CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Description
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85
CVEs mapped to this weakness (23,317)
page 825 of 1,166| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-52083 | 0.00 | — | 0.00 | Dec 28, 2023 | Winter is a free, open-source content management system. Prior to 1.2.4, users with the `media.manage_media` permission can upload files to the Media Manager and rename them after uploading. Previously, media manager files were only sanitized on upload, not on renaming, which… | |||
| CVE-2023-27150 | — | 0.00 | — | 0.00 | Dec 26, 2023 | openCRX 5.2.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Name field after creation of a Tracker in Manage Activity. | ||
| CVE-2023-48650 | — | 0.00 | — | 0.00 | Dec 25, 2023 | Concrete CMS before 8.5.14 and 9 before 9.2.3 is vulnerable to an admin adding a stored XSS payload via the Layout Preset name. | ||
| CVE-2023-49337 | — | 0.00 | — | 0.01 | Dec 25, 2023 | Concrete CMS before 9.2.3 allows Stored XSS on the Admin Dashboard via /dashboard/system/basics/name. (8.5 and earlier are unaffected.) | ||
| CVE-2023-50727 | 0.00 | — | 0.01 | Dec 22, 2023 | Resque is a Redis-backed Ruby library for creating background jobs, placing them on multiple queues, and processing them later. Reflected XSS issue occurs when /queues is appended with /"><svg%20onload=alert(domain)>. This issue has been patched in version 2.6.0. | |||
| CVE-2023-50725 | 0.00 | — | 0.01 | Dec 22, 2023 | Resque is a Redis-backed Ruby library for creating background jobs, placing them on multiple queues, and processing them later. The following paths in resque-web have been found to be vulnerable to reflected XSS: "/failed/?class=" and… | |||
| CVE-2023-7036 | 0.00 | — | 0.01 | Dec 21, 2023 | A vulnerability was found in automad up to 1.10.9. It has been classified as problematic. This affects the function upload of the file FileCollectionController.php of the component Content Type Handler. The manipulation leads to unrestricted upload. It is possible to initiate… | |||
| CVE-2023-50724 | 0.00 | — | 0.00 | Dec 21, 2023 | Resque (pronounced like "rescue") is a Redis-backed library for creating background jobs, placing those jobs on multiple queues, and processing them later. resque-web in resque versions before 2.1.0 are vulnerable to reflected XSS through the current_queue parameter in the path… | |||
| CVE-2023-47265 | 0.00 | — | 0.01 | Dec 21, 2023 | Apache Airflow, versions 2.6.0 through 2.7.3 has a stored XSS vulnerability that allows a DAG author to add an unbounded and not-sanitized javascript in the parameter description field of the DAG. This Javascript can be executed on the client side of any of the user who looks… | |||
| CVE-2023-6911 | 0.00 | — | 0.00 | Dec 18, 2023 | Multiple WSO2 products have been identified as vulnerable due to improper output encoding, a Stored Cross Site Scripting (XSS) attack can be carried out by an attacker injecting a malicious payload into the Registry feature of the Management Console. | |||
| CVE-2023-6886 | — | 0.00 | — | 0.01 | Dec 17, 2023 | A vulnerability was found in xnx3 wangmarket 6.1. It has been rated as critical. Affected by this issue is some unknown functionality of the component Role Management Page. The manipulation leads to code injection. The attack may be launched remotely. The exploit has been… | ||
| CVE-2023-6890 | — | 0.00 | — | 0.00 | Dec 16, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.17. | ||
| CVE-2023-6889 | — | 0.00 | — | 0.00 | Dec 16, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.17. | ||
| CVE-2023-50137 | — | 0.00 | — | 0.00 | Dec 14, 2023 | JFinalcms 5.0.0 is vulnerable to Cross Site Scripting (XSS) in the site management office. | ||
| CVE-2023-50100 | — | 0.00 | — | 0.00 | Dec 14, 2023 | JFinalcms 5.0.0 is vulnerable to Cross Site Scripting (XSS) via carousel image editing. | ||
| CVE-2023-50101 | — | 0.00 | — | 0.00 | Dec 14, 2023 | JFinalcms 5.0.0 is vulnerable to Cross Site Scripting (XSS) via Label management editing. | ||
| CVE-2023-50102 | — | 0.00 | — | 0.00 | Dec 14, 2023 | JFinalcms 5.0.0 is vulnerable to Cross Site Scripting (XSS). | ||
| CVE-2023-47620 | — | 0.00 | — | 0.00 | Dec 13, 2023 | Scrypted is a home video integration and automation platform. In versions 0.55.0 and prior, a reflected cross-site scripting vulnerability exists in the plugin-http.ts file via the `owner' and 'pkg` parameters. An attacker can run arbitrary JavaScript code. | ||
| CVE-2023-47623 | — | 0.00 | — | 0.00 | Dec 13, 2023 | Scrypted is a home video integration and automation platform. In versions 0.55.0 and prior, a reflected cross-site scripting vulnerability exists in the login page via the `redirect_uri` parameter. By specifying a url with the javascript scheme (`javascript:`), an attacker can… | ||
| CVE-2023-6379 | — | 0.00 | — | 0.02 | Dec 13, 2023 | Cross-site scripting (XSS) vulnerability in Alkacon Software Open CMS, affecting versions 14 and 15 of the 'Mercury' template. This vulnerability could allow a remote attacker to send a specially crafted JavaScript payload to a victim and partially take control of their browsing… |
- CVE-2023-52083Dec 28, 2023risk 0.00cvss —epss 0.00
Winter is a free, open-source content management system. Prior to 1.2.4, users with the `media.manage_media` permission can upload files to the Media Manager and rename them after uploading. Previously, media manager files were only sanitized on upload, not on renaming, which…
- CVE-2023-27150Dec 26, 2023risk 0.00cvss —epss 0.00
openCRX 5.2.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Name field after creation of a Tracker in Manage Activity.
