VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (23,319)

page 817 of 1,166
  • CVE-2024-34899May 13, 2024
    risk 0.00cvss epss 0.00

    WWBN AVideo 12.4 is vulnerable to Cross Site Scripting (XSS).

  • CVE-2023-50717May 13, 2024
    risk 0.00cvss epss 0.01

    NocoDB is software for building databases as spreadsheets. Starting in verson 0.202.6 and prior to version 0.202.10, an attacker can upload a html file with malicious content. If user tries to open that file in browser malicious scripts can be executed leading stored cross-site…

  • CVE-2024-34081May 13, 2024
    risk 0.00cvss epss 0.01

    MantisBT (Mantis Bug Tracker) is an open source issue tracker. Improper escaping of a custom field's name allows an attacker to inject HTML and, if CSP settings permit, achieve execution of arbitrary JavaScript when resolving or closing issues (`bug_change_status_page.php`)…

  • CVE-2024-34064May 6, 2024
    risk 0.00cvss epss 0.01

    Jinja is an extensible templating engine. The `xmlattr` filter in affected versions of Jinja accepts keys containing non-attribute characters. XML/HTML attributes cannot contain spaces, `/`, `>`, or `=`, as each would then be interpreted as starting a separate attribute. If an…

  • CVE-2024-34500May 5, 2024
    risk 0.00cvss epss 0.00

    An issue was discovered in the UnlinkedWikibase extension in MediaWiki before 1.39.6, 1.40.x before 1.40.2, and 1.41.x before 1.41.1. XSS can occur through an interface message. Error messages (in the $err var) are not escaped before being passed to Html::rawElement() in the…

  • CVE-2024-34467May 4, 2024
    risk 0.00cvss epss 0.00

    ThinkPHP 8.0.3 allows remote attackers to exploit XSS due to inadequate filtering of function argument values in think_exception.tpl.

  • CVE-2024-34067May 3, 2024
    risk 0.00cvss epss 0.00

    Pterodactyl is a free, open-source game server management panel built with PHP, React, and Go. Importing a malicious egg or gaining access to wings instance could lead to cross site scripting (XSS) on the panel, which could be used to gain an administrator account on the panel.…

  • CVE-2024-34449May 3, 2024
    risk 0.00cvss epss 0.00

    Vditor 3.10.3 allows XSS via an attribute of an A element. NOTE: the vendor indicates that a user is supposed to mitigate this via sanitize=true.

  • CVE-2024-4216May 2, 2024
    risk 0.00cvss epss 0.00

    pgAdmin <= 8.5 is affected by XSS vulnerability in /settings/store API response json payload. This vulnerability allows attackers to execute malicious script at the client end.

  • CVE-2024-32979May 1, 2024
    risk 0.00cvss epss 0.00

    Nautobot is a Network Source of Truth and Network Automation Platform built as a web application atop the Django Python framework with a PostgreSQL or MySQL database. It was discovered that due to improper handling and escaping of user-provided query parameters, a maliciously…

  • CVE-2024-31828Apr 26, 2024
    risk 0.00cvss epss 0.01

    Cross Site Scripting vulnerability in Lavalite CMS v.10.1.0 allows attackers to execute arbitrary code and obtain sensitive information via a crafted payload to the URL.

  • CVE-2024-33670Apr 26, 2024
    risk 0.00cvss epss 0.00

    Passbolt API before 4.6.2 allows HTML injection in a URL parameter, resulting in custom content being displayed when a user visits the crafted URL. Although the injected content is not executed as JavaScript due to Content Security Policy (CSP) restrictions, it may still impact…

  • CVE-2024-32479Apr 22, 2024
    risk 0.00cvss epss 0.34

    LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. Prior to version 24.4.0, there is improper sanitization on the `Service` template name, which can lead to stored Cross-site Scripting. Version 24.4.0 fixes this vulnerability.

  • CVE-2024-29376Apr 22, 2024
    risk 0.00cvss epss 0.00

    Sylius 1.12.13 is vulnerable to Cross Site Scripting (XSS) via the "Province" field in Address Book.

  • CVE-2024-29217Apr 21, 2024
    risk 0.00cvss epss 0.01

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Answer.This issue affects Apache Answer: before 1.3.0. XSS attack when user changes personal website. A logged-in user, when modifying their personal website, can input…

  • CVE-2024-29029Apr 19, 2024
    risk 0.00cvss epss 0.01

    memos is a privacy-first, lightweight note-taking service. In memos 0.13.2, an SSRF vulnerability exists at the /o/get/image that allows unauthenticated users to enumerate the internal network and retrieve images. The response from the image request is then copied into the…

  • CVE-2024-27306Apr 18, 2024
    risk 0.00cvss epss 0.01

    aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. A XSS vulnerability exists on index pages for static file handling. This vulnerability is fixed in 3.9.4. We have always recommended using a reverse proxy server (e.g. nginx) for serving static…

  • CVE-2024-3575Apr 16, 2024
    risk 0.00cvss epss 0.00

    Cross-site Scripting (XSS) - Stored in mindsdb/mindsdb

  • CVE-2024-32489Apr 15, 2024
    risk 0.00cvss epss 0.01

    TCPDF before 6.7.4 mishandles calls that use HTML syntax.

  • CVE-2024-20759Apr 10, 2024
    risk 0.00cvss epss 0.01

    Adobe Commerce versions 2.4.6-p4, 2.4.5-p6, 2.4.4-p7, 2.4.7-beta3 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be…