CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Description
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85
CVEs mapped to this weakness (46,607)
page 77 of 2,331| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-32484 | Hig | 0.50 | 7.4 | 0.21 | Jul 22, 2024 | An reflected XSS vulnerability exists in the handling of invalid paths in the Flask server in Ankitects Anki 24.04. A specially crafted flashcard can lead to JavaScript code execution and result in an arbitrary file read. An attacker can share a malicious flashcard to trigger… | ||
| CVE-2024-35267 | Hig | 0.50 | 7.6 | 0.02 | Jul 9, 2024 | Azure DevOps Server Spoofing Vulnerability | ||
| CVE-2024-35266 | Hig | 0.50 | 7.6 | 0.02 | Jul 9, 2024 | Azure DevOps Server Spoofing Vulnerability | ||
| CVE-2024-29022 | Hig | 0.50 | 8.8 | 0.01 | Apr 12, 2024 | Xibo is an Open Source Digital Signage platform with a web content management system and Windows display player software. In affected versions some request headers are not correctly sanitised when stored in the session and display tables. These headers can be used to inject a… | ||
| CVE-2024-3092 | Hig | 0.50 | 8.7 | 0.01 | Apr 12, 2024 | An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.9 before 16.9.4, all versions starting from 16.10 before 16.10.2. A payload may lead to a Stored XSS while using the diff viewer, allowing attackers to perform arbitrary actions on behalf of… | ||
| CVE-2024-29891 | Hig | 0.50 | 8.7 | 0.01 | Mar 27, 2024 | ZITADEL users can upload their own avatar image and various image types are allowed. Due to a missing check, an attacker could upload HTML and pretend it is an image to gain access to the victim's account in certain scenarios. A possible victim would need to directly open the… | ||
| CVE-2024-21328 | Hig | 0.50 | 7.6 | 0.01 | Feb 13, 2024 | Dynamics 365 Sales Spoofing Vulnerability | ||
| CVE-2024-21327 | Hig | 0.50 | 7.6 | 0.01 | Feb 13, 2024 | Microsoft Dynamics 365 Customer Engagement Cross-Site Scripting Vulnerability | ||
| CVE-2023-37520 | Hig | 0.50 | 7.7 | 0.00 | Dec 21, 2023 | Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability identified in BigFix Server version 9.5.12.68, allowing for potential data exfiltration. This XSS vulnerability is in the Gather Status Report, which is served by the BigFix Relay. | ||
| CVE-2023-37519 | Hig | 0.50 | 7.7 | 0.00 | Dec 21, 2023 | Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability. This XSS vulnerability is in the Download Status Report, which is served by the BigFix Server. | ||
| CVE-2022-45365 | Hig | 0.50 | 7.1 | 0.49 | Dec 14, 2023 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Aleksandar Urošević Stock Ticker allows Reflected XSS.This issue affects Stock Ticker: from n/a through 3.23.2. | ||
| CVE-2023-37979 | Hig | 0.50 | 7.1 | 0.10 | Jul 27, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Saturday Drive Ninja Forms Contact Form plugin <= 3.6.25 versions. | ||
| CVE-2023-35155 | Hig | 0.50 | 8.8 | 0.01 | Jun 23, 2023 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Users are able to forge an URL with a payload allowing to inject Javascript in the page (XSS). For instance, the following URL execute an `alter` on the browser:… | ||
| CVE-2023-3083 | Hig | 0.50 | 8.7 | 0.01 | Jun 3, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.9. | ||
| CVE-2022-33934 | Hig | 0.50 | 7.7 | 0.00 | Feb 10, 2023 | Dell PowerScale OneFS, versions 8.2.x through 9.4.x contain multiple stored cross-site scripting vulnerabilities. A remote authenticated malicious user with high privileges may potentially exploit these vulnerabilities to store malicious HTML or JavaScript code through multiple… | ||
| CVE-2023-24814 | Hig | 0.50 | 8.8 | 0.01 | Feb 7, 2023 | TYPO3 is a free and open source Content Management Framework released under the GNU General Public License. In affected versions the TYPO3 core component `GeneralUtility::getIndpEnv()` uses the unfiltered server environment variable `PATH_INFO`, which allows attackers to inject… | ||
| CVE-2022-35909 | Hig | 0.50 | 8.8 | 0.02 | Aug 19, 2022 | In Jellyfin before 10.8, the /users endpoint has incorrect access control for admin functionality. | ||
| CVE-2022-30999 | Hig | 0.50 | 8.7 | 0.01 | Jun 2, 2022 | FriendsofFlarum (FoF) Upload is an extension that handles file uploads intelligently for your forum. If FoF Upload prior to version 1.2.3 is configured to allow the uploading of SVG files ('image/svg+xml'), navigating directly to an SVG file URI could execute arbitrary… | ||
| CVE-2022-22773 | Hig | 0.50 | 7.7 | 0.01 | May 17, 2022 | The REST API component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server - Community Edition, TIBCO JasperReports Server - Developer Edition, TIBCO JasperReports Server for AWS Marketplace, TIBCO JasperReports Server for ActiveMatrix BPM, and TIBCO… | ||
