VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (46,607)

page 77 of 2,331
  • CVE-2024-32484HigJul 22, 2024
    risk 0.50cvss 7.4epss 0.21

    An reflected XSS vulnerability exists in the handling of invalid paths in the Flask server in Ankitects Anki 24.04. A specially crafted flashcard can lead to JavaScript code execution and result in an arbitrary file read. An attacker can share a malicious flashcard to trigger…

  • CVE-2024-35267HigJul 9, 2024
    risk 0.50cvss 7.6epss 0.02

    Azure DevOps Server Spoofing Vulnerability

  • CVE-2024-35266HigJul 9, 2024
    risk 0.50cvss 7.6epss 0.02

    Azure DevOps Server Spoofing Vulnerability

  • CVE-2024-29022HigApr 12, 2024
    risk 0.50cvss 8.8epss 0.01

    Xibo is an Open Source Digital Signage platform with a web content management system and Windows display player software. In affected versions some request headers are not correctly sanitised when stored in the session and display tables. These headers can be used to inject a…

  • CVE-2024-3092HigApr 12, 2024
    risk 0.50cvss 8.7epss 0.01

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.9 before 16.9.4, all versions starting from 16.10 before 16.10.2. A payload may lead to a Stored XSS while using the diff viewer, allowing attackers to perform arbitrary actions on behalf of…

  • CVE-2024-29891HigMar 27, 2024
    risk 0.50cvss 8.7epss 0.01

    ZITADEL users can upload their own avatar image and various image types are allowed. Due to a missing check, an attacker could upload HTML and pretend it is an image to gain access to the victim's account in certain scenarios. A possible victim would need to directly open the…

  • CVE-2024-21328HigFeb 13, 2024
    risk 0.50cvss 7.6epss 0.01

    Dynamics 365 Sales Spoofing Vulnerability

  • CVE-2024-21327HigFeb 13, 2024
    risk 0.50cvss 7.6epss 0.01

    Microsoft Dynamics 365 Customer Engagement Cross-Site Scripting Vulnerability

  • CVE-2023-37520HigDec 21, 2023
    risk 0.50cvss 7.7epss 0.00

    Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability identified in BigFix Server version 9.5.12.68, allowing for potential data exfiltration. This XSS vulnerability is in the Gather Status Report, which is served by the BigFix Relay.

  • CVE-2023-37519HigDec 21, 2023
    risk 0.50cvss 7.7epss 0.00

    Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability. This XSS vulnerability is in the Download Status Report, which is served by the BigFix Server. 

  • CVE-2022-45365HigDec 14, 2023
    risk 0.50cvss 7.1epss 0.49

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Aleksandar Urošević Stock Ticker allows Reflected XSS.This issue affects Stock Ticker: from n/a through 3.23.2.

  • CVE-2023-37979HigJul 27, 2023
    risk 0.50cvss 7.1epss 0.10

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Saturday Drive Ninja Forms Contact Form plugin <= 3.6.25 versions.

  • CVE-2023-35155HigJun 23, 2023
    risk 0.50cvss 8.8epss 0.01

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Users are able to forge an URL with a payload allowing to inject Javascript in the page (XSS). For instance, the following URL execute an `alter` on the browser:…

  • CVE-2023-3083HigJun 3, 2023
    risk 0.50cvss 8.7epss 0.01

    Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.9.

  • CVE-2022-33934HigFeb 10, 2023
    risk 0.50cvss 7.7epss 0.00

    Dell PowerScale OneFS, versions 8.2.x through 9.4.x contain multiple stored cross-site scripting vulnerabilities. A remote authenticated malicious user with high privileges may potentially exploit these vulnerabilities to store malicious HTML or JavaScript code through multiple…

  • CVE-2023-24814HigFeb 7, 2023
    risk 0.50cvss 8.8epss 0.01

    TYPO3 is a free and open source Content Management Framework released under the GNU General Public License. In affected versions the TYPO3 core component `GeneralUtility::getIndpEnv()` uses the unfiltered server environment variable `PATH_INFO`, which allows attackers to inject…

  • CVE-2022-35909HigAug 19, 2022
    risk 0.50cvss 8.8epss 0.02

    In Jellyfin before 10.8, the /users endpoint has incorrect access control for admin functionality.

  • CVE-2022-30999HigJun 2, 2022
    risk 0.50cvss 8.7epss 0.01

    FriendsofFlarum (FoF) Upload is an extension that handles file uploads intelligently for your forum. If FoF Upload prior to version 1.2.3 is configured to allow the uploading of SVG files ('image/svg+xml'), navigating directly to an SVG file URI could execute arbitrary…

  • CVE-2022-22773HigMay 17, 2022
    risk 0.50cvss 7.7epss 0.01

    The REST API component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server - Community Edition, TIBCO JasperReports Server - Developer Edition, TIBCO JasperReports Server for AWS Marketplace, TIBCO JasperReports Server for ActiveMatrix BPM, and TIBCO…

  • CVE-2020-25163HigApr 18, 2022
    risk 0.50cvss 7.7epss 0.01

    A remote attacker with write access to PI ProcessBook files could inject code that is imported into OSIsoft PI Vision 2020 versions prior to 3.5.0. Unauthorized information disclosure, modification, or deletion is also possible if a victim views or interacts with the infected…