CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Description
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85
CVEs mapped to this weakness (23,319)
page 812 of 1,166| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-45613 | 0.00 | — | 0.00 | Sep 25, 2024 | CKEditor 5 is a JavaScript rich-text editor. Starting in version 40.0.0 and prior to version 43.1.1, a Cross-Site Scripting (XSS) vulnerability is present in the CKEditor 5 clipboard package. This vulnerability could be triggered by a specific user action, leading to… | |||
| CVE-2024-9148 | — | 0.00 | — | 0.01 | Sep 24, 2024 | Flowise < 2.1.1 suffers from a Stored Cross-Site vulnerability due to a lack of input sanitization in Flowise Chat Embed < 2.0.0. | ||
| CVE-2024-47069 | — | 0.00 | — | 0.00 | Sep 23, 2024 | Oveleon Cookie Bar is a cookie bar is for the Contao Open Source CMS and allows a visitor to define cookie & privacy settings for the website. Prior to versions 1.16.3 and 2.1.3, the `block/locale` endpoint does not properly sanitize the user-controlled `locale` input before… | ||
| CVE-2024-47068 | 0.00 | — | 0.01 | Sep 23, 2024 | Rollup is a module bundler for JavaScript. Versions prior to 2.79.2, 3.29.5, and 4.22.4 are susceptible to a DOM Clobbering vulnerability when bundling scripts with properties from `import.meta` (e.g., `import.meta.url`) in `cjs`/`umd`/`iife` format. The DOM Clobbering gadget… | |||
| CVE-2021-27917 | 0.00 | — | 0.00 | Sep 18, 2024 | Prior to this patch, a stored XSS vulnerability existed in the contact tracking and page hits report. | |||
| CVE-2024-47050 | 0.00 | — | 0.00 | Sep 18, 2024 | Prior to this patch being applied, Mautic's tracking was vulnerable to Cross-Site Scripting through the Page URL variable. | |||
| CVE-2024-47058 | 0.00 | — | 0.00 | Sep 18, 2024 | With access to edit a Mautic form, the attacker can add Cross-Site Scripting stored in the html filed. This could be used to steal sensitive information from the user's current session. | |||
| CVE-2022-25774 | 0.00 | — | 0.00 | Sep 18, 2024 | Prior to the patched version, logged in users of Mautic are vulnerable to a self XSS vulnerability in the notifications within Mautic. Users could inject malicious code into the notification when saving Dashboards. | |||
| CVE-2024-46976 | 0.00 | — | 0.00 | Sep 17, 2024 | Backstage is an open framework for building developer portals. An attacker with control of the contents of the TechDocs storage buckets is able to inject executable scripts in the TechDocs content that will be executed in the victim's browser when browsing documentation or… | |||
| CVE-2024-45612 | 0.00 | — | 0.00 | Sep 17, 2024 | Contao is an Open Source CMS. In affected versions an untrusted user can inject insert tags into the canonical tag, which are then replaced on the web page (front end). Users are advised to update to Contao 4.13.49, 5.3.15 or 5.4.3. Users unable to upgrade should disable… | |||
| CVE-2024-45803 | 0.00 | — | 0.00 | Sep 17, 2024 | Wire UI is a library of components and resources to empower Laravel and Livewire application development. A potential Cross-Site Scripting (XSS) vulnerability has been identified in the `/wireui/button` endpoint, specifically through the `label` query parameter. Malicious actors… | |||
| CVE-2021-27915 | 0.00 | — | 0.01 | Sep 17, 2024 | Prior to the patched version, there is an XSS vulnerability in the description fields within the Mautic application which could be exploited by a logged in user of Mautic with the appropriate permissions. This could lead to the user having elevated access to the system. | |||
| CVE-2024-39910 | 0.00 | — | 0.00 | Sep 16, 2024 | decidim is a Free Open-Source participatory democracy, citizen participation and open government for cities and organizations. The WYSWYG editor QuillJS is subject to potential XSS attach in case the attacker manages to modify the HTML before being uploaded to the server. The… | |||
