VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (46,607)

page 72 of 2,331
  • CVE-2023-41471HigAug 29, 2025
    risk 0.51cvss 7.8epss 0.00

    Cross Site Scripting vulnerability in copyparty before 1.9.2 allows a local attacker to execute arbitrary code via a crafted payload to the WEEKEND-PLANS function. NOTE: this is disputed because WEEKEND-PLANS is accessible only to actors who already have write access to the…

  • CVE-2024-52281HigApr 16, 2025
    risk 0.51cvss 8.9epss 0.01

    A: Improper Neutralization of Input During Web Page Generation vulnerability in SUSE rancher allows a malicious actor to perform a Stored XSS attack through the cluster description field. This issue affects rancher: from 2.9.0 before 2.9.4.

  • CVE-2024-12755HigFeb 11, 2025
    risk 0.51cvss 7.9epss 0.00

    A Cross-Site Scripting (XSS) vulnerability in Avaya Spaces may have allowed unauthorized code execution and potential disclose of sensitive information.

  • CVE-2024-54139HigDec 13, 2024
    risk 0.51cvss 7.9epss 0.00

    Combodo iTop is an open source and web-based IT service management platform. Prior to versions 2.7.11, 3.1.2, and 3.2.0., iTop has a cross-site scripting vulnerability that can lead to cross-site request forgery on the `_table_id` parameter. Versions 2.7.11, 3.1.2, and 3.2.0…

  • CVE-2024-6497HigJul 20, 2024
    risk 0.51cvss 8.8epss 0.11

    The SEO Plugin by Squirrly SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter in all versions up to, and including, 12.3.19 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…

  • CVE-2024-37166HigJun 10, 2024
    risk 0.51cvss 8.9epss 0.00

    ghtml is software that uses tagged templates for template engine functionality. It is possible to introduce user-controlled JavaScript code and trigger a Cross-Site Scripting (XSS) vulnerability in some cases. Version 2.0.0 introduces changes to mitigate this issue. Version…

  • CVE-2024-36413HigJun 10, 2024
    risk 0.51cvss 8.9epss 0.00

    SuiteCRM is an open-source Customer Relationship Management (CRM) software application. Prior to versions 7.14.4 and 8.6.1, a vulnerability in the import module error view allows for a cross-site scripting attack. Versions 7.14.4 and 8.6.1 contain a fix for this issue.

  • CVE-2024-37063HigJun 4, 2024
    risk 0.51cvss 7.8epss 0.00

    A cross-site scripting (XSS) vulnerability in versions 3.7.0 or newer of Ydata's ydata-profiling open-source library allows for payloads to be run when a maliocusly crafted report is viewed in the browser.

  • CVE-2024-29000HigMay 20, 2024
    risk 0.51cvss 7.9epss 0.00

    The SolarWinds Platform was determined to be affected by a reflected cross-site scripting vulnerability affecting the web console. A high-privileged user and user interaction is required to exploit this vulnerability.

  • CVE-2023-25365HigFeb 8, 2024
    risk 0.51cvss 7.8epss 0.00

    Cross Site Scripting vulnerability found in October CMS v.3.2.0 allows local attacker to execute arbitrary code via the file type .mp3

  • CVE-2023-29207HigApr 15, 2023
    risk 0.51cvss 8.9epss 0.01

    XWiki Commons are technical libraries common to several other top level XWiki projects. The Livetable Macro wasn't properly sanitizing column names, thus allowing the insertion of raw HTML code including JavaScript. This vulnerability was also exploitable via the Documents…

  • CVE-2023-26480HigMar 2, 2023
    risk 0.51cvss 8.9epss 0.01

    XWiki Platform is a generic wiki platform. Starting in version 12.10, a user without script rights can introduce a stored cross-site scripting by using the Live Data macro. This has been patched in XWiki 14.9, 14.4.7, and 13.10.10. There are no known workarounds.

  • CVE-2022-1940HigJun 6, 2022
    risk 0.51cvss 7.7epss 0.06

    A Stored Cross-Site Scripting vulnerability in Jira integration in GitLab EE affecting all versions from 13.11 prior to 14.9.5, 14.10 prior to 14.10.4, and 15.0 prior to 15.0.1 allows an attacker to execute arbitrary JavaScript code in GitLab on a victim's behalf via specially…

  • CVE-2021-26829MedKEVJun 11, 2021
    risk 0.51cvss 5.4epss 0.48

    OpenPLC ScadaBR through 0.9.1 on Linux and through 1.12.4 on Windows allows stored XSS via system_settings.shtm.

  • CVE-2021-21028HigFeb 11, 2021
    risk 0.51cvss 8.8epss 0.04

    Acrobat Reader DC versions versions 2020.013.20074 (and earlier), 2020.001.30018 (and earlier) and 2017.011.30188 (and earlier) are affected by a Use After Free vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in…

  • CVE-2020-25399HigNov 5, 2020
    risk 0.51cvss 7.8epss 0.01

    Stored XSS in InterMind iMind Server through 3.13.65 allows any user to hijack another user's session by sending a malicious file in the chat.

  • CVE-2020-9496MedJul 15, 2020
    risk 0.51cvss 6.1epss 0.99

    XML-RPC request are vulnerable to unsafe deserialization and Cross-Site Scripting issues in Apache OFBiz 17.12.03

  • CVE-2018-11449HigJun 26, 2018
    risk 0.51cvss 7.8epss 0.00

    A vulnerability has been identified in SCALANCE M875 (All versions). An attacker with access to the local file system might obtain passwords for administrative users. Successful exploitation requires read access to files on the local file system. A successful attack could allow…

  • CVE-2026-82089HigAug 28, 2026
    risk 0.50cvss epss 0.00

    The wallabag (aka fr.gaulupeau.apps.InThePoche) application through 2.6.0 for Android allows XSS because /api/entries data is loaded into a WebView.

  • CVE-2026-47665HigAug 26, 2026
    risk 0.50cvss 8.7epss 0.00

    Penpot is an open-source design and prototyping platform. In versions up to and including 2.14.3, Penpot is vulnerable to stored cross-site scripting through file comments, whose content is stored as raw text and rendered into the page with innerHTML without any sanitization.…