CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Description
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85
CVEs mapped to this weakness (22,695)
page 672 of 1,135| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-7934 | — | 0.03 | — | 0.03 | Jan 28, 2020 | In LifeRay Portal CE 7.1.0 through 7.2.1 GA2, the First Name, Middle Name, and Last Name fields for user accounts in MyAccountPortlet are all vulnerable to a persistent XSS issue. Any user can modify these fields with a particular XSS payload, and it will be stored in the… | ||
| CVE-2019-9553 | — | 0.03 | — | 0.01 | Dec 31, 2019 | Bolt 3.6.4 has XSS via the slug, teaser, or title parameter to editcontent/pages, a related issue to CVE-2017-11128 and CVE-2018-19933. | ||
| CVE-2019-13236 | — | 0.03 | — | 0.04 | Aug 27, 2019 | In system/workplace/ in Alkacon OpenCms 10.5.4 and 10.5.5, there are multiple Reflected and Stored XSS issues in the management interface. | ||
| CVE-2019-13235 | — | 0.03 | — | 0.04 | Aug 27, 2019 | In the Alkacon OpenCms Apollo Template 10.5.4 and 10.5.5, there is XSS in the Login form. | ||
| CVE-2019-13234 | — | 0.03 | — | 0.02 | Aug 27, 2019 | In the Alkacon OpenCms Apollo Template 10.5.4 and 10.5.5, there is XSS in the search engine. | ||
| CVE-2019-13068 | — | 0.03 | — | 0.05 | Jun 29, 2019 | public/app/features/panel/panel_ctrl.ts in Grafana before 6.2.5 allows HTML Injection in panel drilldown links (via the Title or url field). | ||
| CVE-2019-10226 | — | 0.03 | — | 0.02 | Jun 10, 2019 | HTML Injection has been discovered in the v0.19.0 version of the Fat Free CRM product via an authenticated request to the /comments URI. NOTE: the vendor disputes the significance of this report because some HTML formatting (such as with an H1 element) is allowed, but there is a… | ||
| CVE-2019-6588 | — | 0.03 | — | 0.01 | Jun 3, 2019 | In Liferay Portal before 7.1 CE GA4, an XSS vulnerability exists in the SimpleCaptcha API when custom code passes unsanitized input into the "url" parameter of the JSP taglib call <liferay-ui:captcha url="<%= url %>" /> or <liferay-captcha:captcha url="<%= url %>" />. Liferay… | ||
| CVE-2019-0186 | — | 0.03 | — | 0.06 | Apr 26, 2019 | The input fields of the Apache Pluto "Chat Room" demo portlet 3.0.0 and 3.0.1 are vulnerable to Cross-Site Scripting (XSS) attacks. Mitigation: * Uninstall the ChatRoomDemo war file - or - * migrate to version 3.1.0 of the chat-room-demo war file | ||
| CVE-2018-19799 | 0.03 | — | 0.02 | Dec 26, 2018 | Dolibarr ERP/CRM through 8.0.3 has /exports/export.php?datatoexport= XSS. | |||
| CVE-2018-20418 | — | 0.03 | — | 0.00 | Dec 24, 2018 | index.php?p=admin/actions/entries/save-entry in Craft CMS 3.0.25 allows XSS by saving a new title from the console tab. | ||
| CVE-2018-19933 | — | 0.03 | — | 0.02 | Dec 17, 2018 | Bolt CMS <3.6.2 allows XSS via text input click preview button as demonstrated by the Title field of a Configured and New Entry. | ||
| CVE-2018-18548 | — | 0.03 | — | 0.02 | Oct 24, 2018 | ajenticp (aka Ajenti Docker control panel) for Ajenti through v1.2.23.13 has XSS via a filename that is mishandled in File Manager. | ||