| CVE-2024-32034 | 0.00 | — | 0.00 | Sep 16, 2024 | decidim is a Free Open-Source participatory democracy, citizen participation and open government for cities and organizations. The admin panel is subject to potential Cross-site scripting (XSS) attach in case an admin assigns a valuator to a proposal, or does any other action… | |||
| CVE-2024-8863 | 0.00 | — | 0.00 | Sep 14, 2024 | A vulnerability, which was classified as problematic, was found in aimhubio aim up to 3.24. Affected is the function dangerouslySetInnerHTML of the file textbox.tsx of the component Text Explorer. The manipulation of the argument query leads to cross site scripting. It is… | |||
| CVE-2024-45856 | 0.00 | — | 0.00 | Sep 12, 2024 | A cross-site scripting (XSS) vulnerability exists in all versions of the MindsDB platform, enabling the execution of a JavaScript payload whenever a user enumerates an ML Engine, database, project, or dataset containing arbitrary JavaScript code within the web UI. | |||
| CVE-2024-45595 | 0.00 | — | 0.01 | Sep 10, 2024 | D-Tale is a visualizer for Pandas data structures. Users hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. Users should upgrade to version 3.14.1 where the "Custom Filter" input is turned off by default. | |||
| CVE-2024-45592 | 0.00 | — | 0.00 | Sep 10, 2024 | auditor-bundle, formerly known as DoctrineAuditBundle, integrates auditor library into any Symfony 3.4+ application. Prior to version 5.2.6, there is an unescaped entity property enabling Javascript injection. This is possible because `%source_label%` in twig macro is not… | |||
| CVE-2024-43800 | — | 0.00 | — | 0.01 | Sep 10, 2024 | serve-static serves static files. serve-static passes untrusted user input - even after sanitizing it - to redirect() may execute untrusted code. This issue is patched in serve-static 1.16.0. | ||
| CVE-2024-43799 | — | 0.00 | — | 0.01 | Sep 10, 2024 | Send is a library for streaming files from the file system as a http response. Send passes untrusted user input to SendStream.redirect() which executes untrusted code. This issue is patched in send 0.19.0. |
- CVE-2024-45613Sep 25, 2024risk 0.00cvss —epss 0.00
CKEditor 5 is a JavaScript rich-text editor. Starting in version 40.0.0 and prior to version 43.1.1, a Cross-Site Scripting (XSS) vulnerability is present in the CKEditor 5 clipboard package. This vulnerability could be triggered by a specific user action, leading to…
- CVE-2024-9148Sep 24, 2024risk 0.00cvss —epss 0.01
Flowise < 2.1.1 suffers from a Stored Cross-Site vulnerability due to a lack of input sanitization in Flowise Chat Embed < 2.0.0.
- CVE-2024-47069Sep 23, 2024risk 0.00cvss —epss 0.00
Oveleon Cookie Bar is a cookie bar is for the Contao Open Source CMS and allows a visitor to define cookie & privacy settings for the website. Prior to versions 1.16.3 and 2.1.3, the `block/locale` endpoint does not properly sanitize the user-controlled `locale` input before…
- CVE-2024-47068Sep 23, 2024risk 0.00cvss —epss 0.01
Rollup is a module bundler for JavaScript. Versions prior to 2.79.2, 3.29.5, and 4.22.4 are susceptible to a DOM Clobbering vulnerability when bundling scripts with properties from `import.meta` (e.g., `import.meta.url`) in `cjs`/`umd`/`iife` format. The DOM Clobbering gadget…
- CVE-2021-27917Sep 18, 2024risk 0.00cvss —epss 0.00
Prior to this patch, a stored XSS vulnerability existed in the contact tracking and page hits report.
- CVE-2024-47050Sep 18, 2024risk 0.00cvss —epss 0.00
Prior to this patch being applied, Mautic's tracking was vulnerable to Cross-Site Scripting through the Page URL variable.