| CVE-2020-25163 | Hig | 0.50 | 7.7 | 0.01 | Apr 18, 2022 | A remote attacker with write access to PI ProcessBook files could inject code that is imported into OSIsoft PI Vision 2020 versions prior to 3.5.0. Unauthorized information disclosure, modification, or deletion is also possible if a victim views or interacts with the infected… |
- risk 0.50cvss 7.4epss 0.21
An reflected XSS vulnerability exists in the handling of invalid paths in the Flask server in Ankitects Anki 24.04. A specially crafted flashcard can lead to JavaScript code execution and result in an arbitrary file read. An attacker can share a malicious flashcard to trigger…
- risk 0.50cvss 7.6epss 0.02
Azure DevOps Server Spoofing Vulnerability
- risk 0.50cvss 7.6epss 0.02
Azure DevOps Server Spoofing Vulnerability
- risk 0.50cvss 8.8epss 0.01
Xibo is an Open Source Digital Signage platform with a web content management system and Windows display player software. In affected versions some request headers are not correctly sanitised when stored in the session and display tables. These headers can be used to inject a…
- risk 0.50cvss 8.7epss 0.01
An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.9 before 16.9.4, all versions starting from 16.10 before 16.10.2. A payload may lead to a Stored XSS while using the diff viewer, allowing attackers to perform arbitrary actions on behalf of…
- risk 0.50cvss 8.7epss 0.01
ZITADEL users can upload their own avatar image and various image types are allowed. Due to a missing check, an attacker could upload HTML and pretend it is an image to gain access to the victim's account in certain scenarios. A possible victim would need to directly open the…
- risk 0.50cvss 7.6epss 0.01
Dynamics 365 Sales Spoofing Vulnerability
- risk 0.50cvss 7.6epss 0.01
Microsoft Dynamics 365 Customer Engagement Cross-Site Scripting Vulnerability
- risk 0.50cvss 7.7epss 0.00
Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability identified in BigFix Server version 9.5.12.68, allowing for potential data exfiltration. This XSS vulnerability is in the Gather Status Report, which is served by the BigFix Relay.
- risk 0.50cvss 7.7epss 0.00
Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability. This XSS vulnerability is in the Download Status Report, which is served by the BigFix Server.
- risk 0.50cvss 7.1epss 0.49
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Aleksandar Urošević Stock Ticker allows Reflected XSS.This issue affects Stock Ticker: from n/a through 3.23.2.
- risk 0.50cvss 7.1epss 0.10
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Saturday Drive Ninja Forms Contact Form plugin <= 3.6.25 versions.
- risk 0.50cvss 8.8epss 0.01
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Users are able to forge an URL with a payload allowing to inject Javascript in the page (XSS). For instance, the following URL execute an `alter` on the browser:…
- risk 0.50cvss 8.7epss 0.01
Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.9.
- risk 0.50cvss 7.7epss 0.00
Dell PowerScale OneFS, versions 8.2.x through 9.4.x contain multiple stored cross-site scripting vulnerabilities. A remote authenticated malicious user with high privileges may potentially exploit these vulnerabilities to store malicious HTML or JavaScript code through multiple…
- risk 0.50cvss 8.8epss 0.01
TYPO3 is a free and open source Content Management Framework released under the GNU General Public License. In affected versions the TYPO3 core component `GeneralUtility::getIndpEnv()` uses the unfiltered server environment variable `PATH_INFO`, which allows attackers to inject…
- risk 0.50cvss 8.8epss 0.02
In Jellyfin before 10.8, the /users endpoint has incorrect access control for admin functionality.
- risk 0.50cvss 8.7epss 0.01
FriendsofFlarum (FoF) Upload is an extension that handles file uploads intelligently for your forum. If FoF Upload prior to version 1.2.3 is configured to allow the uploading of SVG files ('image/svg+xml'), navigating directly to an SVG file URI could execute arbitrary…
- risk 0.50cvss 7.7epss 0.01
The REST API component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server - Community Edition, TIBCO JasperReports Server - Developer Edition, TIBCO JasperReports Server for AWS Marketplace, TIBCO JasperReports Server for ActiveMatrix BPM, and TIBCO…
- risk 0.50cvss 7.7epss 0.01
A remote attacker with write access to PI ProcessBook files could inject code that is imported into OSIsoft PI Vision 2020 versions prior to 3.5.0. Unauthorized information disclosure, modification, or deletion is also possible if a victim views or interacts with the infected…