VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (46,607)

page 69 of 2,331
  • CVE-2023-0742CriFeb 8, 2023
    risk 0.52cvss 9.0epss 0.01

    Cross-site Scripting (XSS) - Stored in GitHub repository answerdev/answer prior to 1.0.4.

  • CVE-2023-0741CriFeb 8, 2023
    risk 0.52cvss 9.0epss 0.01

    Cross-site Scripting (XSS) - DOM in GitHub repository answerdev/answer prior to 1.0.4.

  • CVE-2023-0740CriFeb 8, 2023
    risk 0.52cvss 9.0epss 0.01

    Cross-site Scripting (XSS) - Stored in GitHub repository answerdev/answer prior to 1.0.4.

  • CVE-2022-43532HigJan 5, 2023
    risk 0.52cvss 8.0epss 0.00

    A vulnerability in the web-based management interface of ClearPass Policy Manager could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against an administrative user of the interface. A successful exploit allows an attacker to…

  • CVE-2022-4866CriDec 31, 2022
    risk 0.52cvss 9.0epss 0.01

    Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.9.1.

  • CVE-2022-4865CriDec 31, 2022
    risk 0.52cvss 9.0epss 0.01

    Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.9.1.

  • CVE-2022-41266HigDec 13, 2022
    risk 0.52cvss 8.0epss 0.00

    Due to a lack of proper input validation, SAP Commerce Webservices 2.0 (Swagger UI) - versions 1905, 2005, 2105, 2011, 2205, allows malicious inputs from untrusted sources, which can be leveraged by an attacker to execute a DOM Cross-Site Scripting (XSS) attack.  As a result,…

  • CVE-2022-38754HigDec 8, 2022
    risk 0.52cvss 8.0epss 0.01

    A potential vulnerability has been identified in Micro Focus Operations Bridge - Containerized. The vulnerability could be exploited by a malicious authenticated OBM (Operations Bridge Manager) user to run Java Scripts in the browser context of another OBM user. Please note: The…

  • CVE-2022-41938CriNov 19, 2022
    risk 0.52cvss 9.0epss 0.01

    Flarum is an open source discussion platform. Flarum's page title system allowed for page titles to be converted into HTML DOM nodes when pages were rendered. The change was made after `v1.5` and was not noticed. This allowed an attacker to inject malicious HTML markup using a…

  • CVE-2022-43569HigNov 4, 2022
    risk 0.52cvss 8.0epss 0.01

    In Splunk Enterprise versions below 8.1.12, 8.2.9, and 9.0.2, an authenticated user can inject and store arbitrary scripts that can lead to persistent cross-site scripting (XSS) in the object name of a Data Model.

  • CVE-2022-39950HigNov 2, 2022
    risk 0.52cvss 8.0epss 0.01

    An improper neutralization of input during web page generation vulnerability [CWE-79] exists in FortiManager and FortiAnalyzer 6.0.0 all versions, 6.2.0 all versions, 6.4.0 through 6.4.8, and 7.0.0 through 7.0.4. Report templates may allow a low privilege level attacker to…

  • CVE-2022-38373HigNov 2, 2022
    risk 0.52cvss 8.0epss 0.00

    An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiDeceptor management interface 4.2.0, 4.1.0 through 4.1.1, 4.0.2 may allow an authenticated user to perform a cross site scripting (XSS) attack via sending requests with specially…

  • CVE-2022-35851HigNov 2, 2022
    risk 0.52cvss 8.0epss 0.00

    An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiADC management interface 7.1.0 may allow a remote and authenticated attacker to trigger a stored cross site scripting (XSS) attack via configuring a specially crafted IP Address.

  • CVE-2022-30578HigSep 21, 2022
    risk 0.52cvss 8.0epss 0.01

    The Web Server component of TIBCO Software Inc.'s TIBCO EBX Add-ons contains an easily exploitable vulnerability that allows a low privileged attacker with network access to execute Stored Cross Site Scripting (XSS) on the affected system. A successful attack using this…

  • CVE-2022-30577HigSep 21, 2022
    risk 0.52cvss 8.0epss 0.01

    The Web Server component of TIBCO Software Inc.'s TIBCO EBX contains an easily exploitable vulnerability that allows a low privileged attacker with network access to execute Stored Cross Site Scripting (XSS) on the affected system. A successful attack using this vulnerability…

  • CVE-2022-35131CriJul 25, 2022
    risk 0.52cvss 9.0epss 0.02

    Joplin v2.8.8 allows attackers to execute arbitrary commands via a crafted payload injected into the Node titles.

  • CVE-2016-1000273criJul 20, 2022
    risk 0.52cvss epss 0.02

    JavaMelody is a monitoring tool for JavaEE applications. Versions prior to 1.61.0 are vulnerable to a cross-site scripting (XSS) attack. This issue was patched in version 1.61.0, and users are recommended to upgrade to the latest version. There are no known workarounds.

  • CVE-2022-31035CriJun 27, 2022
    risk 0.52cvss 9.0epss 0.01

    Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. All versions of Argo CD starting with v1.0.0 are vulnerable to a cross-site scripting (XSS) bug allowing a malicious user to inject a `javascript:` link in the UI. When clicked by a victim user, the script…

  • CVE-2022-22776HigMay 18, 2022
    risk 0.52cvss 8.0epss 0.01

    The Web Server component of TIBCO Software Inc.'s TIBCO BusinessConnect Trading Community Management contains easily exploitable vulnerabilities that allows a low privileged attacker with network access to execute Stored Cross Site Scripting (XSS) on the affected system. A…

  • CVE-2022-28707HigMay 5, 2022
    risk 0.52cvss 8.0epss 0.01

    On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, and 14.1.x versions prior to 14.1.4.6, a stored cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility (also referred to as the BIG-IP TMUI)…