CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Description
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85
CVEs mapped to this weakness (46,607)
page 84 of 2,331| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-30047 | Hig | 0.49 | 7.6 | 0.01 | May 14, 2024 | Dynamics 365 Customer Insights Spoofing Vulnerability | ||
| CVE-2024-27082 | Hig | 0.49 | 7.6 | 0.01 | May 14, 2024 | Cacti provides an operational monitoring and fault management framework. Versions of Cacti prior to 1.2.27 are vulnerable to stored cross-site scripting, a type of cross-site scripting where malicious scripts are permanently stored on a target server and served to users who… | ||
| CVE-2024-4337 | Hig | 0.49 | 7.6 | 0.00 | Apr 30, 2024 | Adive Framework 2.0.8, does not sufficiently encode user-controlled inputs, resulting in a persistent Cross-Site Scripting (XSS) vulnerability via the /adive/admin/nav/add, in multiple parameters. This vulnerability allows an attacker to retrieve the session details of an… | ||
| CVE-2024-4336 | Hig | 0.49 | 7.6 | 0.00 | Apr 30, 2024 | Adive Framework 2.0.8, does not sufficiently encode user-controlled inputs, resulting in a persistent Cross-Site Scripting (XSS) vulnerability via the /adive/admin/tables/add, in multiple parameters. An attacker could retrieve the session details of an authenticated user. | ||
| CVE-2024-29003 | Hig | 0.49 | 7.5 | 0.01 | Apr 18, 2024 | The SolarWinds Platform was susceptible to a XSS vulnerability that affects the maps section of the user interface. This vulnerability requires authentication and requires user interaction. | ||
| CVE-2024-29504 | Hig | 0.49 | 7.6 | 0.01 | Apr 10, 2024 | Cross Site Scripting vulnerability in Summernote v.0.8.18 and before allows a remote attacker to execute arbtirary code via a crafted payload to the codeview parameter. | ||
| CVE-2024-28434 | Hig | 0.49 | 7.6 | 0.01 | Mar 25, 2024 | The CRM platform Twenty is vulnerable to stored cross site scripting via file upload in version 0.3.0. A crafted svg file can trigger the execution of the javascript code. | ||
| CVE-2024-21419 | Hig | 0.49 | 7.6 | 0.01 | Mar 12, 2024 | Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | ||
| CVE-2024-24907 | Hig | 0.49 | 7.6 | 0.00 | Mar 1, 2024 | Dell Secure Connect Gateway (SCG) Policy Manager, all versions, contain(s) a Stored Cross-Site Scripting Vulnerability in the Filters page. An adjacent network high privileged attacker could potentially exploit this vulnerability, leading to the storage of malicious HTML or… | ||
| CVE-2024-24905 | Hig | 0.49 | 7.6 | 0.00 | Mar 1, 2024 | Dell Secure Connect Gateway (SCG) Policy Manager, all versions, contain(s) a Stored Cross-Site Scripting Vulnerability. An adjacent network high privileged attacker could potentially exploit this vulnerability, leading to the storage of malicious HTML or JavaScript codes in a… | ||
| CVE-2024-24904 | Hig | 0.49 | 7.6 | 0.00 | Mar 1, 2024 | Dell Secure Connect Gateway (SCG) Policy Manager, all versions, contain(s) a Stored Cross-Site Scripting Vulnerability. An adjacent network high privileged attacker could potentially exploit this vulnerability, leading to the storage of malicious HTML or JavaScript codes in a… | ||
| CVE-2024-24906 | Hig | 0.49 | 7.6 | 0.00 | Mar 1, 2024 | Dell Secure Connect Gateway (SCG) Policy Manager, all versions, contain(s) a Stored Cross-Site Scripting Vulnerability in Policy page. An adjacent network high privileged attacker could potentially exploit this vulnerability, leading to the storage of malicious HTML or… | ||
| CVE-2024-1474 | Hig | 0.49 | 7.5 | 0.00 | Feb 21, 2024 | In WS_FTP Server versions before 8.8.5, reflected cross-site scripting issues have been identified on various user supplied inputs on the WS_FTP Server administrative interface. | ||
| CVE-2024-1648 | Hig | 0.49 | 7.5 | 0.01 | Feb 20, 2024 | electron-pdf version 20.0.0 allows an external attacker to remotely obtain arbitrary local files. This is possible because the application does not validate the HTML content entered by the user. | ||
| CVE-2024-1647 | Hig | 0.49 | 7.5 | 0.01 | Feb 20, 2024 | Pyhtml2pdf version 0.0.6 allows an external attacker to remotely obtain arbitrary local files. This is possible because the application does not validate the HTML content entered by the user. | ||
| CVE-2023-6123 | Hig | 0.49 | 7.5 | 0.01 | Feb 15, 2024 | Improper Neutralization vulnerability affects OpenText ALM Octane version 16.2.100 and above. The vulnerability could result in a remote code execution attack. | ||
