CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Description
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85
CVEs mapped to this weakness (46,607)
page 69 of 2,331| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-0742 | Cri | 0.52 | 9.0 | 0.01 | Feb 8, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository answerdev/answer prior to 1.0.4. | ||
| CVE-2023-0741 | Cri | 0.52 | 9.0 | 0.01 | Feb 8, 2023 | Cross-site Scripting (XSS) - DOM in GitHub repository answerdev/answer prior to 1.0.4. | ||
| CVE-2023-0740 | Cri | 0.52 | 9.0 | 0.01 | Feb 8, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository answerdev/answer prior to 1.0.4. | ||
| CVE-2022-43532 | Hig | 0.52 | 8.0 | 0.00 | Jan 5, 2023 | A vulnerability in the web-based management interface of ClearPass Policy Manager could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against an administrative user of the interface. A successful exploit allows an attacker to… | ||
| CVE-2022-4866 | Cri | 0.52 | 9.0 | 0.01 | Dec 31, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.9.1. | ||
| CVE-2022-4865 | Cri | 0.52 | 9.0 | 0.01 | Dec 31, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.9.1. | ||
| CVE-2022-41266 | Hig | 0.52 | 8.0 | 0.00 | Dec 13, 2022 | Due to a lack of proper input validation, SAP Commerce Webservices 2.0 (Swagger UI) - versions 1905, 2005, 2105, 2011, 2205, allows malicious inputs from untrusted sources, which can be leveraged by an attacker to execute a DOM Cross-Site Scripting (XSS) attack. As a result,… | ||
| CVE-2022-38754 | Hig | 0.52 | 8.0 | 0.01 | Dec 8, 2022 | A potential vulnerability has been identified in Micro Focus Operations Bridge - Containerized. The vulnerability could be exploited by a malicious authenticated OBM (Operations Bridge Manager) user to run Java Scripts in the browser context of another OBM user. Please note: The… | ||
| CVE-2022-41938 | Cri | 0.52 | 9.0 | 0.01 | Nov 19, 2022 | Flarum is an open source discussion platform. Flarum's page title system allowed for page titles to be converted into HTML DOM nodes when pages were rendered. The change was made after `v1.5` and was not noticed. This allowed an attacker to inject malicious HTML markup using a… | ||
| CVE-2022-43569 | Hig | 0.52 | 8.0 | 0.01 | Nov 4, 2022 | In Splunk Enterprise versions below 8.1.12, 8.2.9, and 9.0.2, an authenticated user can inject and store arbitrary scripts that can lead to persistent cross-site scripting (XSS) in the object name of a Data Model. | ||
| CVE-2022-39950 | Hig | 0.52 | 8.0 | 0.01 | Nov 2, 2022 | An improper neutralization of input during web page generation vulnerability [CWE-79] exists in FortiManager and FortiAnalyzer 6.0.0 all versions, 6.2.0 all versions, 6.4.0 through 6.4.8, and 7.0.0 through 7.0.4. Report templates may allow a low privilege level attacker to… | ||
| CVE-2022-38373 | Hig | 0.52 | 8.0 | 0.00 | Nov 2, 2022 | An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiDeceptor management interface 4.2.0, 4.1.0 through 4.1.1, 4.0.2 may allow an authenticated user to perform a cross site scripting (XSS) attack via sending requests with specially… | ||
| CVE-2022-35851 | Hig | 0.52 | 8.0 | 0.00 | Nov 2, 2022 | An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiADC management interface 7.1.0 may allow a remote and authenticated attacker to trigger a stored cross site scripting (XSS) attack via configuring a specially crafted IP Address. | ||
| CVE-2022-30578 | Hig | 0.52 | 8.0 | 0.01 | Sep 21, 2022 | The Web Server component of TIBCO Software Inc.'s TIBCO EBX Add-ons contains an easily exploitable vulnerability that allows a low privileged attacker with network access to execute Stored Cross Site Scripting (XSS) on the affected system. A successful attack using this… | ||
| CVE-2022-30577 | Hig | 0.52 | 8.0 | 0.01 | Sep 21, 2022 | The Web Server component of TIBCO Software Inc.'s TIBCO EBX contains an easily exploitable vulnerability that allows a low privileged attacker with network access to execute Stored Cross Site Scripting (XSS) on the affected system. A successful attack using this vulnerability… | ||
| CVE-2022-35131 | Cri | 0.52 | 9.0 | 0.02 | Jul 25, 2022 | Joplin v2.8.8 allows attackers to execute arbitrary commands via a crafted payload injected into the Node titles. | ||
| CVE-2016-1000273 | cri | 0.52 | — | 0.02 | Jul 20, 2022 | JavaMelody is a monitoring tool for JavaEE applications. Versions prior to 1.61.0 are vulnerable to a cross-site scripting (XSS) attack. This issue was patched in version 1.61.0, and users are recommended to upgrade to the latest version. There are no known workarounds. | ||
| CVE-2022-31035 | Cri | 0.52 | 9.0 | 0.01 | Jun 27, 2022 | Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. All versions of Argo CD starting with v1.0.0 are vulnerable to a cross-site scripting (XSS) bug allowing a malicious user to inject a `javascript:` link in the UI. When clicked by a victim user, the script… | ||
| CVE-2022-22776 | Hig | 0.52 | 8.0 | 0.01 | May 18, 2022 | The Web Server component of TIBCO Software Inc.'s TIBCO BusinessConnect Trading Community Management contains easily exploitable vulnerabilities that allows a low privileged attacker with network access to execute Stored Cross Site Scripting (XSS) on the affected system. A… | ||
| CVE-2022-28707 | Hig | 0.52 | 8.0 | 0.01 | May 5, 2022 | On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, and 14.1.x versions prior to 14.1.4.6, a stored cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility (also referred to as the BIG-IP TMUI)… |
- risk 0.52cvss 9.0epss 0.01
Cross-site Scripting (XSS) - Stored in GitHub repository answerdev/answer prior to 1.0.4.
