CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Description
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85
CVEs mapped to this weakness (23,319)
page 814 of 1,166| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-7394 | — | 0.00 | — | 0.00 | Aug 8, 2024 | Concrete CMS versions 9 through 9.3.2 and below 8.5.18 are vulnerable to Stored XSS in getAttributeSetName(). A rogue administrator could inject malicious code. The Concrete CMS team gave this a CVSS v4.0 rank of 4.6 with vector https://www.first.org/cvss/calculator/4.0#CVSS:… | ||
| CVE-2024-6706 | — | 0.00 | — | 0.01 | Aug 7, 2024 | Attackers can craft a malicious prompt that coerces the language model into executing arbitrary JavaScript in the context of the web page. | ||
| CVE-2024-41677 | 0.00 | — | 0.00 | Aug 6, 2024 | Qwik is a performance focused javascript framework. A potential mutation XSS vulnerability exists in Qwik for versions up to but not including 1.6.0. Qwik improperly escapes HTML on server-side rendering. It converts strings according to the rules found in the `render-ssr.ts`… | |||
| CVE-2024-40101 | 0.00 | — | 0.01 | Aug 6, 2024 | A Reflected Cross-site scripting (XSS) vulnerability exists in '/search' in microweber 2.0.15 and earlier allowing unauthenticated remote attackers to inject arbitrary web script or HTML via the 'keywords' parameter. | |||
| CVE-2024-34343 | 0.00 | — | 0.00 | Aug 5, 2024 | Nuxt is a free and open-source framework to create full-stack web applications and websites with Vue.js. The `navigateTo` function attempts to blockthe `javascript:` protocol, but does not correctly use API's provided by `unjs/ufo`. This library also contains parsing… | |||
| CVE-2024-41380 | 0.00 | — | 0.00 | Aug 5, 2024 | microweber 2.0.16 was discovered to contain a Cross Site Scripting (XSS) vulnerability via userfiles\modules\tags\add_tagging_tagged.php. | |||
| CVE-2024-41381 | 0.00 | — | 0.00 | Aug 5, 2024 | microweber 2.0.16 was discovered to contain a Cross Site Scripting (XSS) vulnerability via userfiles\modules\settings\admin.php. | |||
| CVE-2024-41953 | 0.00 | — | 0.01 | Jul 31, 2024 | Zitadel is an open source identity management system. ZITADEL uses HTML for emails and renders certain information such as usernames dynamically. That information can be entered by users or administrators. Due to a missing output sanitization, these emails could include… | |||
| CVE-2024-41947 | 0.00 | — | 0.02 | Jul 31, 2024 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. By creating a conflict when another user with more rights is currently editing a page, it is possible to execute JavaScript snippets on the side of the other user, which… | |||
| CVE-2024-7300 | — | 0.00 | — | 0.00 | Jul 31, 2024 | A vulnerability classified as problematic has been found in Bolt CMS 3.7.1. Affected is an unknown function of the file /bolt/editcontent/showcases of the component Showcase Creation Handler. The manipulation of the argument title/textarea leads to cross site scripting. It is… | ||
| CVE-2024-6578 | — | 0.00 | — | 0.00 | Jul 29, 2024 | A stored cross-site scripting (XSS) vulnerability exists in aimhubio/aim version 3.19.3. The vulnerability arises from the improper neutralization of input during web page generation, specifically in the logs-tab for runs. The terminal output logs are displayed using the… | ||
| CVE-2024-41810 | 0.00 | — | 0.01 | Jul 29, 2024 | Twisted is an event-based framework for internet applications, supporting Python 3.6+. The `twisted.web.util.redirectTo` function contains an HTML injection vulnerability. If application code allows an attacker to control the redirect URL this vulnerability may result in… | |||
