CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Description
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85
CVEs mapped to this weakness (23,317)
page 832 of 1,166| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-43830 | — | 0.00 | — | 0.01 | Sep 27, 2023 | A Cross-site scripting (XSS) vulnerability in /panel/configuration/financial/ of Subrion v4.2.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into several fields: 'Minimum deposit', 'Maximum deposit' and/or 'Maximum balance'. | ||
| CVE-2022-4137 | 0.00 | — | 0.01 | Sep 25, 2023 | A reflected cross-site scripting (XSS) vulnerability was found in the 'oob' OAuth endpoint due to incorrect null-byte handling. This issue allows a malicious link to insert an arbitrary URI into a Keycloak error page. This flaw requires a user or administrator to interact with a… | |||
| CVE-2023-42817 | 0.00 | — | 0.00 | Sep 25, 2023 | Pimcore admin-ui-classic-bundle provides a Backend UI for Pimcore. The translation value with text including “%s” (from “%suggest%) is parsed by sprintf() even though it’s supposed to be output literally to the user. The translations may be accessible by a user with… | |||
| CVE-2023-42458 | 0.00 | — | 0.01 | Sep 21, 2023 | Zope is an open-source web application server. Prior to versions 4.8.10 and 5.8.5, there is a stored cross site scripting vulnerability for SVG images. Note that an image tag with an SVG image as source is never vulnerable, even when the SVG image contains malicious code. To… | |||
| CVE-2023-41048 | 0.00 | — | 0.00 | Sep 21, 2023 | plone.namedfile allows users to handle `File` and `Image` fields targeting, but not depending on, Plone Dexterity content. Prior to versions 5.6.1, 6.0.3, 6.1.3, and 6.2.1, there is a stored cross site scripting vulnerability for SVG images. A security hotfix from 2021 already… | |||
| CVE-2018-5478 | 0.00 | — | 0.00 | Sep 21, 2023 | Contao 3.x before 3.5.32 allows XSS via the unsubscribe module in the frontend newsletter extension. | |||
| CVE-2023-43499 | 0.00 | — | 0.01 | Sep 20, 2023 | Jenkins Build Failure Analyzer Plugin 2.4.1 and earlier does not escape Failure Cause names in build logs, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to create or update Failure Causes. | |||
| CVE-2023-43495 | 0.00 | — | 0.01 | Sep 20, 2023 | Jenkins 2.423 and earlier, LTS 2.414.1 and earlier does not escape the value of the 'caption' constructor parameter of 'ExpandableDetailsNote', resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control this parameter. | |||
| CVE-2022-1438 | 0.00 | — | 0.01 | Sep 20, 2023 | A flaw was found in Keycloak. Under specific circumstances, HTML entities are not sanitized during user impersonation, resulting in a Cross-site scripting (XSS) vulnerability. | |||
| CVE-2023-38888 | 0.00 | — | 0.01 | Sep 20, 2023 | Cross Site Scripting vulnerability in Dolibarr ERP CRM v.17.0.1 and before allows a remote attacker to obtain sensitive information and execute arbitrary code via the REST API module, related to analyseVarsForSqlAndScriptsInjection and testSqlAndScriptInject. | |||
| CVE-2023-5060 | 0.00 | — | 0.01 | Sep 19, 2023 | Cross-site Scripting (XSS) - DOM in GitHub repository librenms/librenms prior to 23.9.1. | |||
| CVE-2023-42399 | — | 0.00 | — | 0.01 | Sep 19, 2023 | Cross Site Scripting vulnerability in xdsoft.net Jodit Editor v.4.0.0-beta.86 allows a remote attacker to obtain sensitive information via the rich text editor component. | ||
| CVE-2023-37611 | — | 0.00 | — | 0.01 | Sep 18, 2023 | Cross Site Scripting (XSS) vulnerability in Neos CMS 8.3.3 allows a remote authenticated attacker to execute arbitrary code via a crafted SVG file to the neos/management/media component. | ||
| CVE-2023-4982 | 0.00 | — | 0.01 | Sep 15, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository librenms/librenms prior to 23.9.0. | |||
| CVE-2023-4981 | 0.00 | — | 0.01 | Sep 15, 2023 | Cross-site Scripting (XSS) - DOM in GitHub repository librenms/librenms prior to 23.9.0. | |||
| CVE-2023-4980 | 0.00 | — | 0.01 | Sep 15, 2023 | Cross-site Scripting (XSS) - Generic in GitHub repository librenms/librenms prior to 23.9.0. | |||
| CVE-2023-4978 | 0.00 | — | 0.01 | Sep 15, 2023 | Cross-site Scripting (XSS) - DOM in GitHub repository librenms/librenms prior to 23.9.0. | |||
| CVE-2023-4979 | 0.00 | — | 0.01 | Sep 15, 2023 | Cross-site Scripting (XSS) - Reflected in GitHub repository librenms/librenms prior to 23.9.0. | |||
| CVE-2023-41592 | — | 0.00 | — | 0.01 | Sep 14, 2023 | Froala Editor v4.0.1 to v4.1.1 was discovered to contain a cross-site scripting (XSS) vulnerability. | ||
| CVE-2023-4913 | — | 0.00 | — | 0.00 | Sep 12, 2023 | Cross-site Scripting (XSS) - Reflected in GitHub repository cecilapp/cecil prior to 7.47.1. |
- CVE-2023-43830Sep 27, 2023risk 0.00cvss —epss 0.01
A Cross-site scripting (XSS) vulnerability in /panel/configuration/financial/ of Subrion v4.2.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into several fields: 'Minimum deposit', 'Maximum deposit' and/or 'Maximum balance'.