- risk 0.52cvss 9.0epss 0.01
Cross-site Scripting (XSS) - DOM in GitHub repository answerdev/answer prior to 1.0.4.
- risk 0.52cvss 9.0epss 0.01
Cross-site Scripting (XSS) - Stored in GitHub repository answerdev/answer prior to 1.0.4.
- risk 0.52cvss 8.0epss 0.00
A vulnerability in the web-based management interface of ClearPass Policy Manager could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against an administrative user of the interface. A successful exploit allows an attacker to…
- risk 0.52cvss 9.0epss 0.01
Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.9.1.
- risk 0.52cvss 9.0epss 0.01
Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.9.1.
- risk 0.52cvss 8.0epss 0.00
Due to a lack of proper input validation, SAP Commerce Webservices 2.0 (Swagger UI) - versions 1905, 2005, 2105, 2011, 2205, allows malicious inputs from untrusted sources, which can be leveraged by an attacker to execute a DOM Cross-Site Scripting (XSS) attack. As a result,…
- risk 0.52cvss 8.0epss 0.01
A potential vulnerability has been identified in Micro Focus Operations Bridge - Containerized. The vulnerability could be exploited by a malicious authenticated OBM (Operations Bridge Manager) user to run Java Scripts in the browser context of another OBM user. Please note: The…
- risk 0.52cvss 9.0epss 0.01
Flarum is an open source discussion platform. Flarum's page title system allowed for page titles to be converted into HTML DOM nodes when pages were rendered. The change was made after `v1.5` and was not noticed. This allowed an attacker to inject malicious HTML markup using a…
- risk 0.52cvss 8.0epss 0.01
In Splunk Enterprise versions below 8.1.12, 8.2.9, and 9.0.2, an authenticated user can inject and store arbitrary scripts that can lead to persistent cross-site scripting (XSS) in the object name of a Data Model.
- risk 0.52cvss 8.0epss 0.01
An improper neutralization of input during web page generation vulnerability [CWE-79] exists in FortiManager and FortiAnalyzer 6.0.0 all versions, 6.2.0 all versions, 6.4.0 through 6.4.8, and 7.0.0 through 7.0.4. Report templates may allow a low privilege level attacker to…
- risk 0.52cvss 8.0epss 0.00
An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiDeceptor management interface 4.2.0, 4.1.0 through 4.1.1, 4.0.2 may allow an authenticated user to perform a cross site scripting (XSS) attack via sending requests with specially…
- risk 0.52cvss 8.0epss 0.00
An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiADC management interface 7.1.0 may allow a remote and authenticated attacker to trigger a stored cross site scripting (XSS) attack via configuring a specially crafted IP Address.
- risk 0.52cvss 8.0epss 0.01
The Web Server component of TIBCO Software Inc.'s TIBCO EBX Add-ons contains an easily exploitable vulnerability that allows a low privileged attacker with network access to execute Stored Cross Site Scripting (XSS) on the affected system. A successful attack using this…
- risk 0.52cvss 8.0epss 0.01
The Web Server component of TIBCO Software Inc.'s TIBCO EBX contains an easily exploitable vulnerability that allows a low privileged attacker with network access to execute Stored Cross Site Scripting (XSS) on the affected system. A successful attack using this vulnerability…
- risk 0.52cvss 9.0epss 0.02
Joplin v2.8.8 allows attackers to execute arbitrary commands via a crafted payload injected into the Node titles.
- risk 0.52cvss —epss 0.02
JavaMelody is a monitoring tool for JavaEE applications. Versions prior to 1.61.0 are vulnerable to a cross-site scripting (XSS) attack. This issue was patched in version 1.61.0, and users are recommended to upgrade to the latest version. There are no known workarounds.
- risk 0.52cvss 9.0epss 0.01
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. All versions of Argo CD starting with v1.0.0 are vulnerable to a cross-site scripting (XSS) bug allowing a malicious user to inject a `javascript:` link in the UI. When clicked by a victim user, the script…
- risk 0.52cvss 8.0epss 0.01
The Web Server component of TIBCO Software Inc.'s TIBCO BusinessConnect Trading Community Management contains easily exploitable vulnerabilities that allows a low privileged attacker with network access to execute Stored Cross Site Scripting (XSS) on the affected system. A…
- risk 0.52cvss 8.0epss 0.01
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, and 14.1.x versions prior to 14.1.4.6, a stored cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility (also referred to as the BIG-IP TMUI)…