A vulnerability was determined in itsourcecode POS Point of Sale System 1.0. Affected by this issue is some unknown functionality of the file /inventory/main/vendors/datatables/unit_testing/templates/2512.php. This manipulation of the argument scripts causes cross site…

  • CVE-2025-10026LowSep 5, 2025
    risk 0.23cvss 3.5epss 0.00

    A vulnerability was found in itsourcecode POS Point of Sale System 1.0. Affected by this vulnerability is an unknown functionality of the file /inventory/main/vendors/datatables/unit_testing/templates/-complex_header.php. The manipulation of the argument scripts results in cross…

  • CVE-2025-9940LowSep 4, 2025
    risk 0.23cvss 3.5epss 0.00

    A vulnerability was detected in CodeAstro Real Estate Management System 1.0. This affects an unknown function of the file /feature.php. Performing manipulation of the argument msg results in cross site scripting. The attack can be initiated remotely. The exploit is now public…

  • CVE-2025-9939LowSep 4, 2025
    risk 0.23cvss 3.5epss 0.00

    A security vulnerability has been detected in CodeAstro Real Estate Management System 1.0. The impacted element is an unknown function of the file /propertyview.php. Such manipulation of the argument msg leads to cross site scripting. It is possible to launch the attack…

  • CVE-2025-9845LowSep 3, 2025
    risk 0.23cvss 3.5epss 0.00

    A vulnerability has been found in code-projects Fruit Shop Management System 1.0. Affected by this vulnerability is an unknown functionality of the file products.php. Such manipulation of the argument product_code/gen_name/product_name/supplier leads to cross site scripting. It…

  • CVE-2025-9834LowSep 2, 2025
    risk 0.23cvss 3.5epss 0.00

    A flaw has been found in PHPGurukul Small CRM 4.0. Affected by this issue is some unknown functionality of the file /registration.php. Executing manipulation of the argument Username can lead to cross site scripting. It is possible to launch the attack remotely. The exploit has…

  • CVE-2025-9796LowSep 1, 2025
    risk 0.23cvss 3.5epss 0.00

    A vulnerability was found in thinkgem JeeSite up to 5.12.1. This affects the function decodeUrl2 of the file common/src/main/java/com/jeesite/common/codec/EncodeUtils.java. The manipulation results in cross site scripting. It is possible to launch the attack remotely. The…

  • CVE-2025-9754LowSep 1, 2025
    risk 0.23cvss 3.5epss 0.00

    A flaw has been found in Campcodes Online Hospital Management System 1.0. The impacted element is an unknown function of the file /edit-profile.php of the component Edit Profile Page. Executing manipulation of the argument Username can lead to cross site scripting. The attack…