CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Description
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85
CVEs mapped to this weakness (46,607)
page 83 of 2,331| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-47920 | Hig | 0.49 | 7.5 | 0.01 | Dec 30, 2024 | Tiki Wiki CMS – CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | ||
| CVE-2024-47917 | — | Hig | 0.49 | 7.5 | 0.00 | Dec 30, 2024 | CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | |
| CVE-2024-49053 | Hig | 0.49 | 7.6 | 0.01 | Nov 26, 2024 | Microsoft Dynamics 365 Sales Spoofing Vulnerability | ||
| CVE-2022-26324 | Hig | 0.49 | 7.6 | 0.00 | Nov 22, 2024 | Possible XSS in iManager URL for access Component has been discovered in OpenText™ iManager 3.2.6.0000. | ||
| CVE-2024-48536 | Hig | 0.49 | 7.5 | 0.00 | Nov 20, 2024 | Incorrect access control in eSoft Planner 3.24.08271-USA allow attackers to view all transactions performed by the company via supplying a crafted web request. | ||
| CVE-2024-52598 | Hig | 0.49 | 7.5 | 0.01 | Nov 20, 2024 | 2FAuth is a web app to manage Two-Factor Authentication (2FA) accounts and generate their security codes. Two interconnected vulnerabilities exist in version 5.4.1 a SSRF and URI validation bypass issue. The endpoint at POST /api/v1/twofaccounts/preview allows setting a remote… | ||
| CVE-2023-49952 | Hig | 0.49 | 7.5 | 0.00 | Nov 18, 2024 | Mastodon 4.1.x before 4.1.17 and 4.2.x before 4.2.9 allows a bypass of rate limiting via a crafted HTTP request header. | ||
| CVE-2024-45254 | — | Hig | 0.49 | 7.5 | 0.00 | Nov 14, 2024 | VaeMendis - CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | |
| CVE-2020-11926 | Hig | 0.49 | 7.5 | 0.01 | Nov 7, 2024 | An issue was discovered in Luvion Grand Elite 3 Connect through 2020-02-25. Clients can authenticate themselves to the device using a username and password. These credentials can be obtained through an unauthenticated web request, e.g., for a JavaScript file. Also, the disclosed… | ||
| CVE-2020-11859 | Hig | 0.49 | 7.6 | 0.00 | Nov 6, 2024 | Improper Input Validation vulnerability in OpenText iManager allows Cross-Site Scripting (XSS). This issue affects iManager before 3.2.3 | ||
| CVE-2024-44080 | Hig | 0.49 | 7.5 | 0.01 | Oct 29, 2024 | In Jitsi Meet before 2.0.9779, the functionality to share an image using giphy was implemented in an insecure way, resulting in clients loading GIFs from any arbitrary URL if a message from another participant contains a URL encoded in the expected format. | ||
| CVE-2024-5429 | Hig | 0.49 | 7.6 | 0.00 | Oct 17, 2024 | The Logo Slider WordPress plugin before 4.1.0 does not validate and escape some of its Slider Settings before outputting them back in attributes, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks | ||
| CVE-2024-9394 | Hig | 0.49 | 7.5 | 0.00 | Oct 1, 2024 | An attacker could, via a specially crafted multipart response, execute arbitrary JavaScript under the `resource://devtools` origin. This could allow them to access cross-origin JSON content. This access is limited to "same site" documents by the Site Isolation feature on… | ||
| CVE-2024-9198 | Hig | 0.49 | 7.6 | 0.00 | Sep 26, 2024 | Vulnerability in Clibo Manager v1.1.9.1 that could allow an attacker to execute an stored Cross-Site Scripting (stored XSS ) by uploading a malicious .svg image in the section: Profile > Profile picture. | ||
| CVE-2024-42346 | Hig | 0.49 | 7.6 | 0.01 | Sep 20, 2024 | Galaxy is a free, open-source system for analyzing data, authoring workflows, training and education, publishing tools, managing infrastructure, and more. The editor visualization, /visualizations endpoint, can be used to store HTML tags and trigger javascript execution upon… | ||
| CVE-2024-43476 | Hig | 0.49 | 7.6 | 0.01 | Sep 10, 2024 | Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | ||
| CVE-2024-39403 | Hig | 0.49 | 7.6 | 0.01 | Aug 14, 2024 | Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be… | ||
| CVE-2024-41357 | Hig | 0.49 | 7.1 | 0.01 | Jul 26, 2024 | phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via /app/admin/powerDNS/record-edit.php. | ||
| CVE-2024-2301 | Hig | 0.49 | 7.6 | 0.00 | May 23, 2024 | Certain HP LaserJet Pro devices are potentially vulnerable to a Cross-Site Scripting (XSS) attack via the web management interface of the device. | ||
| CVE-2024-30048 | Hig | 0.49 | 7.6 | 0.01 | May 14, 2024 | Dynamics 365 Customer Insights Spoofing Vulnerability |
- risk 0.49cvss 7.5epss 0.01
Tiki Wiki CMS – CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- risk 0.49cvss 7.5epss 0.00
CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- risk 0.49cvss 7.6epss 0.01
Microsoft Dynamics 365 Sales Spoofing Vulnerability
- risk 0.49cvss 7.6epss 0.00
Possible XSS in iManager URL for access Component has been discovered in OpenText™ iManager 3.2.6.0000.