| CVE-2018-14059 | — | 0.03 | — | 0.00 | Aug 24, 2018 | Pimcore allows XSS via Users, Assets, Data Objects, Video Thumbnails, Image Thumbnails, Field-Collections, Objectbrick, Classification Store, Document Types, Predefined Properties, Predefined Asset Metadata, Quantity Value, and Static Routes functions. | ||
| CVE-2018-11564 | — | 0.03 | — | 0.01 | Jun 1, 2018 | Stored XSS in YOOtheme Pagekit 1.0.13 and earlier allows a user to upload malicious code via the picture upload feature. A user with elevated privileges could upload a photo to the system in an SVG format. This file will be uploaded to the system and it will not be stripped or… | ||
| CVE-2015-6176 | 0.03 | — | 0.04 | Dec 9, 2015 | Microsoft Edge mishandles HTML attributes in HTTP responses, which allows remote attackers to bypass a cross-site scripting (XSS) protection mechanism via unspecified vectors, aka "Microsoft Edge XSS Filter Bypass Vulnerability." | |||
| CVE-2015-8038 | 0.03 | — | 0.02 | Nov 2, 2015 | Multiple cross-site scripting (XSS) vulnerabilities in the Graphical User Interface (GUI) in Fortinet FortiManager before 5.2.4 allow remote attackers to inject arbitrary web script or HTML via the (1) sharedjobmanager or (2) SOMServiceObjDialog. | |||
| CVE-2015-8037 | 0.03 | — | 0.02 | Nov 2, 2015 | Multiple cross-site scripting (XSS) vulnerabilities in the Graphical User Interface (GUI) in Fortinet FortiManager before 5.2.4 allow remote attackers to inject arbitrary web script or HTML via the (1) SOMVpnSSLPortalDialog or (2) FGDMngUpdHistory. | |||
| CVE-2015-6494 | 0.03 | — | 0.01 | Oct 28, 2015 | Cross-site scripting (XSS) vulnerability in Infinite Automation Mango Automation 2.5.x and 2.6.x before 2.6.0 build 430 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors. | |||
| CVE-2015-6477 | — | 0.03 | — | 0.33 | Oct 18, 2015 | Multiple cross-site scripting (XSS) vulnerabilities in the Wind Farm Portal application in Nordex Control 2 (NC2) SCADA 16 and earlier allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. |
- CVE-2020-7934Jan 28, 2020risk 0.03cvss —epss 0.03
In LifeRay Portal CE 7.1.0 through 7.2.1 GA2, the First Name, Middle Name, and Last Name fields for user accounts in MyAccountPortlet are all vulnerable to a persistent XSS issue. Any user can modify these fields with a particular XSS payload, and it will be stored in the…
- CVE-2019-9553Dec 31, 2019risk 0.03cvss —epss 0.01
Bolt 3.6.4 has XSS via the slug, teaser, or title parameter to editcontent/pages, a related issue to CVE-2017-11128 and CVE-2018-19933.
- CVE-2019-13236Aug 27, 2019risk 0.03cvss —epss 0.04
In system/workplace/ in Alkacon OpenCms 10.5.4 and 10.5.5, there are multiple Reflected and Stored XSS issues in the management interface.
- CVE-2019-13235Aug 27, 2019risk 0.03cvss —epss 0.04
In the Alkacon OpenCms Apollo Template 10.5.4 and 10.5.5, there is XSS in the Login form.
- CVE-2019-13234Aug 27, 2019risk 0.03cvss —epss 0.02
In the Alkacon OpenCms Apollo Template 10.5.4 and 10.5.5, there is XSS in the search engine.
- CVE-2019-13068Jun 29, 2019risk 0.03cvss —epss 0.05
public/app/features/panel/panel_ctrl.ts in Grafana before 6.2.5 allows HTML Injection in panel drilldown links (via the Title or url field).