- CVE-2022-4137Sep 25, 2023risk 0.00cvss —epss 0.01
A reflected cross-site scripting (XSS) vulnerability was found in the 'oob' OAuth endpoint due to incorrect null-byte handling. This issue allows a malicious link to insert an arbitrary URI into a Keycloak error page. This flaw requires a user or administrator to interact with a…
- CVE-2023-42817Sep 25, 2023risk 0.00cvss —epss 0.00
Pimcore admin-ui-classic-bundle provides a Backend UI for Pimcore. The translation value with text including “%s” (from “%suggest%) is parsed by sprintf() even though it’s supposed to be output literally to the user. The translations may be accessible by a user with…
- CVE-2023-42458Sep 21, 2023risk 0.00cvss —epss 0.01
Zope is an open-source web application server. Prior to versions 4.8.10 and 5.8.5, there is a stored cross site scripting vulnerability for SVG images. Note that an image tag with an SVG image as source is never vulnerable, even when the SVG image contains malicious code. To…
- CVE-2023-41048Sep 21, 2023risk 0.00cvss —epss 0.00
plone.namedfile allows users to handle `File` and `Image` fields targeting, but not depending on, Plone Dexterity content. Prior to versions 5.6.1, 6.0.3, 6.1.3, and 6.2.1, there is a stored cross site scripting vulnerability for SVG images. A security hotfix from 2021 already…
- CVE-2018-5478Sep 21, 2023risk 0.00cvss —epss 0.00
Contao 3.x before 3.5.32 allows XSS via the unsubscribe module in the frontend newsletter extension.
- CVE-2023-43499Sep 20, 2023risk 0.00cvss —epss 0.01
Jenkins Build Failure Analyzer Plugin 2.4.1 and earlier does not escape Failure Cause names in build logs, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to create or update Failure Causes.
- CVE-2023-43495Sep 20, 2023risk 0.00cvss —epss 0.01
Jenkins 2.423 and earlier, LTS 2.414.1 and earlier does not escape the value of the 'caption' constructor parameter of 'ExpandableDetailsNote', resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control this parameter.
- CVE-2022-1438Sep 20, 2023risk 0.00cvss —epss 0.01
A flaw was found in Keycloak. Under specific circumstances, HTML entities are not sanitized during user impersonation, resulting in a Cross-site scripting (XSS) vulnerability.
- CVE-2023-38888Sep 20, 2023risk 0.00cvss —epss 0.01
Cross Site Scripting vulnerability in Dolibarr ERP CRM v.17.0.1 and before allows a remote attacker to obtain sensitive information and execute arbitrary code via the REST API module, related to analyseVarsForSqlAndScriptsInjection and testSqlAndScriptInject.
- CVE-2023-5060Sep 19, 2023risk 0.00cvss —epss 0.01
Cross-site Scripting (XSS) - DOM in GitHub repository librenms/librenms prior to 23.9.1.
- CVE-2023-42399Sep 19, 2023risk 0.00cvss —epss 0.01
Cross Site Scripting vulnerability in xdsoft.net Jodit Editor v.4.0.0-beta.86 allows a remote attacker to obtain sensitive information via the rich text editor component.
- CVE-2023-37611Sep 18, 2023risk 0.00cvss —epss 0.01
Cross Site Scripting (XSS) vulnerability in Neos CMS 8.3.3 allows a remote authenticated attacker to execute arbitrary code via a crafted SVG file to the neos/management/media component.
- CVE-2023-4982Sep 15, 2023risk 0.00cvss —epss 0.01
Cross-site Scripting (XSS) - Stored in GitHub repository librenms/librenms prior to 23.9.0.
- CVE-2023-4981Sep 15, 2023risk 0.00cvss —epss 0.01
Cross-site Scripting (XSS) - DOM in GitHub repository librenms/librenms prior to 23.9.0.
- CVE-2023-4980Sep 15, 2023risk 0.00cvss —epss 0.01
Cross-site Scripting (XSS) - Generic in GitHub repository librenms/librenms prior to 23.9.0.
- CVE-2023-4978Sep 15, 2023risk 0.00cvss —epss 0.01
Cross-site Scripting (XSS) - DOM in GitHub repository librenms/librenms prior to 23.9.0.
- CVE-2023-4979Sep 15, 2023risk 0.00cvss —epss 0.01
Cross-site Scripting (XSS) - Reflected in GitHub repository librenms/librenms prior to 23.9.0.
- CVE-2023-41592Sep 14, 2023risk 0.00cvss —epss 0.01
Froala Editor v4.0.1 to v4.1.1 was discovered to contain a cross-site scripting (XSS) vulnerability.
- CVE-2023-4913Sep 12, 2023risk 0.00cvss —epss 0.00
Cross-site Scripting (XSS) - Reflected in GitHub repository cecilapp/cecil prior to 7.47.1.