VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (46,607)

page 83 of 2,331
  • CVE-2024-47920HigDec 30, 2024
    risk 0.49cvss 7.5epss 0.01

    Tiki Wiki CMS – CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

  • CVE-2024-47917HigDec 30, 2024
    risk 0.49cvss 7.5epss 0.00

    CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

  • CVE-2024-49053HigNov 26, 2024
    risk 0.49cvss 7.6epss 0.01

    Microsoft Dynamics 365 Sales Spoofing Vulnerability

  • CVE-2022-26324HigNov 22, 2024
    risk 0.49cvss 7.6epss 0.00

    Possible XSS in iManager URL for access Component has been discovered in OpenText™ iManager 3.2.6.0000.

  • CVE-2024-48536HigNov 20, 2024
    risk 0.49cvss 7.5epss 0.00

    Incorrect access control in eSoft Planner 3.24.08271-USA allow attackers to view all transactions performed by the company via supplying a crafted web request.

  • CVE-2024-52598HigNov 20, 2024
    risk 0.49cvss 7.5epss 0.01

    2FAuth is a web app to manage Two-Factor Authentication (2FA) accounts and generate their security codes. Two interconnected vulnerabilities exist in version 5.4.1 a SSRF and URI validation bypass issue. The endpoint at POST /api/v1/twofaccounts/preview allows setting a remote…

  • CVE-2023-49952HigNov 18, 2024
    risk 0.49cvss 7.5epss 0.00

    Mastodon 4.1.x before 4.1.17 and 4.2.x before 4.2.9 allows a bypass of rate limiting via a crafted HTTP request header.

  • CVE-2024-45254HigNov 14, 2024
    risk 0.49cvss 7.5epss 0.00

    VaeMendis - CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

  • CVE-2020-11926HigNov 7, 2024
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Luvion Grand Elite 3 Connect through 2020-02-25. Clients can authenticate themselves to the device using a username and password. These credentials can be obtained through an unauthenticated web request, e.g., for a JavaScript file. Also, the disclosed…

  • CVE-2020-11859HigNov 6, 2024
    risk 0.49cvss 7.6epss 0.00

    Improper Input Validation vulnerability in OpenText iManager allows Cross-Site Scripting (XSS). This issue affects iManager before 3.2.3

  • CVE-2024-44080HigOct 29, 2024
    risk 0.49cvss 7.5epss 0.01

    In Jitsi Meet before 2.0.9779, the functionality to share an image using giphy was implemented in an insecure way, resulting in clients loading GIFs from any arbitrary URL if a message from another participant contains a URL encoded in the expected format.

  • CVE-2024-5429HigOct 17, 2024
    risk 0.49cvss 7.6epss 0.00

    The Logo Slider WordPress plugin before 4.1.0 does not validate and escape some of its Slider Settings before outputting them back in attributes, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

  • CVE-2024-9394HigOct 1, 2024
    risk 0.49cvss 7.5epss 0.00

    An attacker could, via a specially crafted multipart response, execute arbitrary JavaScript under the `resource://devtools` origin. This could allow them to access cross-origin JSON content. This access is limited to "same site" documents by the Site Isolation feature on…

  • CVE-2024-9198HigSep 26, 2024
    risk 0.49cvss 7.6epss 0.00

    Vulnerability in Clibo Manager v1.1.9.1 that could allow an attacker to execute an stored Cross-Site Scripting (stored XSS ) by uploading a malicious .svg image in the section: Profile > Profile picture.

  • CVE-2024-42346HigSep 20, 2024
    risk 0.49cvss 7.6epss 0.01

    Galaxy is a free, open-source system for analyzing data, authoring workflows, training and education, publishing tools, managing infrastructure, and more. The editor visualization, /visualizations endpoint, can be used to store HTML tags and trigger javascript execution upon…

  • CVE-2024-43476HigSep 10, 2024
    risk 0.49cvss 7.6epss 0.01

    Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability

  • CVE-2024-39403HigAug 14, 2024
    risk 0.49cvss 7.6epss 0.01

    Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be…

  • CVE-2024-41357HigJul 26, 2024
    risk 0.49cvss 7.1epss 0.01

    phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via /app/admin/powerDNS/record-edit.php.

  • CVE-2024-2301HigMay 23, 2024
    risk 0.49cvss 7.6epss 0.00

    Certain HP LaserJet Pro devices are potentially vulnerable to a Cross-Site Scripting (XSS) attack via the web management interface of the device.

  • CVE-2024-30048HigMay 14, 2024
    risk 0.49cvss 7.6epss 0.01

    Dynamics 365 Customer Insights Spoofing Vulnerability