- CVE-2024-47058Sep 18, 2024risk 0.00cvss —epss 0.00
With access to edit a Mautic form, the attacker can add Cross-Site Scripting stored in the html filed. This could be used to steal sensitive information from the user's current session.
- CVE-2022-25774Sep 18, 2024risk 0.00cvss —epss 0.00
Prior to the patched version, logged in users of Mautic are vulnerable to a self XSS vulnerability in the notifications within Mautic. Users could inject malicious code into the notification when saving Dashboards.
- CVE-2024-46976Sep 17, 2024risk 0.00cvss —epss 0.00
Backstage is an open framework for building developer portals. An attacker with control of the contents of the TechDocs storage buckets is able to inject executable scripts in the TechDocs content that will be executed in the victim's browser when browsing documentation or…
- CVE-2024-45612Sep 17, 2024risk 0.00cvss —epss 0.00
Contao is an Open Source CMS. In affected versions an untrusted user can inject insert tags into the canonical tag, which are then replaced on the web page (front end). Users are advised to update to Contao 4.13.49, 5.3.15 or 5.4.3. Users unable to upgrade should disable…
- CVE-2024-45803Sep 17, 2024risk 0.00cvss —epss 0.00
Wire UI is a library of components and resources to empower Laravel and Livewire application development. A potential Cross-Site Scripting (XSS) vulnerability has been identified in the `/wireui/button` endpoint, specifically through the `label` query parameter. Malicious actors…
- CVE-2021-27915Sep 17, 2024risk 0.00cvss —epss 0.01
Prior to the patched version, there is an XSS vulnerability in the description fields within the Mautic application which could be exploited by a logged in user of Mautic with the appropriate permissions. This could lead to the user having elevated access to the system.
- CVE-2024-39910Sep 16, 2024risk 0.00cvss —epss 0.00
decidim is a Free Open-Source participatory democracy, citizen participation and open government for cities and organizations. The WYSWYG editor QuillJS is subject to potential XSS attach in case the attacker manages to modify the HTML before being uploaded to the server. The…
- CVE-2024-32034Sep 16, 2024risk 0.00cvss —epss 0.00
decidim is a Free Open-Source participatory democracy, citizen participation and open government for cities and organizations. The admin panel is subject to potential Cross-site scripting (XSS) attach in case an admin assigns a valuator to a proposal, or does any other action…
- CVE-2024-8863Sep 14, 2024risk 0.00cvss —epss 0.00
A vulnerability, which was classified as problematic, was found in aimhubio aim up to 3.24. Affected is the function dangerouslySetInnerHTML of the file textbox.tsx of the component Text Explorer. The manipulation of the argument query leads to cross site scripting. It is…
- CVE-2024-45856Sep 12, 2024risk 0.00cvss —epss 0.00
A cross-site scripting (XSS) vulnerability exists in all versions of the MindsDB platform, enabling the execution of a JavaScript payload whenever a user enumerates an ML Engine, database, project, or dataset containing arbitrary JavaScript code within the web UI.
- CVE-2024-45595Sep 10, 2024risk 0.00cvss —epss 0.01
D-Tale is a visualizer for Pandas data structures. Users hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. Users should upgrade to version 3.14.1 where the "Custom Filter" input is turned off by default.
- CVE-2024-45592Sep 10, 2024risk 0.00cvss —epss 0.00
auditor-bundle, formerly known as DoctrineAuditBundle, integrates auditor library into any Symfony 3.4+ application. Prior to version 5.2.6, there is an unescaped entity property enabling Javascript injection. This is possible because `%source_label%` in twig macro is not…
- CVE-2024-43800Sep 10, 2024risk 0.00cvss —epss 0.01
serve-static serves static files. serve-static passes untrusted user input - even after sanitizing it - to redirect() may execute untrusted code. This issue is patched in serve-static 1.16.0.
- CVE-2024-43799Sep 10, 2024risk 0.00cvss —epss 0.01
Send is a library for streaming files from the file system as a http response. Send passes untrusted user input to SendStream.redirect() which executes untrusted code. This issue is patched in send 0.19.0.