CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Description
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85
CVEs mapped to this weakness (23,319)
page 817 of 1,166| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-34899 | 0.00 | — | 0.00 | May 13, 2024 | WWBN AVideo 12.4 is vulnerable to Cross Site Scripting (XSS). | |||
| CVE-2023-50717 | 0.00 | — | 0.01 | May 13, 2024 | NocoDB is software for building databases as spreadsheets. Starting in verson 0.202.6 and prior to version 0.202.10, an attacker can upload a html file with malicious content. If user tries to open that file in browser malicious scripts can be executed leading stored cross-site… | |||
| CVE-2024-34081 | 0.00 | — | 0.01 | May 13, 2024 | MantisBT (Mantis Bug Tracker) is an open source issue tracker. Improper escaping of a custom field's name allows an attacker to inject HTML and, if CSP settings permit, achieve execution of arbitrary JavaScript when resolving or closing issues (`bug_change_status_page.php`)… | |||
| CVE-2024-34064 | 0.00 | — | 0.01 | May 6, 2024 | Jinja is an extensible templating engine. The `xmlattr` filter in affected versions of Jinja accepts keys containing non-attribute characters. XML/HTML attributes cannot contain spaces, `/`, `>`, or `=`, as each would then be interpreted as starting a separate attribute. If an… | |||
| CVE-2024-34500 | — | 0.00 | — | 0.00 | May 5, 2024 | An issue was discovered in the UnlinkedWikibase extension in MediaWiki before 1.39.6, 1.40.x before 1.40.2, and 1.41.x before 1.41.1. XSS can occur through an interface message. Error messages (in the $err var) are not escaped before being passed to Html::rawElement() in the… | ||
| CVE-2024-34467 | 0.00 | — | 0.00 | May 4, 2024 | ThinkPHP 8.0.3 allows remote attackers to exploit XSS due to inadequate filtering of function argument values in think_exception.tpl. | |||
| CVE-2024-34067 | 0.00 | — | 0.00 | May 3, 2024 | Pterodactyl is a free, open-source game server management panel built with PHP, React, and Go. Importing a malicious egg or gaining access to wings instance could lead to cross site scripting (XSS) on the panel, which could be used to gain an administrator account on the panel.… | |||
| CVE-2024-34449 | — | 0.00 | — | 0.00 | May 3, 2024 | Vditor 3.10.3 allows XSS via an attribute of an A element. NOTE: the vendor indicates that a user is supposed to mitigate this via sanitize=true. | ||
| CVE-2024-4216 | 0.00 | — | 0.00 | May 2, 2024 | pgAdmin <= 8.5 is affected by XSS vulnerability in /settings/store API response json payload. This vulnerability allows attackers to execute malicious script at the client end. | |||
| CVE-2024-32979 | 0.00 | — | 0.00 | May 1, 2024 | Nautobot is a Network Source of Truth and Network Automation Platform built as a web application atop the Django Python framework with a PostgreSQL or MySQL database. It was discovered that due to improper handling and escaping of user-provided query parameters, a maliciously… | |||
| CVE-2024-31828 | 0.00 | — | 0.01 | Apr 26, 2024 | Cross Site Scripting vulnerability in Lavalite CMS v.10.1.0 allows attackers to execute arbitrary code and obtain sensitive information via a crafted payload to the URL. | |||
| CVE-2024-33670 | — | 0.00 | — | 0.00 | Apr 26, 2024 | Passbolt API before 4.6.2 allows HTML injection in a URL parameter, resulting in custom content being displayed when a user visits the crafted URL. Although the injected content is not executed as JavaScript due to Content Security Policy (CSP) restrictions, it may still impact… | ||
| CVE-2024-32479 | 0.00 | — | 0.34 | Apr 22, 2024 | LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. Prior to version 24.4.0, there is improper sanitization on the `Service` template name, which can lead to stored Cross-site Scripting. Version 24.4.0 fixes this vulnerability. | |||
| CVE-2024-29376 | 0.00 | — | 0.00 | Apr 22, 2024 | Sylius 1.12.13 is vulnerable to Cross Site Scripting (XSS) via the "Province" field in Address Book. | |||
| CVE-2024-29217 | — | 0.00 | — | 0.01 | Apr 21, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Answer.This issue affects Apache Answer: before 1.3.0. XSS attack when user changes personal website. A logged-in user, when modifying their personal website, can input… | ||
| CVE-2024-29029 | 0.00 | — | 0.01 | Apr 19, 2024 | memos is a privacy-first, lightweight note-taking service. In memos 0.13.2, an SSRF vulnerability exists at the /o/get/image that allows unauthenticated users to enumerate the internal network and retrieve images. The response from the image request is then copied into the… | |||
| CVE-2024-27306 | 0.00 | — | 0.01 | Apr 18, 2024 | aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. A XSS vulnerability exists on index pages for static file handling. This vulnerability is fixed in 3.9.4. We have always recommended using a reverse proxy server (e.g. nginx) for serving static… | |||
| CVE-2024-3575 | 0.00 | — | 0.00 | Apr 16, 2024 | Cross-site Scripting (XSS) - Stored in mindsdb/mindsdb | |||
| CVE-2024-32489 | — | 0.00 | — | 0.01 | Apr 15, 2024 | TCPDF before 6.7.4 mishandles calls that use HTML syntax. | ||
| CVE-2024-20759 | 0.00 | — | 0.01 | Apr 10, 2024 | Adobe Commerce versions 2.4.6-p4, 2.4.5-p6, 2.4.4-p7, 2.4.7-beta3 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be… |
- CVE-2024-34899May 13, 2024risk 0.00cvss —epss 0.00
WWBN AVideo 12.4 is vulnerable to Cross Site Scripting (XSS).