| CVE-2024-21396 | Hig | 0.49 | 7.6 | 0.01 | Feb 13, 2024 | Dynamics 365 Sales Spoofing Vulnerability | ||
| CVE-2024-21394 | Hig | 0.49 | 7.6 | 0.01 | Feb 13, 2024 | Dynamics 365 Field Service Spoofing Vulnerability | ||
| CVE-2024-21393 | Hig | 0.49 | 7.6 | 0.01 | Feb 13, 2024 | Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | ||
| CVE-2024-21389 | Hig | 0.49 | 7.6 | 0.01 | Feb 13, 2024 | Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability |
- risk 0.49cvss 7.6epss 0.01
Dynamics 365 Customer Insights Spoofing Vulnerability
- risk 0.49cvss 7.6epss 0.01
Cacti provides an operational monitoring and fault management framework. Versions of Cacti prior to 1.2.27 are vulnerable to stored cross-site scripting, a type of cross-site scripting where malicious scripts are permanently stored on a target server and served to users who…
- risk 0.49cvss 7.6epss 0.00
Adive Framework 2.0.8, does not sufficiently encode user-controlled inputs, resulting in a persistent Cross-Site Scripting (XSS) vulnerability via the /adive/admin/nav/add, in multiple parameters. This vulnerability allows an attacker to retrieve the session details of an…
- risk 0.49cvss 7.6epss 0.00
Adive Framework 2.0.8, does not sufficiently encode user-controlled inputs, resulting in a persistent Cross-Site Scripting (XSS) vulnerability via the /adive/admin/tables/add, in multiple parameters. An attacker could retrieve the session details of an authenticated user.
- risk 0.49cvss 7.5epss 0.01
The SolarWinds Platform was susceptible to a XSS vulnerability that affects the maps section of the user interface. This vulnerability requires authentication and requires user interaction.
- risk 0.49cvss 7.6epss 0.01
Cross Site Scripting vulnerability in Summernote v.0.8.18 and before allows a remote attacker to execute arbtirary code via a crafted payload to the codeview parameter.
- risk 0.49cvss 7.6epss 0.01
The CRM platform Twenty is vulnerable to stored cross site scripting via file upload in version 0.3.0. A crafted svg file can trigger the execution of the javascript code.
- risk 0.49cvss 7.6epss 0.01
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
- risk 0.49cvss 7.6epss 0.00
Dell Secure Connect Gateway (SCG) Policy Manager, all versions, contain(s) a Stored Cross-Site Scripting Vulnerability in the Filters page. An adjacent network high privileged attacker could potentially exploit this vulnerability, leading to the storage of malicious HTML or…
- risk 0.49cvss 7.6epss 0.00
Dell Secure Connect Gateway (SCG) Policy Manager, all versions, contain(s) a Stored Cross-Site Scripting Vulnerability. An adjacent network high privileged attacker could potentially exploit this vulnerability, leading to the storage of malicious HTML or JavaScript codes in a…
- risk 0.49cvss 7.6epss 0.00
Dell Secure Connect Gateway (SCG) Policy Manager, all versions, contain(s) a Stored Cross-Site Scripting Vulnerability. An adjacent network high privileged attacker could potentially exploit this vulnerability, leading to the storage of malicious HTML or JavaScript codes in a…
- risk 0.49cvss 7.6epss 0.00
Dell Secure Connect Gateway (SCG) Policy Manager, all versions, contain(s) a Stored Cross-Site Scripting Vulnerability in Policy page. An adjacent network high privileged attacker could potentially exploit this vulnerability, leading to the storage of malicious HTML or…
- risk 0.49cvss 7.5epss 0.00
In WS_FTP Server versions before 8.8.5, reflected cross-site scripting issues have been identified on various user supplied inputs on the WS_FTP Server administrative interface.
- risk 0.49cvss 7.5epss 0.01
electron-pdf version 20.0.0 allows an external attacker to remotely obtain arbitrary local files. This is possible because the application does not validate the HTML content entered by the user.
- risk 0.49cvss 7.5epss 0.01
Pyhtml2pdf version 0.0.6 allows an external attacker to remotely obtain arbitrary local files. This is possible because the application does not validate the HTML content entered by the user.
- risk 0.49cvss 7.5epss 0.01
Improper Neutralization vulnerability affects OpenText ALM Octane version 16.2.100 and above. The vulnerability could result in a remote code execution attack.
- risk 0.49cvss 7.6epss 0.01
Dynamics 365 Sales Spoofing Vulnerability
- risk 0.49cvss 7.6epss 0.01
Dynamics 365 Field Service Spoofing Vulnerability
- risk 0.49cvss 7.6epss 0.01
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
- risk 0.49cvss 7.6epss 0.01
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability