VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (22,695)

page 643 of 1,135
  • CVE-2026-1971LowFeb 6, 2026
    risk 0.16cvss 2.4epss 0.00

    A vulnerability has been found in Edimax BR-6288ACL up to 1.12. Impacted is the function wiz_WISP24gmanual of the file wiz_WISP24gmanual.asp. Such manipulation of the argument manualssid leads to cross site scripting. The attack can be launched remotely. The exploit has been…

  • CVE-2026-1744LowFeb 2, 2026
    risk 0.16cvss 2.4epss 0.00

    A vulnerability was found in D-Link DSL-6641K N8.TR069.20131126. Affected by this issue is the function doSubmitPPP of the file sp_pppoe_user.js. The manipulation of the argument Username results in cross site scripting. The attack may be launched remotely. The exploit has been…

  • CVE-2026-1705LowJan 30, 2026
    risk 0.16cvss 2.4epss 0.00

    A vulnerability was detected in D-Link DSL-6641K N8.TR069.20131126. Affected by this issue is the function ad_virtual_server_vdsl of the component Web Interface. Performing a manipulation of the argument Name results in cross site scripting. It is possible to initiate the attack…

  • CVE-2026-1520LowJan 28, 2026
    risk 0.16cvss 2.4epss 0.00

    A vulnerability was identified in rethinkdb up to 2.4.3. Affected by this issue is some unknown functionality of the component Secondary Index Handler. Such manipulation leads to cross site scripting. It is possible to launch the attack remotely. The exploit is publicly…

  • CVE-2026-1444LowJan 26, 2026
    risk 0.16cvss 2.4epss 0.00

    A vulnerability has been found in iJason-Liu Books_Manager up to 298ba736387ca37810466349af13a0fdf828e99c. This affects an unknown part of the file controllers/books_center/add_book_check.php. Such manipulation of the argument mark leads to cross site scripting. The attack can…

  • CVE-2026-1151LowJan 19, 2026
    risk 0.16cvss 2.4epss 0.00

    A weakness has been identified in technical-laohu mpay up to 1.2.4. The affected element is an unknown function of the component User Center. This manipulation of the argument Nickname causes cross site scripting. The attack may be initiated remotely. The exploit has been made…

  • CVE-2025-15505LowJan 11, 2026
    risk 0.16cvss 2.4epss 0.00

    A vulnerability was found in Luxul XWR-600 up to 4.0.1. The affected element is an unknown function of the component Web Administration Interface. The manipulation of the argument Guest Network/Wireless Profile SSID results in cross site scripting. The attack may be launched…

  • CVE-2026-0824LowJan 10, 2026
    risk 0.16cvss 3.5epss 0.00

    A security flaw has been discovered in questdb ui up to 1.11.9. Impacted is an unknown function of the component Web Console. The manipulation results in cross site scripting. The attack can be executed remotely. The exploit has been released to the public and may be used for…

  • CVE-2026-0730LowJan 8, 2026
    risk 0.16cvss 2.4epss 0.00

    A flaw has been found in PHPGurukul Staff Leave Management System 1.0. The affected element is the function ADD_STAFF/UPDATE_STAFF of the file /staffleave/slms/slms/adminviews.py of the component SVG File Handler. Executing a manipulation of the argument profile_pic can lead to…

  • CVE-2026-0642LowJan 7, 2026
    risk 0.16cvss 2.4epss 0.00

    A vulnerability was detected in projectworlds House Rental and Property Listing 1.0. This issue affects some unknown processing of the file /app/complaint.php. The manipulation of the argument Name results in cross site scripting. The attack may be launched remotely. The exploit…

  • CVE-2025-15452LowJan 5, 2026
    risk 0.16cvss 2.4epss 0.00

    A weakness has been identified in xnx3 wangmarket up to 4.9. This affects the function variableList of the file /admin/system/variableList.do of the component Backend Variable Search. Executing a manipulation of the argument Description can lead to cross site scripting. The…

  • CVE-2025-15451LowJan 5, 2026
    risk 0.16cvss 2.4epss 0.00

    A security flaw has been discovered in xnx3 wangmarket up to 4.9. Affected by this issue is some unknown functionality of the file /admin/system/variableSave.do of the component System Variables Page. Performing a manipulation of the argument Description results in cross site…

  • CVE-2025-15437LowJan 2, 2026
    risk 0.16cvss 3.5epss 0.00

    A vulnerability was found in LigeroSmart up to 6.1.24. This affects an unknown part of the component Environment Variable Handler. Performing a manipulation of the argument REQUEST_URI results in cross site scripting. The attack may be initiated remotely. The exploit has been…

  • CVE-2025-15416LowJan 1, 2026
    risk 0.16cvss 2.4epss 0.00

    A vulnerability was found in xnx3 wangmarket up to 6.4. This affects an unknown function of the file /siteVar/save.do of the component Add Global Variable Handler. The manipulation of the argument Remark/Variable Value results in cross site scripting. The attack can be executed…

  • CVE-2019-25262LowDec 31, 2025
    risk 0.16cvss 3.5epss 0.00

    A security vulnerability has been detected in elinicksic Razgover up to db37dfc5c82f023a40f2f7834ded6633fb2b5262. This affects an unknown part of the file Chattify/send.php of the component Chat Message Handler. Such manipulation of the argument msg leads to cross site…

  • CVE-2025-15372LowDec 31, 2025
    risk 0.16cvss 2.4epss 0.00

    A weakness has been identified in youlaitech vue3-element-admin up to 3.4.0. This issue affects some unknown processing of the file src/views/system/notice/index.vue of the component Notice Handler. This manipulation causes cross site scripting. It is possible to initiate the…

  • CVE-2025-15214LowDec 30, 2025
    risk 0.16cvss 2.4epss 0.00

    A vulnerability was found in Campcodes Park Ticketing System 1.0. The impacted element is the function save_pricing of the file admin_class.php. The manipulation of the argument name/ride results in cross site scripting. The attack may be performed from remote. The exploit has…

  • CVE-2025-15204LowDec 29, 2025
    risk 0.16cvss 2.4epss 0.00

    A vulnerability was determined in SohuTV CacheCloud up to 3.2.0. Affected is the function doQuartzList of the file src/main/java/com/sohu/cache/web/controller/QuartzManageController.java. Executing manipulation can lead to cross site scripting. It is possible to launch the…

  • CVE-2025-15203LowDec 29, 2025
    risk 0.16cvss 2.4epss 0.00

    A vulnerability was found in SohuTV CacheCloud up to 3.2.0. This impacts the function index of the file src/main/java/com/sohu/cache/web/controller/ResourceController.java. Performing manipulation results in cross site scripting. It is possible to initiate the attack remotely.…

  • CVE-2025-15202LowDec 29, 2025
    risk 0.16cvss 2.4epss 0.00

    A vulnerability has been found in SohuTV CacheCloud up to 3.2.0. This affects the function taskQueueList of the file src/main/java/com/sohu/cache/web/controller/TaskController.java. Such manipulation leads to cross site scripting. The attack may be performed from remote. The…