- CVE-2023-50717May 13, 2024risk 0.00cvss —epss 0.01
NocoDB is software for building databases as spreadsheets. Starting in verson 0.202.6 and prior to version 0.202.10, an attacker can upload a html file with malicious content. If user tries to open that file in browser malicious scripts can be executed leading stored cross-site…
- CVE-2024-34081May 13, 2024risk 0.00cvss —epss 0.01
MantisBT (Mantis Bug Tracker) is an open source issue tracker. Improper escaping of a custom field's name allows an attacker to inject HTML and, if CSP settings permit, achieve execution of arbitrary JavaScript when resolving or closing issues (`bug_change_status_page.php`)…
- CVE-2024-34064May 6, 2024risk 0.00cvss —epss 0.01
Jinja is an extensible templating engine. The `xmlattr` filter in affected versions of Jinja accepts keys containing non-attribute characters. XML/HTML attributes cannot contain spaces, `/`, `>`, or `=`, as each would then be interpreted as starting a separate attribute. If an…
- CVE-2024-34500May 5, 2024risk 0.00cvss —epss 0.00
An issue was discovered in the UnlinkedWikibase extension in MediaWiki before 1.39.6, 1.40.x before 1.40.2, and 1.41.x before 1.41.1. XSS can occur through an interface message. Error messages (in the $err var) are not escaped before being passed to Html::rawElement() in the…
- CVE-2024-34467May 4, 2024risk 0.00cvss —epss 0.00
ThinkPHP 8.0.3 allows remote attackers to exploit XSS due to inadequate filtering of function argument values in think_exception.tpl.
- CVE-2024-34067May 3, 2024risk 0.00cvss —epss 0.00
Pterodactyl is a free, open-source game server management panel built with PHP, React, and Go. Importing a malicious egg or gaining access to wings instance could lead to cross site scripting (XSS) on the panel, which could be used to gain an administrator account on the panel.…
- CVE-2024-34449May 3, 2024risk 0.00cvss —epss 0.00
Vditor 3.10.3 allows XSS via an attribute of an A element. NOTE: the vendor indicates that a user is supposed to mitigate this via sanitize=true.
- CVE-2024-4216May 2, 2024risk 0.00cvss —epss 0.00
pgAdmin <= 8.5 is affected by XSS vulnerability in /settings/store API response json payload. This vulnerability allows attackers to execute malicious script at the client end.
- CVE-2024-32979May 1, 2024risk 0.00cvss —epss 0.00
Nautobot is a Network Source of Truth and Network Automation Platform built as a web application atop the Django Python framework with a PostgreSQL or MySQL database. It was discovered that due to improper handling and escaping of user-provided query parameters, a maliciously…
- CVE-2024-31828Apr 26, 2024risk 0.00cvss —epss 0.01
Cross Site Scripting vulnerability in Lavalite CMS v.10.1.0 allows attackers to execute arbitrary code and obtain sensitive information via a crafted payload to the URL.
- CVE-2024-33670Apr 26, 2024risk 0.00cvss —epss 0.00
Passbolt API before 4.6.2 allows HTML injection in a URL parameter, resulting in custom content being displayed when a user visits the crafted URL. Although the injected content is not executed as JavaScript due to Content Security Policy (CSP) restrictions, it may still impact…
- CVE-2024-32479Apr 22, 2024risk 0.00cvss —epss 0.34
LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. Prior to version 24.4.0, there is improper sanitization on the `Service` template name, which can lead to stored Cross-site Scripting. Version 24.4.0 fixes this vulnerability.
- CVE-2024-29376Apr 22, 2024risk 0.00cvss —epss 0.00
Sylius 1.12.13 is vulnerable to Cross Site Scripting (XSS) via the "Province" field in Address Book.
- CVE-2024-29217Apr 21, 2024risk 0.00cvss —epss 0.01
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Answer.This issue affects Apache Answer: before 1.3.0. XSS attack when user changes personal website. A logged-in user, when modifying their personal website, can input…
- CVE-2024-29029Apr 19, 2024risk 0.00cvss —epss 0.01
memos is a privacy-first, lightweight note-taking service. In memos 0.13.2, an SSRF vulnerability exists at the /o/get/image that allows unauthenticated users to enumerate the internal network and retrieve images. The response from the image request is then copied into the…
- CVE-2024-27306Apr 18, 2024risk 0.00cvss —epss 0.01
aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. A XSS vulnerability exists on index pages for static file handling. This vulnerability is fixed in 3.9.4. We have always recommended using a reverse proxy server (e.g. nginx) for serving static…
- CVE-2024-3575Apr 16, 2024risk 0.00cvss —epss 0.00
Cross-site Scripting (XSS) - Stored in mindsdb/mindsdb
- CVE-2024-32489Apr 15, 2024risk 0.00cvss —epss 0.01
TCPDF before 6.7.4 mishandles calls that use HTML syntax.
- CVE-2024-20759Apr 10, 2024risk 0.00cvss —epss 0.01
Adobe Commerce versions 2.4.6-p4, 2.4.5-p6, 2.4.4-p7, 2.4.7-beta3 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be…