- CVE-2023-48650Dec 25, 2023risk 0.00cvss —epss 0.00
Concrete CMS before 8.5.14 and 9 before 9.2.3 is vulnerable to an admin adding a stored XSS payload via the Layout Preset name.
- CVE-2023-49337Dec 25, 2023risk 0.00cvss —epss 0.01
Concrete CMS before 9.2.3 allows Stored XSS on the Admin Dashboard via /dashboard/system/basics/name. (8.5 and earlier are unaffected.)
- CVE-2023-50727Dec 22, 2023risk 0.00cvss —epss 0.01
Resque is a Redis-backed Ruby library for creating background jobs, placing them on multiple queues, and processing them later. Reflected XSS issue occurs when /queues is appended with /"><svg%20onload=alert(domain)>. This issue has been patched in version 2.6.0.
- CVE-2023-50725Dec 22, 2023risk 0.00cvss —epss 0.01
Resque is a Redis-backed Ruby library for creating background jobs, placing them on multiple queues, and processing them later. The following paths in resque-web have been found to be vulnerable to reflected XSS: "/failed/?class=" and…
- CVE-2023-7036Dec 21, 2023risk 0.00cvss —epss 0.01
A vulnerability was found in automad up to 1.10.9. It has been classified as problematic. This affects the function upload of the file FileCollectionController.php of the component Content Type Handler. The manipulation leads to unrestricted upload. It is possible to initiate…
- CVE-2023-50724Dec 21, 2023risk 0.00cvss —epss 0.00
Resque (pronounced like "rescue") is a Redis-backed library for creating background jobs, placing those jobs on multiple queues, and processing them later. resque-web in resque versions before 2.1.0 are vulnerable to reflected XSS through the current_queue parameter in the path…
- CVE-2023-47265Dec 21, 2023risk 0.00cvss —epss 0.01
Apache Airflow, versions 2.6.0 through 2.7.3 has a stored XSS vulnerability that allows a DAG author to add an unbounded and not-sanitized javascript in the parameter description field of the DAG. This Javascript can be executed on the client side of any of the user who looks…
- CVE-2023-6911Dec 18, 2023risk 0.00cvss —epss 0.00
Multiple WSO2 products have been identified as vulnerable due to improper output encoding, a Stored Cross Site Scripting (XSS) attack can be carried out by an attacker injecting a malicious payload into the Registry feature of the Management Console.
- CVE-2023-6886Dec 17, 2023risk 0.00cvss —epss 0.01
A vulnerability was found in xnx3 wangmarket 6.1. It has been rated as critical. Affected by this issue is some unknown functionality of the component Role Management Page. The manipulation leads to code injection. The attack may be launched remotely. The exploit has been…
- CVE-2023-6890Dec 16, 2023risk 0.00cvss —epss 0.00
Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.17.
- CVE-2023-6889Dec 16, 2023risk 0.00cvss —epss 0.00
Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.17.
- CVE-2023-50137Dec 14, 2023risk 0.00cvss —epss 0.00
JFinalcms 5.0.0 is vulnerable to Cross Site Scripting (XSS) in the site management office.
- CVE-2023-50100Dec 14, 2023risk 0.00cvss —epss 0.00
JFinalcms 5.0.0 is vulnerable to Cross Site Scripting (XSS) via carousel image editing.
- CVE-2023-50101Dec 14, 2023risk 0.00cvss —epss 0.00
JFinalcms 5.0.0 is vulnerable to Cross Site Scripting (XSS) via Label management editing.
- CVE-2023-50102Dec 14, 2023risk 0.00cvss —epss 0.00
JFinalcms 5.0.0 is vulnerable to Cross Site Scripting (XSS).
- CVE-2023-47620Dec 13, 2023risk 0.00cvss —epss 0.00
Scrypted is a home video integration and automation platform. In versions 0.55.0 and prior, a reflected cross-site scripting vulnerability exists in the plugin-http.ts file via the `owner' and 'pkg` parameters. An attacker can run arbitrary JavaScript code.
- CVE-2023-47623Dec 13, 2023risk 0.00cvss —epss 0.00
Scrypted is a home video integration and automation platform. In versions 0.55.0 and prior, a reflected cross-site scripting vulnerability exists in the login page via the `redirect_uri` parameter. By specifying a url with the javascript scheme (`javascript:`), an attacker can…
- CVE-2023-6379Dec 13, 2023risk 0.00cvss —epss 0.02
Cross-site scripting (XSS) vulnerability in Alkacon Software Open CMS, affecting versions 14 and 15 of the 'Mercury' template. This vulnerability could allow a remote attacker to send a specially crafted JavaScript payload to a victim and partially take control of their browsing…