- risk 0.49cvss 7.5epss 0.00
Incorrect access control in eSoft Planner 3.24.08271-USA allow attackers to view all transactions performed by the company via supplying a crafted web request.
- risk 0.49cvss 7.5epss 0.01
2FAuth is a web app to manage Two-Factor Authentication (2FA) accounts and generate their security codes. Two interconnected vulnerabilities exist in version 5.4.1 a SSRF and URI validation bypass issue. The endpoint at POST /api/v1/twofaccounts/preview allows setting a remote…
- risk 0.49cvss 7.5epss 0.00
Mastodon 4.1.x before 4.1.17 and 4.2.x before 4.2.9 allows a bypass of rate limiting via a crafted HTTP request header.
- risk 0.49cvss 7.5epss 0.00
VaeMendis - CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- risk 0.49cvss 7.5epss 0.01
An issue was discovered in Luvion Grand Elite 3 Connect through 2020-02-25. Clients can authenticate themselves to the device using a username and password. These credentials can be obtained through an unauthenticated web request, e.g., for a JavaScript file. Also, the disclosed…
- risk 0.49cvss 7.6epss 0.00
Improper Input Validation vulnerability in OpenText iManager allows Cross-Site Scripting (XSS). This issue affects iManager before 3.2.3
- risk 0.49cvss 7.5epss 0.01
In Jitsi Meet before 2.0.9779, the functionality to share an image using giphy was implemented in an insecure way, resulting in clients loading GIFs from any arbitrary URL if a message from another participant contains a URL encoded in the expected format.
- risk 0.49cvss 7.6epss 0.00
The Logo Slider WordPress plugin before 4.1.0 does not validate and escape some of its Slider Settings before outputting them back in attributes, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
- risk 0.49cvss 7.5epss 0.00
An attacker could, via a specially crafted multipart response, execute arbitrary JavaScript under the `resource://devtools` origin. This could allow them to access cross-origin JSON content. This access is limited to "same site" documents by the Site Isolation feature on…
- risk 0.49cvss 7.6epss 0.00
Vulnerability in Clibo Manager v1.1.9.1 that could allow an attacker to execute an stored Cross-Site Scripting (stored XSS ) by uploading a malicious .svg image in the section: Profile > Profile picture.
- risk 0.49cvss 7.6epss 0.01
Galaxy is a free, open-source system for analyzing data, authoring workflows, training and education, publishing tools, managing infrastructure, and more. The editor visualization, /visualizations endpoint, can be used to store HTML tags and trigger javascript execution upon…
- risk 0.49cvss 7.6epss 0.01
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
- risk 0.49cvss 7.6epss 0.01
Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be…
- risk 0.49cvss 7.1epss 0.01
phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via /app/admin/powerDNS/record-edit.php.
- risk 0.49cvss 7.6epss 0.00
Certain HP LaserJet Pro devices are potentially vulnerable to a Cross-Site Scripting (XSS) attack via the web management interface of the device.
- risk 0.49cvss 7.6epss 0.01
Dynamics 365 Customer Insights Spoofing Vulnerability