VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (22,695)

page 640 of 1,135
  • CVE-2026-7011LowApr 26, 2026
    risk 0.16cvss 2.4epss 0.00

    A weakness has been identified in MaxSite CMS up to 109.3. Affected by this vulnerability is an unknown functionality of the file /admin/plugin_antispam of the component Antispam Plugin. Executing a manipulation of the argument f_logging_file can lead to cross site scripting. It…

  • CVE-2026-7001LowApr 25, 2026
    risk 0.16cvss 2.4epss 0.00

    A vulnerability was found in Datacom DM4100 1.3.6.1.4.1.3709. This affects an unknown part of the component Ethernet Configuration Page. Performing a manipulation of the argument Name results in cross site scripting. It is possible to initiate the attack remotely. The exploit…

  • CVE-2026-7000LowApr 25, 2026
    risk 0.16cvss 2.4epss 0.00

    A vulnerability has been found in Datacom DM4100 1.3.6.1.4.1.3709. Affected by this issue is some unknown functionality of the component VLAN Page. Such manipulation of the argument VLAN Name leads to cross site scripting. The attack may be performed from remote. The exploit has…

  • CVE-2026-6999LowApr 25, 2026
    risk 0.16cvss 2.4epss 0.00

    A flaw has been found in BIVOCOM TR321 21.1.1.50. Affected by this vulnerability is an unknown functionality of the component Wireless Setting. This manipulation of the argument Network Name SSID causes cross site scripting. The attack is possible to be carried out remotely. The…

  • CVE-2026-6998LowApr 25, 2026
    risk 0.16cvss 2.4epss 0.00

    A vulnerability was detected in BDCOM P3310D 0.4.2 10.1.0F Build 86345. Affected is an unknown function of the component New RMON Statistics Page. The manipulation of the argument Owner results in cross site scripting. The attack can be executed remotely. The exploit is now…

  • CVE-2026-6997LowApr 25, 2026
    risk 0.16cvss 2.4epss 0.00

    A security vulnerability has been detected in BDCOM P3310D 0.4.2 10.1.0F Build 86345. This impacts an unknown function of the component New RMON History Page. The manipulation of the argument Owner leads to cross site scripting. Remote exploitation of the attack is possible. The…

  • CVE-2026-6996LowApr 25, 2026
    risk 0.16cvss 2.4epss 0.00

    A weakness has been identified in BDCOM P3310D 0.4.2 10.1.0F Build 86345. This affects an unknown function of the component rmon event Tab. Executing a manipulation of the argument Description can lead to cross site scripting. The attack may be launched remotely. The exploit has…

  • CVE-2026-6995LowApr 25, 2026
    risk 0.16cvss 2.4epss 0.00

    A security flaw has been discovered in BDCOM P3310D 0.4.2 10.1.0F Build 86345. The impacted element is an unknown function of the file /index.asp of the component New User Page. Performing a manipulation of the argument User name results in cross site scripting. The attack may…

  • CVE-2026-4313LowApr 24, 2026
    risk 0.16cvss epss 0.00

    AdaptiveGRC is vulnerable to Stored XSS via text type fields across the forms. Authenticated attacker can replace the value of the text field in the HTTP POST request. Improper parameter validation by the server results in arbitrary JavaScript execution in the victim's browser.…

  • CVE-2026-6651LowApr 20, 2026
    risk 0.16cvss 2.4epss 0.00

    A security flaw has been discovered in erponline.xyz ERP Online up to 4.0.0. This vulnerability affects unknown code of the component Inventory Edit Item Page. The manipulation of the argument Item Name results in cross site scripting. The attack may be launched remotely. The…

  • CVE-2026-6624LowApr 20, 2026
    risk 0.16cvss 2.4epss 0.00

    A weakness has been identified in BichitroGan ISP Billing Software 2025.3.20. Affected is an unknown function of the file /?\_route=pool/add of the component Pool List Interface. Executing a manipulation can lead to cross site scripting. The attack may be performed from remote.…

  • CVE-2026-6623LowApr 20, 2026
    risk 0.16cvss 2.4epss 0.00

    A security flaw has been discovered in BichitroGan ISP Billing Software 2025.3.20. This impacts an unknown function of the file /?_route=settings/users-view/ of the component Profile Page Handler. Performing a manipulation results in cross site scripting. The attack is possible…

  • CVE-2026-6622LowApr 20, 2026
    risk 0.16cvss 2.4epss 0.00

    A vulnerability was identified in BichitroGan ISP Billing Software 2025.3.20. This affects an unknown function of the file /?\_route=customers/edit/ of the component Customer Handler. Such manipulation leads to cross site scripting. The attack can be executed remotely. The…

  • CVE-2026-6216LowApr 13, 2026
    risk 0.16cvss 3.5epss 0.00

    A security vulnerability has been detected in DbGate up to 7.1.4. This affects an unknown function of the file packages/web/src/icons/FontIcon.svelte of the component SVG Icon String Handler. Such manipulation of the argument applicationIcon leads to cross site scripting. The…

  • CVE-2026-6184LowApr 13, 2026
    risk 0.16cvss 2.4epss 0.00

    A weakness has been identified in code-projects Simple Content Management System 1.0. This affects an unknown part of the file /web/admin/welcome.php. Executing a manipulation of the argument News Title can lead to cross site scripting. The attack can be executed remotely. The…

  • CVE-2026-6003LowApr 10, 2026
    risk 0.16cvss 2.4epss 0.00

    A security vulnerability has been detected in code-projects Simple IT Discussion Forum 1.0. This issue affects some unknown processing of the file /admin/user.php. Such manipulation of the argument fname leads to cross site scripting. The attack may be performed from remote. The…

  • CVE-2026-5836LowApr 9, 2026
    risk 0.16cvss 2.4epss 0.00

    A vulnerability has been found in code-projects Online Shoe Store 1.0. Affected by this issue is some unknown functionality of the file /admin/admin_product.php. The manipulation of the argument product_name leads to cross site scripting. The attack can be initiated remotely.…

  • CVE-2026-5835LowApr 9, 2026
    risk 0.16cvss 2.4epss 0.00

    A flaw has been found in code-projects Online Shoe Store 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/admin_football.php. Executing a manipulation of the argument product_name can lead to cross site scripting. It is possible to launch the…

  • CVE-2026-5834LowApr 9, 2026
    risk 0.16cvss 2.4epss 0.00

    A vulnerability was detected in code-projects Online Shoe Store 1.0. Affected is an unknown function of the file /admin/admin_running.php. Performing a manipulation of the argument product_name results in cross site scripting. It is possible to initiate the attack remotely. The…

  • CVE-2026-5668LowApr 6, 2026
    risk 0.16cvss 2.4epss 0.00

    A flaw has been found in Cyber-III Student-Management-System up to 1a938fa61e9f735078e9b291d2e6215b4942af3f. This affects an unknown part of the file /admin/Add%20notice/add%20notice.php. This manipulation of the argument $_SERVER['PHP_SELF'] causes cross site scripting. It is…