VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (46,607)

page 68 of 2,331
  • CVE-2023-37425HigAug 22, 2023
    risk 0.52cvss 8.0epss 0.00

    A vulnerability in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an unauthenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against an administrative user of the interface. A successful exploit allows…

  • CVE-2023-36892HigAug 8, 2023
    risk 0.52cvss 8.0epss 0.02

    Microsoft SharePoint Server Spoofing Vulnerability

  • CVE-2023-36891HigAug 8, 2023
    risk 0.52cvss 8.0epss 0.02

    Microsoft SharePoint Server Spoofing Vulnerability

  • CVE-2023-32652HigJul 7, 2023
    risk 0.52cvss 8.0epss 0.00

    PiiGAB M-Bus does not validate identification strings before processing, which could make it vulnerable to cross-site scripting attacks.

  • CVE-2023-36477CriJun 30, 2023
    risk 0.52cvss 9.0epss 0.01

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user with edit rights can edit all pages in the `CKEditor' space. This makes it possible to perform a variety of harmful actions, such as removing technical documents,…

  • CVE-2023-36471CriJun 29, 2023
    risk 0.52cvss 9.0epss 0.01

    Xwiki commons is the common modules used by other XWiki top level projects. The HTML sanitizer that is included in XWiki since version 14.6RC1 allowed form and input HTML tags. In the context of XWiki, this allows an attacker without script right to either create forms that can…

  • CVE-2023-35153CriJun 23, 2023
    risk 0.52cvss 9.0epss 0.01

    XWiki Platform is a generic wiki platform. Starting in version 5.4.4 and prior to versions 14.4.8, 14.10.4, and 15.0, a stored cross-site scripting vulnerability can be exploited by users with edit rights by adding a `AppWithinMinutes.FormFieldCategoryClass` class on a page and…

  • CVE-2023-34464CriJun 23, 2023
    risk 0.52cvss 9.0epss 0.01

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Starting in version 2.2.1 until versions 14.4.8, 14.10.5, and 15.1RC1 of org.xwiki.platform:xwiki-platform-web and any version prior to 14.4.8, 14.10.5, and 15.1.RC1 of…

  • CVE-2023-3086CriJun 3, 2023
    risk 0.52cvss 9.0epss 0.01

    Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.9.

  • CVE-2023-32070CriMay 10, 2023
    risk 0.52cvss 9.0epss 0.01

    XWiki Platform is a generic wiki platform. Prior to version 14.6-rc-1, HTML rendering didn't check for dangerous attributes/attribute values. This allowed cross-site scripting (XSS) attacks via attributes and link URLs, e.g., supported in XWiki syntax. This has been patched in…

  • CVE-2023-31126CriMay 9, 2023
    risk 0.52cvss 9.0epss 0.01

    `org.xwiki.commons:xwiki-commons-xml` is an XML library used by the open-source wiki platform XWiki. The HTML sanitizer, introduced in version 14.6-rc-1, allows the injection of arbitrary HTML code and thus cross-site scripting via invalid data attributes. This vulnerability…

  • CVE-2023-30860HigMay 8, 2023
    risk 0.52cvss 8.0epss 0.01

    WWBN AVideo is an open source video platform. In AVideo prior to version 12.4, a normal user can make a Meeting Schedule where the user can invite another user in that Meeting, but it does not properly sanitize the malicious characters when creating a Meeting Room. This allows…

  • CVE-2023-29528CriApr 20, 2023
    risk 0.52cvss 9.0epss 0.01

    XWiki Commons are technical libraries common to several other top level XWiki projects. The "restricted" mode of the HTML cleaner in XWiki, introduced in version 4.2-milestone-1 and massively improved in version 14.6-rc-1, allowed the injection of arbitrary HTML code and thus…

  • CVE-2023-29206CriApr 15, 2023
    risk 0.52cvss 9.0epss 0.01

    XWiki Commons are technical libraries common to several other top level XWiki projects. There was no check in the author of a JavaScript xobject or StyleSheet xobject added in a XWiki document, so until now it was possible for a user having only Edit Right to create such object…

  • CVE-2023-29202CriApr 15, 2023
    risk 0.52cvss 9.0epss 0.01

    XWiki Commons are technical libraries common to several other top level XWiki projects. The RSS macro that is bundled in XWiki included the content of the feed items without any cleaning in the HTML output when the parameter `content` was set to `true`. This allowed arbitrary…

  • CVE-2023-29201CriApr 15, 2023
    risk 0.52cvss 9.0epss 0.01

    XWiki Commons are technical libraries common to several other top level XWiki projects. The "restricted" mode of the HTML cleaner in XWiki, introduced in version 4.2-milestone-1, only escaped `` and ``-tags but neither attributes that can be used to inject scripts…

  • CVE-2022-45064HigApr 13, 2023
    risk 0.52cvss 8.0epss 0.01

    The SlingRequestDispatcher doesn't correctly implement the RequestDispatcher API resulting in a generic type of include-based cross-site scripting issues on the Apache Sling level. The vulnerability is exploitable by an attacker that is able to include a resource with specific…

  • CVE-2023-0084HigMar 2, 2023
    risk 0.52cvss 7.2epss 0.29

    The Metform Elementor Contact Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via text areas on forms in versions up to, and including, 3.1.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated…

  • CVE-2023-22933HigFeb 14, 2023
    risk 0.52cvss 8.0epss 0.01

    In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, a View allows for Cross-Site Scripting (XSS) in an extensible mark-up language (XML) View through the ‘layoutPanel’ attribute in the ‘module’ tag’.

  • CVE-2023-0743CriFeb 8, 2023
    risk 0.52cvss 9.0epss 0.01

    Cross-site Scripting (XSS) - Generic in GitHub repository answerdev/answer prior to 1.0.4.