| CVE-2024-41676 | 0.00 | — | 0.00 | Jul 29, 2024 | Magento-lts is a long-term support alternative to Magento Community Edition (CE). This XSS vulnerability affects the design/header/welcome, design/header/logo_src, design/header/logo_src_small, and design/header/logo_alt system configs.They are intended to enable admins to set a… | |||
| CVE-2024-41374 | 0.00 | — | 0.00 | Jul 26, 2024 | ICEcoder 8.1 is vulnerable to Cross Site Scripting (XSS) via lib/settings-screen.php | |||
| CVE-2024-41375 | 0.00 | — | 0.00 | Jul 26, 2024 | ICEcoder 8.1 is vulnerable to Cross Site Scripting (XSS) via lib/terminal-xhr.php | |||
| CVE-2024-41656 | 0.00 | — | 0.00 | Jul 23, 2024 | Sentry is an error tracking and performance monitoring platform. Starting in version 10.0.0 and prior to version 24.7.1, an unsanitized payload sent by an Integration platform integration allows storing arbitrary HTML tags on the Sentry side with the subsequent rendering them on… | |||
| CVE-2024-38503 | — | 0.00 | — | 0.01 | Jul 22, 2024 | When editing a user, group or any object in the Syncope Console, HTML tags could be added to any text field and could lead to potential exploits. The same vulnerability was found in the Syncope Enduser, when editing “Personal Information” or “User Requests”. Users are… | ||
| CVE-2024-41709 | — | 0.00 | — | 0.00 | Jul 22, 2024 | Backdrop CMS before 1.27.3 and 1.28.x before 1.28.2 does not sufficiently sanitize field labels before they are displayed in certain places. This vulnerability is mitigated by the fact that an attacker must have a role with the "administer fields" permission. | ||
| CVE-2024-32981 | 0.00 | — | 0.00 | Jul 17, 2024 | Silverstripe framework is the PHP framework forming the base for the Silverstripe CMS. In affected versions a bad actor with access to edit content in the CMS could add send a specifically crafted encoded payload to the server, which could be used to inject a JavaScript payload… | |||
| CVE-2024-39863 | 0.00 | — | 0.01 | Jul 17, 2024 | Apache Airflow versions before 2.9.3 have a vulnerability that allows an authenticated attacker to inject a malicious link when installing a provider. Users are recommended to upgrade to version 2.9.3, which fixes this issue. |
- CVE-2024-7394Aug 8, 2024risk 0.00cvss —epss 0.00
Concrete CMS versions 9 through 9.3.2 and below 8.5.18 are vulnerable to Stored XSS in getAttributeSetName(). A rogue administrator could inject malicious code. The Concrete CMS team gave this a CVSS v4.0 rank of 4.6 with vector https://www.first.org/cvss/calculator/4.0#CVSS:…
- CVE-2024-6706Aug 7, 2024risk 0.00cvss —epss 0.01
Attackers can craft a malicious prompt that coerces the language model into executing arbitrary JavaScript in the context of the web page.
- CVE-2024-41677Aug 6, 2024risk 0.00cvss —epss 0.00
Qwik is a performance focused javascript framework. A potential mutation XSS vulnerability exists in Qwik for versions up to but not including 1.6.0. Qwik improperly escapes HTML on server-side rendering. It converts strings according to the rules found in the `render-ssr.ts`…
- CVE-2024-40101Aug 6, 2024risk 0.00cvss —epss 0.01
A Reflected Cross-site scripting (XSS) vulnerability exists in '/search' in microweber 2.0.15 and earlier allowing unauthenticated remote attackers to inject arbitrary web script or HTML via the 'keywords' parameter.
- CVE-2024-34343Aug 5, 2024risk 0.00cvss —epss 0.00
Nuxt is a free and open-source framework to create full-stack web applications and websites with Vue.js. The `navigateTo` function attempts to blockthe `javascript:` protocol, but does not correctly use API's provided by `unjs/ufo`. This library also contains parsing…
- CVE-2024-41380Aug 5, 2024risk 0.00cvss —epss 0.00
microweber 2.0.16 was discovered to contain a Cross Site Scripting (XSS) vulnerability via userfiles\modules\tags\add_tagging_tagged.php.
