VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (22,695)

page 641 of 1,135
  • CVE-2026-5647LowApr 6, 2026
    risk 0.16cvss 2.4epss 0.00

    A vulnerability was detected in code-projects Online Shoe Store 1.0. This affects an unknown part of the file /admin/admin_feature.php of the component Add Product Page. The manipulation of the argument product_name results in cross site scripting. The attack may be launched…

  • CVE-2026-5644LowApr 6, 2026
    risk 0.16cvss 2.4epss 0.00

    A security flaw has been discovered in Cyber-III Student-Management-System up to 1a938fa61e9f735078e9b291d2e6215b4942af3f. Affected is an unknown function of the file /admin/Add%20notice/batch-notice.php. Performing a manipulation of the argument $_SERVER['PHP_SELF'] results in…

  • CVE-2026-5643LowApr 6, 2026
    risk 0.16cvss 2.4epss 0.00

    A vulnerability was identified in Cyber-III Student-Management-System up to 1a938fa61e9f735078e9b291d2e6215b4942af3f. This impacts an unknown function of the file /admin/Add%20notice/notice.php of the component Admin Add Endpoint. Such manipulation of the argument…

  • CVE-2026-5370LowApr 2, 2026
    risk 0.16cvss 3.5epss 0.00

    A vulnerability was identified in krayin laravel-crm up to 2.2. Impacted is the function composeMail of the file packages/Webkul/Admin/tests/e2e-pw/tests/mail/inbox.spec.ts of the component Activities Module/Notes Module. The manipulation leads to cross site scripting. Remote…

  • CVE-2026-5209LowMar 31, 2026
    risk 0.16cvss 2.4epss 0.00

    A security vulnerability has been detected in SourceCodester Leave Application System 1.0. Affected by this issue is some unknown functionality of the component User Management Handler. Such manipulation leads to cross site scripting. The attack may be launched remotely. The…

  • CVE-2026-5106LowMar 30, 2026
    risk 0.16cvss 2.4epss 0.00

    A flaw has been found in code-projects Exam Form Submission 1.0. The impacted element is an unknown function of the file /admin/update_fst.php. Executing a manipulation of the argument sname can lead to cross site scripting. It is possible to launch the attack remotely. The…

  • CVE-2026-4972LowMar 27, 2026
    risk 0.16cvss 2.4epss 0.00

    A security vulnerability has been detected in code-projects Online Reviewer System up to 1.0. Affected is an unknown function of the file /system/system/students/assessments/databank/btn_functions.php. Such manipulation of the argument Description leads to cross site scripting.…

  • CVE-2026-4909LowMar 27, 2026
    risk 0.16cvss 2.4epss 0.00

    A weakness has been identified in code-projects Exam Form Submission 1.0. This impacts an unknown function of the file /admin/update_s7.php. This manipulation of the argument sname causes cross site scripting. It is possible to initiate the attack remotely. The exploit has been…

  • CVE-2026-4899LowMar 26, 2026
    risk 0.16cvss 2.4epss 0.00

    A security flaw has been discovered in code-projects Online Food Ordering System 1.0. Affected by this issue is some unknown functionality of the file /dbfood/food.php. The manipulation of the argument cuisines results in cross site scripting. It is possible to launch the attack…

  • CVE-2026-4616LowMar 24, 2026
    risk 0.16cvss 2.4epss 0.00

    A security flaw has been discovered in bolo-blog up to 2.6.4. The affected element is an unknown function of the file /console/article/ of the component Article Title Handler. Performing a manipulation of the argument articleTitle results in cross site scripting. It is possible…

  • CVE-2026-4595LowMar 23, 2026
    risk 0.16cvss 2.4epss 0.00

    A vulnerability was determined in code-projects Exam Form Submission 1.0. This vulnerability affects unknown code of the file /admin/update_s6.php. Executing a manipulation of the argument sname can lead to cross site scripting. The attack can be launched remotely. The exploit…

  • CVE-2026-4578LowMar 23, 2026
    risk 0.16cvss 2.4epss 0.00

    A vulnerability was determined in code-projects Exam Form Submission 1.0. The impacted element is an unknown function of the file /admin/update_s3.php. Executing a manipulation of the argument sname can lead to cross site scripting. The attack may be launched remotely. The…

  • CVE-2026-4577LowMar 23, 2026
    risk 0.16cvss 2.4epss 0.00

    A vulnerability was found in code-projects Exam Form Submission 1.0. The affected element is an unknown function of the file /admin/update_s4.php. Performing a manipulation of the argument sname results in cross site scripting. The attack may be initiated remotely. The exploit…

  • CVE-2026-4576LowMar 23, 2026
    risk 0.16cvss 2.4epss 0.00

    A vulnerability has been found in code-projects Exam Form Submission 1.0. Impacted is an unknown function of the file /admin/update_s5.php. Such manipulation of the argument sname leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed…

  • CVE-2026-4575LowMar 23, 2026
    risk 0.16cvss 2.4epss 0.00

    A flaw has been found in code-projects Exam Form Submission 1.0. This issue affects some unknown processing of the file /admin/update_s2.php. This manipulation of the argument sname causes cross site scripting. The attack can be initiated remotely. The exploit has been published…

  • CVE-2026-4544LowMar 22, 2026
    risk 0.16cvss 2.4epss 0.00

    A vulnerability was determined in Wavlink WL-WN578W2 221110. This affects an unknown function of the file /cgi-bin/login.cgi of the component POST Request Handler. Executing a manipulation of the argument homepage/hostname/login_page can lead to cross site scripting. It is…

  • CVE-2026-4474LowMar 20, 2026
    risk 0.16cvss 2.4epss 0.00

    A flaw has been found in itsourcecode University Management System 1.0. Impacted is an unknown function of the file /admin_single_student_update.php. This manipulation of the argument st_name causes cross site scripting. The attack may be initiated remotely. The exploit has been…

  • CVE-2026-4356LowMar 18, 2026
    risk 0.16cvss 2.4epss 0.00

    A flaw has been found in itsourcecode University Management System 1.0. Affected is an unknown function of the file /add_result.php. Executing a manipulation of the argument vr can lead to cross site scripting. The attack may be launched remotely. The exploit has been published…

  • CVE-2026-4225LowMar 16, 2026
    risk 0.16cvss 2.4epss 0.00

    A security flaw has been discovered in CMS Made Simple up to 2.2.21. Impacted is an unknown function of the file admin/listusers.php of the component User Management Module. Performing a manipulation of the argument Message results in cross site scripting. The attack is possible…

  • CVE-2026-4175LowMar 16, 2026
    risk 0.16cvss 3.5epss 0.00

    A vulnerability was determined in Aureus ERP up to 1.3.0-BETA2. The affected element is an unknown function of the file plugins/webkul/chatter/resources/views/filament/infolists/components/messages/content-text-entry.blade.php of the component Chatter Message Handler. Executing…