VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (46,607)

page 67 of 2,331
  • CVE-2024-4180CriJun 4, 2024
    risk 0.52cvss 9.1epss 0.02

    The Events Calendar WordPress plugin before 6.4.0.1 does not properly sanitize user-submitted content when rendering some views via AJAX.

  • CVE-2024-4835HigMay 23, 2024
    risk 0.52cvss 8.0epss 0.01

    A XSS condition exists within GitLab in versions 15.11 before 16.10.6, 16.11 before 16.11.3, and 17.0 before 17.0.1. By leveraging this condition, an attacker can craft a malicious page to exfiltrate sensitive user information.

  • CVE-2024-31156HigMay 8, 2024
    risk 0.52cvss 8.0epss 0.01

    A stored cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an attacker to run JavaScript in the context of the currently logged-in user.  Note: Software versions which have reached End of Technical Support…

  • CVE-2024-30929HigApr 18, 2024
    risk 0.52cvss 8.0epss 0.01

    Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows attackers to execute arbitrary code via the 'back' Parameter in playlist.php

  • CVE-2024-29184HigMar 22, 2024
    risk 0.52cvss 8.0epss 0.01

    FreeScout is a self-hosted help desk and shared mailbox. A Stored Cross-Site Scripting (XSS) vulnerability has been identified within the Signature Input Field of the FreeScout Application prior to version 1.8.128. Stored XSS occurs when user input is not properly sanitized and…

  • CVE-2024-28404HigMar 15, 2024
    risk 0.52cvss 8.0epss 0.00

    TOTOLINK X2000R before V1.0.0-B20231213.1013 contains a Stored Cross-site scripting (XSS) vulnerability in MAC Filtering under the Firewall Page.

  • CVE-2024-28175CriMar 13, 2024
    risk 0.52cvss 9.0epss 0.01

    Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Due to the improper URL protocols filtering of links specified in the `link.argocd.argoproj.io` annotations in the application summary component, an attacker can achieve cross-site scripting with elevated…

  • CVE-2024-2194HigMar 13, 2024
    risk 0.52cvss 7.2epss 0.68

    The WP Statistics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the URL search parameter in all versions up to, and including, 14.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject…

  • CVE-2024-28157HigMar 6, 2024
    risk 0.52cvss 8.0epss 0.01

    Jenkins GitBucket Plugin 0.8 and earlier does not sanitize Gitbucket URLs on build views, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to configure jobs.

  • CVE-2024-1636HigFeb 28, 2024
    risk 0.52cvss 8.0epss 0.00

    Potential Cross-Site Scripting (XSS) in the page editing area.

  • CVE-2023-45137CriOct 25, 2023
    risk 0.52cvss 9.0epss 0.01

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. `org.xwiki.platform:xwiki-platform-web` starting in version 3.1-milestone-2 and prior to version 13.4-rc-1, as well as `org.xwiki.platform:xwiki-platform-web-templates` prior…

  • CVE-2023-45134CriOct 25, 2023
    risk 0.52cvss 9.0epss 0.02

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. `org.xwiki.platform:xwiki-platform-web` starting in version 3.1-milestone-1 and prior to 13.4-rc-1, `org.xwiki.platform:xwiki-platform-web-templates` prior to versions…

  • CVE-2023-37908CriOct 25, 2023
    risk 0.52cvss 9.0epss 0.01

    XWiki Rendering is a generic Rendering system that converts textual input in a given syntax into another syntax. The cleaning of attributes during XHTML rendering, introduced in version 14.6-rc-1, allowed the injection of arbitrary HTML code and thus cross-site scripting via…

  • CVE-2023-44310CriOct 17, 2023
    risk 0.52cvss 9.0epss 0.00

    Stored cross-site scripting (XSS) vulnerability in Page Tree menu Liferay Portal 7.3.6 through 7.4.3.78, and Liferay DXP 7.3 fix pack 1 through update 23, and 7.4 before update 79 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into…

  • CVE-2023-44309CriOct 17, 2023
    risk 0.52cvss 9.0epss 0.00

    Multiple stored cross-site scripting (XSS) vulnerabilities in the fragment components in Liferay Portal 7.4.2 through 7.4.3.53, and Liferay DXP 7.4 before update 54 allow remote attackers to inject arbitrary web script or HTML via a crafted payload injected into any non-HTML…

  • CVE-2023-42629CriOct 17, 2023
    risk 0.52cvss 9.0epss 0.02

    Stored cross-site scripting (XSS) vulnerability in the manage vocabulary page in Liferay Portal 7.4.2 through 7.4.3.87, and Liferay DXP 7.4 before update 88 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into a Vocabulary's…

  • CVE-2023-43659HigOct 16, 2023
    risk 0.52cvss 8.0epss 0.00

    Discourse is an open source platform for community discussion. Improper escaping of user input allowed for Cross-site Scripting attacks via the digest email preview UI. This issue only affects sites with CSP disabled. This issue has been patched in the 3.1.1 stable release as…

  • CVE-2023-26218HigSep 29, 2023
    risk 0.52cvss 8.0epss 0.01

    The Web Client component of TIBCO Software Inc.'s TIBCO Nimbus contains easily exploitable Reflected Cross Site Scripting (XSS) vulnerabilities that allow a low privileged attacker to social engineer a legitimate user with network access to execute scripts targeting the affected…

  • CVE-2023-0625HigSep 25, 2023
    risk 0.52cvss 8.0epss 0.01

    Docker Desktop before 4.12.0 is vulnerable to RCE via a crafted extension description or changelog. This issue affects Docker Desktop: before 4.12.0.

  • CVE-2023-29183HigSep 13, 2023
    risk 0.52cvss 8.0epss 0.01

    An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability [CWE-79] in FortiProxy 7.2.0 through 7.2.4, 7.0.0 through 7.0.10 and FortiOS 7.2.0 through 7.2.4, 7.0.0 through 7.0.11, 6.4.0 through 6.4.12, 6.2.0 through 6.2.14 GUI may allow…