- CVE-2019-10226Jun 10, 2019risk 0.03cvss —epss 0.02
HTML Injection has been discovered in the v0.19.0 version of the Fat Free CRM product via an authenticated request to the /comments URI. NOTE: the vendor disputes the significance of this report because some HTML formatting (such as with an H1 element) is allowed, but there is a…
- CVE-2019-6588Jun 3, 2019risk 0.03cvss —epss 0.01
In Liferay Portal before 7.1 CE GA4, an XSS vulnerability exists in the SimpleCaptcha API when custom code passes unsanitized input into the "url" parameter of the JSP taglib call <liferay-ui:captcha url="<%= url %>" /> or <liferay-captcha:captcha url="<%= url %>" />. Liferay…
- CVE-2019-0186Apr 26, 2019risk 0.03cvss —epss 0.06
The input fields of the Apache Pluto "Chat Room" demo portlet 3.0.0 and 3.0.1 are vulnerable to Cross-Site Scripting (XSS) attacks. Mitigation: * Uninstall the ChatRoomDemo war file - or - * migrate to version 3.1.0 of the chat-room-demo war file
- CVE-2018-19799Dec 26, 2018risk 0.03cvss —epss 0.02
Dolibarr ERP/CRM through 8.0.3 has /exports/export.php?datatoexport= XSS.
- CVE-2018-20418Dec 24, 2018risk 0.03cvss —epss 0.00
index.php?p=admin/actions/entries/save-entry in Craft CMS 3.0.25 allows XSS by saving a new title from the console tab.
- CVE-2018-19933Dec 17, 2018risk 0.03cvss —epss 0.02
Bolt CMS <3.6.2 allows XSS via text input click preview button as demonstrated by the Title field of a Configured and New Entry.
- CVE-2018-18548Oct 24, 2018risk 0.03cvss —epss 0.02
ajenticp (aka Ajenti Docker control panel) for Ajenti through v1.2.23.13 has XSS via a filename that is mishandled in File Manager.
- CVE-2018-14059Aug 24, 2018risk 0.03cvss —epss 0.00
Pimcore allows XSS via Users, Assets, Data Objects, Video Thumbnails, Image Thumbnails, Field-Collections, Objectbrick, Classification Store, Document Types, Predefined Properties, Predefined Asset Metadata, Quantity Value, and Static Routes functions.
- CVE-2018-11564Jun 1, 2018risk 0.03cvss —epss 0.01
Stored XSS in YOOtheme Pagekit 1.0.13 and earlier allows a user to upload malicious code via the picture upload feature. A user with elevated privileges could upload a photo to the system in an SVG format. This file will be uploaded to the system and it will not be stripped or…
- CVE-2015-6176Dec 9, 2015risk 0.03cvss —epss 0.04
Microsoft Edge mishandles HTML attributes in HTTP responses, which allows remote attackers to bypass a cross-site scripting (XSS) protection mechanism via unspecified vectors, aka "Microsoft Edge XSS Filter Bypass Vulnerability."
- CVE-2015-8038Nov 2, 2015risk 0.03cvss —epss 0.02
Multiple cross-site scripting (XSS) vulnerabilities in the Graphical User Interface (GUI) in Fortinet FortiManager before 5.2.4 allow remote attackers to inject arbitrary web script or HTML via the (1) sharedjobmanager or (2) SOMServiceObjDialog.
- CVE-2015-8037Nov 2, 2015risk 0.03cvss —epss 0.02
Multiple cross-site scripting (XSS) vulnerabilities in the Graphical User Interface (GUI) in Fortinet FortiManager before 5.2.4 allow remote attackers to inject arbitrary web script or HTML via the (1) SOMVpnSSLPortalDialog or (2) FGDMngUpdHistory.
- CVE-2015-6494Oct 28, 2015risk 0.03cvss —epss 0.01
Cross-site scripting (XSS) vulnerability in Infinite Automation Mango Automation 2.5.x and 2.6.x before 2.6.0 build 430 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
- CVE-2015-6477Oct 18, 2015risk 0.03cvss —epss 0.33
Multiple cross-site scripting (XSS) vulnerabilities in the Wind Farm Portal application in Nordex Control 2 (NC2) SCADA 16 and earlier allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.