VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (22,695)

page 645 of 1,135
  • CVE-2025-13469LowNov 20, 2025
    risk 0.16cvss 2.4epss 0.00

    A security vulnerability has been detected in Public Knowledge Project omp and ojs 3.3.0/3.4.0/3.5.0. Impacted is an unknown function of the file plugins/paymethod/manual/templates/paymentForm.tpl of the component Payment Instructions Setting Handler. The manipulation of the…

  • CVE-2025-13412LowNov 19, 2025
    risk 0.16cvss 2.4epss 0.00

    A vulnerability was determined in Campcodes Retro Basketball Shoes Online Store 1.0. Affected by this issue is some unknown functionality of the file /admin/admin_running.php. Executing a manipulation of the argument product_name can lead to cross site scripting. The attack may…

  • CVE-2025-13232LowNov 16, 2025
    risk 0.16cvss 3.5epss 0.00

    A flaw has been found in projectsend up to r1720. Impacted is an unknown function of the component File Editor/Custom Download Aliases. This manipulation causes cross site scripting. The attack is possible to be carried out remotely. The exploit has been published and may be…

  • CVE-2025-13186LowNov 14, 2025
    risk 0.16cvss 2.4epss 0.00

    A weakness has been identified in Bdtask/CodeCanyon Isshue Multi Store eCommerce Shopping Cart Solution up to 4.0. This impacts an unknown function of the file /dashboard/Ccustomer/manage_customer. This manipulation of the argument Search causes cross site scripting. The attack…

  • CVE-2025-12920LowNov 9, 2025
    risk 0.16cvss 2.4epss 0.00

    A flaw has been found in qianfox FoxCMS up to 1.2.16. Affected by this vulnerability is the function add/edit of the file app/admin/controller/Product.php. This manipulation of the argument Title causes cross site scripting. It is possible to initiate the attack remotely. The…

  • CVE-2025-12332LowOct 28, 2025
    risk 0.16cvss 2.4epss 0.00

    A flaw has been found in SourceCodester Student Grades Management System 1.0. This affects the function delete_user of the file /admin.php. Executing manipulation can lead to cross site scripting. The attack may be performed from remote. The exploit has been published and may be…

  • CVE-2025-12330LowOct 27, 2025
    risk 0.16cvss 2.4epss 0.00

    A security flaw has been discovered in Willow CMS up to 1.4.0. This issue affects some unknown processing of the file /admin/articles/add of the component Add Post Page. The manipulation of the argument title/body results in cross site scripting. The attack may be launched…

  • CVE-2025-12312LowOct 27, 2025
    risk 0.16cvss 2.4epss 0.00

    A flaw has been found in PHPGurukul Curfew e-Pass Management System 1.0. Impacted is an unknown function of the file view-pass-detail.php. This manipulation of the argument Fullname/Category causes cross site scripting. The attack may be initiated remotely. The exploit has been…

  • CVE-2025-12311LowOct 27, 2025
    risk 0.16cvss 2.4epss 0.00

    A vulnerability was detected in PHPGurukul Curfew e-Pass Management System 1.0. This issue affects some unknown processing of the file edit-category-detail.php. The manipulation of the argument catname results in cross site scripting. The attack can be launched remotely. The…

  • CVE-2025-12303LowOct 27, 2025
    risk 0.16cvss 2.4epss 0.00

    A flaw has been found in PHPGurukul Curfew e-Pass Management System 1.0. The impacted element is an unknown function of the file admin-profile.php. Executing a manipulation of the argument adminname/email can lead to cross site scripting. The attack may be launched remotely. The…

  • CVE-2025-12282LowOct 27, 2025
    risk 0.16cvss 2.4epss 0.00

    A vulnerability was identified in code-projects Client Details System 1.0. The affected element is an unknown function of the file /admin/manage-users.php. The manipulation leads to cross site scripting. The attack can be initiated remotely. The exploit is publicly available and…

  • CVE-2025-12281LowOct 27, 2025
    risk 0.16cvss 2.4epss 0.00

    A vulnerability was determined in code-projects Client Details System 1.0. Impacted is an unknown function of the file /admin/clientview.php. Executing manipulation can lead to cross site scripting. It is possible to launch the attack remotely. The exploit has been publicly…

  • CVE-2025-12280LowOct 27, 2025
    risk 0.16cvss 2.4epss 0.00

    A vulnerability was found in code-projects Client Details System 1.0. This issue affects some unknown processing of the file /update-clients.php. Performing manipulation results in cross site scripting. It is possible to initiate the attack remotely. The exploit has been made…

  • CVE-2025-12279LowOct 27, 2025
    risk 0.16cvss 2.4epss 0.00

    A vulnerability has been found in code-projects Client Details System 1.0. This vulnerability affects unknown code of the file /welcome.php. Such manipulation leads to cross site scripting. The attack may be performed from remote. The exploit has been disclosed to the public and…

  • CVE-2025-12231LowOct 27, 2025
    risk 0.16cvss 2.4epss 0.00

    A security vulnerability has been detected in projectworlds Expense Management System 1.0. Affected is an unknown function of the file /public/admin/expense_categories/create of the component Expense Categories Page. Such manipulation leads to cross site scripting. It is…

  • CVE-2025-12230LowOct 27, 2025
    risk 0.16cvss 2.4epss 0.00

    A weakness has been identified in projectworlds Expense Management System 1.0. This impacts an unknown function of the file /public/admin/currencies/create of the component Currency Page. This manipulation causes cross site scripting. It is possible to initiate the attack…

  • CVE-2025-12229LowOct 27, 2025
    risk 0.16cvss 2.4epss 0.00

    A security flaw has been discovered in projectworlds Expense Management System 1.0. This affects an unknown function of the file /public/admin/roles/create of the component Roles Page. The manipulation results in cross site scripting. The attack may be performed from remote. The…

  • CVE-2025-12228LowOct 27, 2025
    risk 0.16cvss 2.4epss 0.00

    A vulnerability was identified in projectworlds Expense Management System 1.0. The impacted element is an unknown function of the file /public/admin/users/create of the component Users Page. The manipulation leads to cross site scripting. The attack is possible to be carried out…

  • CVE-2025-11485LowOct 8, 2025
    risk 0.16cvss 2.4epss 0.00

    A vulnerability was determined in SourceCodester Student Grades Management System 1.0. Affected is the function add_user of the file /admin.php of the component Manage Users Page. This manipulation of the argument first_name/last_name causes cross site scripting. The attack can…

  • CVE-2025-11437LowOct 8, 2025
    risk 0.16cvss 2.4epss 0.00

    A flaw has been found in JhumanJ OpnForm up to 1.9.3. This affects an unknown part of the file /api/open/forms/ of the component Form Editor. This manipulation causes cross site scripting. The attack may be initiated remotely. The exploit has been published and may be used. This…