VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (46,607)

page 78 of 2,331
  • CVE-2022-28379MedApr 3, 2022
    risk 0.50cvss 6.8epss 0.71

    jc21.com Nginx Proxy Manager before 2.9.17 allows XSS during item deletion.

  • CVE-2021-45394HigJan 18, 2022
    risk 0.50cvss 8.8epss 0.02

    An issue was discovered in Spipu HTML2PDF before 5.2.4. Attackers can trigger deserialization of arbitrary data via the injection of a malicious tag in the converted HTML document.

  • CVE-2022-21662HigJan 6, 2022
    risk 0.50cvss 8.0epss 0.65

    WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. Low-privileged authenticated users (like author) in WordPress core are able to execute JavaScript/perform stored XSS attack, which can affect high-privileged users.…

  • CVE-2021-43853HigDec 22, 2021
    risk 0.50cvss 8.7epss 0.01

    Ajax.NET Professional (AjaxPro) is an AJAX framework available for Microsoft ASP.NET. Affected versions of this package are vulnerable to JavaScript object injection which may result in cross site scripting when leveraged by a malicious user. The affected core relates to…

  • CVE-2021-44544HigDec 22, 2021
    risk 0.50cvss 7.5epss 0.09

    DIAEnergie Version 1.7.5 and prior is vulnerable to multiple cross-site scripting vulnerabilities when arbitrary code is injected into the parameter “name” of the script “HandlerEnergyType.ashx”.

  • CVE-2021-22260HigNov 5, 2021
    risk 0.50cvss 7.7epss 0.01

    A stored Cross-Site Scripting vulnerability in the DataDog integration in all versions of GitLab CE/EE starting from 13.7 before 14.0.9, all versions starting from 14.1 before 14.1.4, and all versions starting from 14.2 before 14.2.2 allows an attacker to execute arbitrary…

  • CVE-2021-41134HigNov 3, 2021
    risk 0.50cvss 8.7epss 0.01

    nbdime provides tools for diffing and merging of Jupyter Notebooks. In affected versions a stored cross-site scripting (XSS) issue exists within the Jupyter-owned nbdime project. It appears that when reading the file name and path from disk, the extension does not sanitize the…

  • CVE-2021-41086HigSep 21, 2021
    risk 0.50cvss 8.7epss 0.01

    jsuites is an open source collection of common required javascript web components. In affected versions users are subject to cross site scripting (XSS) attacks via clipboard content. jsuites is vulnerable to DOM based XSS if the user can be tricked into copying _anything_ from a…

  • CVE-2021-39136HigAug 25, 2021
    risk 0.50cvss 8.7epss 0.01

    baserCMS is an open source content management system with a focus on Japanese language support. In affected versions there is a cross-site scripting vulnerability in the file upload function of the management system of baserCMS. Users are advised to update as soon as possible.…

  • CVE-2021-22238MedAug 20, 2021
    risk 0.50cvss 6.8epss 0.72

    An issue has been discovered in GitLab affecting all versions starting with 13.3. GitLab was vulnerable to a stored XSS by using the design feature in issues.

  • CVE-2021-28807HigJun 3, 2021
    risk 0.50cvss 7.7epss 0.01

    A post-authentication reflected XSS vulnerability has been reported to affect QNAP NAS running Q’center. If exploited, this vulnerability allows remote attackers to inject malicious code. QNAP have already fixed this vulnerability in the following versions of Q’center: QTS…

  • CVE-2021-32818HigMay 14, 2021
    risk 0.50cvss 7.7epss 0.01

    haml-coffee is a JavaScript templating solution. haml-coffee mixes pure template data with engine configuration options through the Express render API. More specifically, haml-coffee supports overriding a series of HTML helper functions through its configuration options. A…

  • CVE-2020-26225HigNov 16, 2020
    risk 0.50cvss 8.7epss 0.01

    In PrestaShop Product Comments before version 4.2.0, an attacker could inject malicious web code into the users' web browsers by creating a malicious link. The problem was introduced in version 4.0.0 and is fixed in 4.2.0

  • CVE-2020-15275HigNov 11, 2020
    risk 0.50cvss 8.7epss 0.02

    MoinMoin is a wiki engine. In MoinMoin before version 1.9.11, an attacker with write permissions can upload an SVG file that contains malicious javascript. This javascript will be executed in a user's browser when the user is viewing that SVG file on the wiki. Users are strongly…

  • CVE-2020-16872HigSep 11, 2020
    risk 0.50cvss 7.6epss 0.02

    A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) does not properly sanitize a specially crafted web request to an affected Dynamics server. An authenticated attacker could exploit the vulnerability by sending a specially crafted request to…

  • CVE-2020-11026HigApr 30, 2020
    risk 0.50cvss 8.7epss 0.02

    In affected versions of WordPress, files with a specially crafted name when uploaded to the Media section can lead to script execution upon accessing the file. This requires an authenticated user with privileges to upload files. This has been patched in version 5.4.1, along with…

  • CVE-2020-2096MedJan 15, 2020
    risk 0.50cvss 6.1epss 0.93

    Jenkins Gitlab Hook Plugin 1.4.2 and earlier does not escape project names in the build_now endpoint, resulting in a reflected XSS vulnerability.

  • CVE-2018-14631HigSep 17, 2018
    risk 0.50cvss 8.8epss 0.02

    moodle before versions 3.5.2, 3.4.5, 3.3.8 is vulnerable to a boost theme - blog search GET parameter insufficiently filtered. The breadcrumb navigation provided by Boost theme when displaying search results of a blog were insufficiently filtered, which could result in reflected…

  • CVE-2026-78071HigAug 28, 2026
    risk 0.49cvss epss 0.00

    Joomla Extension - digital-peak.com - Authenticated, privileged stored XSS in DP Calendar 7.0.0 - 10.11.2 - Location title is rendered in data attribute without escaping leads to XSS, needs create permission in DPCalendar.

  • CVE-2026-66155HigAug 27, 2026
    risk 0.49cvss 7.6epss 0.00

    A vulnerability has been identified in Element maps-ng V47 (All versions < V47.12.3), Element maps-ng V48 (All versions < V48.11.3), Element maps-ng V49 (All versions < V49.16.1). The si-map component does not properly neutralize user-controllable input of the points property…