VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (22,695)

page 628 of 1,135
  • CVE-2025-8743LowAug 8, 2025
    risk 0.23cvss 3.5epss 0.00

    A vulnerability classified as problematic has been found in Scada-LTS up to 2.7.8.1. This affects an unknown part of the file /data_source_edit.shtm of the component Virtual Data Source Property Handler. The manipulation of the argument Name leads to cross site scripting. It is…

  • CVE-2025-8555LowAug 5, 2025
    risk 0.23cvss 3.5epss 0.00

    A vulnerability, which was classified as problematic, was found in atjiu pybbs up to 6.0.0. Affected is an unknown function of the file /search. The manipulation of the argument keyword leads to cross site scripting. It is possible to launch the attack remotely. The exploit has…

  • CVE-2025-8551LowAug 5, 2025
    risk 0.23cvss 3.5epss 0.00

    A vulnerability was found in atjiu pybbs up to 6.0.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /admin/comment/list. The manipulation of the argument Username leads to cross site scripting. The attack may be launched…

  • CVE-2025-8535LowAug 5, 2025
    risk 0.23cvss 3.5epss 0.00

    A vulnerability, which was classified as problematic, has been found in cronoh NanoVault up to 1.2.1. This issue affects the function executeJavaScript of the file /main.js of the component xrb URL Handler. The manipulation leads to cross site scripting. The attack may be…

  • CVE-2025-8511LowAug 3, 2025
    risk 0.23cvss 3.5epss 0.00

    A vulnerability classified as problematic was found in Portabilis i-Diario 1.5.0. This vulnerability affects unknown code of the file /diario-de-observacoes/ of the component Observações. The manipulation of the argument Descrição leads to cross site scripting. The attack…

  • CVE-2025-8510LowAug 3, 2025
    risk 0.23cvss 3.5epss 0.00

    A vulnerability classified as problematic has been found in Portabilis i-Educar 2.10. This affects the function Gerar of the file ieducar/intranet/educar_matricula_lst.php. The manipulation of the argument ref_cod_aluno leads to cross site scripting. It is possible to initiate…

  • CVE-2025-8509LowAug 3, 2025
    risk 0.23cvss 3.5epss 0.00

    A vulnerability was found in Portabilis i-Educar 2.9. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /intranet/educar_servidor_cad.php. The manipulation of the argument matricula leads to cross site scripting. The attack may be…

  • CVE-2025-8508LowAug 3, 2025
    risk 0.23cvss 3.5epss 0.00

    A vulnerability was found in Portabilis i-Educar 2.9. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /intranet/educar_avaliacao_desempenho_cad.php. The manipulation of the argument titulo_avaliacao/descricao leads to…

  • CVE-2025-8507LowAug 3, 2025
    risk 0.23cvss 3.5epss 0.00

    A vulnerability was found in Portabilis i-Educar 2.9. It has been classified as problematic. Affected is an unknown function of the file /intranet/educar_funcao_lst.php. The manipulation of the argument nm_funcao/abreviatura leads to cross site scripting. It is possible to…

  • CVE-2025-8506LowAug 3, 2025
    risk 0.23cvss 3.5epss 0.00

    A vulnerability was found in 495300897 wx-shop up to de1b66331368695779cfc6e4d11a64caddf8716e and classified as problematic. This issue affects some unknown processing of the file /user/editUI. The manipulation leads to cross site scripting. The attack may be initiated remotely.…

  • CVE-2025-8501LowAug 3, 2025
    risk 0.23cvss 3.5epss 0.00

    A vulnerability classified as problematic has been found in code-projects Human Resource Integrated System 1.0. Affected is an unknown function of the file /insert-and-view/action.php. The manipulation of the argument content leads to cross site scripting. It is possible to…

  • CVE-2025-37109LowJul 31, 2025
    risk 0.23cvss 3.5epss 0.00

    Cross-site scripting vulnerability has been identified in HPE Telco Service Activator product

  • CVE-2025-37108LowJul 31, 2025
    risk 0.23cvss 3.5epss 0.00

    Cross-site scripting vulnerability has been identified in HPE Telco Service Activator product

  • CVE-2025-8380LowJul 31, 2025
    risk 0.23cvss 3.5epss 0.00

    A vulnerability classified as problematic was found in Campcodes Online Hotel Reservation System 1.0. This vulnerability affects unknown code of the file /admin/add_query_account.php. The manipulation of the argument Name leads to cross site scripting. The attack can be…

  • CVE-2025-8365LowJul 31, 2025
    risk 0.23cvss 3.5epss 0.00

    A vulnerability was found in Portabilis i-Educar 2.10. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file atendidos_cad.php. The manipulation of the argument nome/nome_social/email leads to cross site scripting. The attack…

  • CVE-2025-8222LowJul 27, 2025
    risk 0.23cvss 3.5epss 0.00

    A vulnerability, which was classified as problematic, has been found in jerryshensjf JPACookieShop 蛋糕商城JPA版 up to 24a15c02b4f75042c9f7f615a3fed2ec1cefb999. Affected by this issue is some unknown functionality of the file GoodsController.java. The manipulation leads to…

  • CVE-2025-8211LowJul 26, 2025
    risk 0.23cvss 3.5epss 0.00

    A vulnerability was found in Roothub up to 2.6. It has been declared as problematic. Affected by this vulnerability is the function Edit of the file src/main/java/cn/roothub/web/admin/SystemConfigAdminController.java. The manipulation leads to cross site scripting. The attack…

  • CVE-2025-8167LowJul 25, 2025
    risk 0.23cvss 3.5epss 0.00

    A vulnerability was found in code-projects Church Donation System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /admin/edit_members.php. The manipulation of the argument fname leads to cross site scripting. The…

  • CVE-2025-8155LowJul 25, 2025
    risk 0.23cvss 3.5epss 0.00

    A vulnerability has been found in D-Link DCS-6010L 1.15.03 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /vb.htm of the component Management Application. The manipulation of the argument paratest leads to cross site…

  • CVE-2025-8115LowJul 24, 2025
    risk 0.23cvss 3.5epss 0.00

    A vulnerability has been found in PHPGurukul Taxi Stand Management System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /admin/new-autoortaxi-entry-form.php. The manipulation of the argument…