- CVE-2024-41381Aug 5, 2024risk 0.00cvss —epss 0.00
microweber 2.0.16 was discovered to contain a Cross Site Scripting (XSS) vulnerability via userfiles\modules\settings\admin.php.
- CVE-2024-41953Jul 31, 2024risk 0.00cvss —epss 0.01
Zitadel is an open source identity management system. ZITADEL uses HTML for emails and renders certain information such as usernames dynamically. That information can be entered by users or administrators. Due to a missing output sanitization, these emails could include…
- CVE-2024-41947Jul 31, 2024risk 0.00cvss —epss 0.02
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. By creating a conflict when another user with more rights is currently editing a page, it is possible to execute JavaScript snippets on the side of the other user, which…
- CVE-2024-7300Jul 31, 2024risk 0.00cvss —epss 0.00
A vulnerability classified as problematic has been found in Bolt CMS 3.7.1. Affected is an unknown function of the file /bolt/editcontent/showcases of the component Showcase Creation Handler. The manipulation of the argument title/textarea leads to cross site scripting. It is…
- CVE-2024-6578Jul 29, 2024risk 0.00cvss —epss 0.00
A stored cross-site scripting (XSS) vulnerability exists in aimhubio/aim version 3.19.3. The vulnerability arises from the improper neutralization of input during web page generation, specifically in the logs-tab for runs. The terminal output logs are displayed using the…
- CVE-2024-41810Jul 29, 2024risk 0.00cvss —epss 0.01
Twisted is an event-based framework for internet applications, supporting Python 3.6+. The `twisted.web.util.redirectTo` function contains an HTML injection vulnerability. If application code allows an attacker to control the redirect URL this vulnerability may result in…
- CVE-2024-41676Jul 29, 2024risk 0.00cvss —epss 0.00
Magento-lts is a long-term support alternative to Magento Community Edition (CE). This XSS vulnerability affects the design/header/welcome, design/header/logo_src, design/header/logo_src_small, and design/header/logo_alt system configs.They are intended to enable admins to set a…
- CVE-2024-41374Jul 26, 2024risk 0.00cvss —epss 0.00
ICEcoder 8.1 is vulnerable to Cross Site Scripting (XSS) via lib/settings-screen.php
- CVE-2024-41375Jul 26, 2024risk 0.00cvss —epss 0.00
ICEcoder 8.1 is vulnerable to Cross Site Scripting (XSS) via lib/terminal-xhr.php
- CVE-2024-41656Jul 23, 2024risk 0.00cvss —epss 0.00
Sentry is an error tracking and performance monitoring platform. Starting in version 10.0.0 and prior to version 24.7.1, an unsanitized payload sent by an Integration platform integration allows storing arbitrary HTML tags on the Sentry side with the subsequent rendering them on…
- CVE-2024-38503Jul 22, 2024risk 0.00cvss —epss 0.01
When editing a user, group or any object in the Syncope Console, HTML tags could be added to any text field and could lead to potential exploits. The same vulnerability was found in the Syncope Enduser, when editing “Personal Information” or “User Requests”. Users are…
- CVE-2024-41709Jul 22, 2024risk 0.00cvss —epss 0.00
Backdrop CMS before 1.27.3 and 1.28.x before 1.28.2 does not sufficiently sanitize field labels before they are displayed in certain places. This vulnerability is mitigated by the fact that an attacker must have a role with the "administer fields" permission.
- CVE-2024-32981Jul 17, 2024risk 0.00cvss —epss 0.00
Silverstripe framework is the PHP framework forming the base for the Silverstripe CMS. In affected versions a bad actor with access to edit content in the CMS could add send a specifically crafted encoded payload to the server, which could be used to inject a JavaScript payload…
- CVE-2024-39863Jul 17, 2024risk 0.00cvss —epss 0.01
Apache Airflow versions before 2.9.3 have a vulnerability that allows an authenticated attacker to inject a malicious link when installing a provider. Users are recommended to upgrade to version 2.9.3, which fixes this issue.