VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (46,607)

page 84 of 2,331
  • CVE-2024-30047HigMay 14, 2024
    risk 0.49cvss 7.6epss 0.01

    Dynamics 365 Customer Insights Spoofing Vulnerability

  • CVE-2024-27082HigMay 14, 2024
    risk 0.49cvss 7.6epss 0.01

    Cacti provides an operational monitoring and fault management framework. Versions of Cacti prior to 1.2.27 are vulnerable to stored cross-site scripting, a type of cross-site scripting where malicious scripts are permanently stored on a target server and served to users who…

  • CVE-2024-4337HigApr 30, 2024
    risk 0.49cvss 7.6epss 0.00

    Adive Framework 2.0.8, does not sufficiently encode user-controlled inputs, resulting in a persistent Cross-Site Scripting (XSS) vulnerability via the /adive/admin/nav/add, in multiple parameters. This vulnerability allows an attacker to retrieve the session details of an…

  • CVE-2024-4336HigApr 30, 2024
    risk 0.49cvss 7.6epss 0.00

    Adive Framework 2.0.8, does not sufficiently encode user-controlled inputs, resulting in a persistent Cross-Site Scripting (XSS) vulnerability via the /adive/admin/tables/add, in multiple parameters. An attacker could retrieve the session details of an authenticated user.

  • CVE-2024-29003HigApr 18, 2024
    risk 0.49cvss 7.5epss 0.01

    The SolarWinds Platform was susceptible to a XSS vulnerability that affects the maps section of the user interface. This vulnerability requires authentication and requires user interaction.

  • CVE-2024-29504HigApr 10, 2024
    risk 0.49cvss 7.6epss 0.01

    Cross Site Scripting vulnerability in Summernote v.0.8.18 and before allows a remote attacker to execute arbtirary code via a crafted payload to the codeview parameter.

  • CVE-2024-28434HigMar 25, 2024
    risk 0.49cvss 7.6epss 0.01

    The CRM platform Twenty is vulnerable to stored cross site scripting via file upload in version 0.3.0. A crafted svg file can trigger the execution of the javascript code.

  • CVE-2024-21419HigMar 12, 2024
    risk 0.49cvss 7.6epss 0.01

    Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability

  • CVE-2024-24907HigMar 1, 2024
    risk 0.49cvss 7.6epss 0.00

    Dell Secure Connect Gateway (SCG) Policy Manager, all versions, contain(s) a Stored Cross-Site Scripting Vulnerability in the Filters page. An adjacent network high privileged attacker could potentially exploit this vulnerability, leading to the storage of malicious HTML or…

  • CVE-2024-24905HigMar 1, 2024
    risk 0.49cvss 7.6epss 0.00

    Dell Secure Connect Gateway (SCG) Policy Manager, all versions, contain(s) a Stored Cross-Site Scripting Vulnerability. An adjacent network high privileged attacker could potentially exploit this vulnerability, leading to the storage of malicious HTML or JavaScript codes in a…

  • CVE-2024-24904HigMar 1, 2024
    risk 0.49cvss 7.6epss 0.00

    Dell Secure Connect Gateway (SCG) Policy Manager, all versions, contain(s) a Stored Cross-Site Scripting Vulnerability. An adjacent network high privileged attacker could potentially exploit this vulnerability, leading to the storage of malicious HTML or JavaScript codes in a…

  • CVE-2024-24906HigMar 1, 2024
    risk 0.49cvss 7.6epss 0.00

    Dell Secure Connect Gateway (SCG) Policy Manager, all versions, contain(s) a Stored Cross-Site Scripting Vulnerability in Policy page. An adjacent network high privileged attacker could potentially exploit this vulnerability, leading to the storage of malicious HTML or…

  • CVE-2024-1474HigFeb 21, 2024
    risk 0.49cvss 7.5epss 0.00

    In WS_FTP Server versions before 8.8.5, reflected cross-site scripting issues have been identified on various user supplied inputs on the WS_FTP Server administrative interface.

  • CVE-2024-1648HigFeb 20, 2024
    risk 0.49cvss 7.5epss 0.01

    electron-pdf version 20.0.0 allows an external attacker to remotely obtain arbitrary local files. This is possible because the application does not validate the HTML content entered by the user.

  • CVE-2024-1647HigFeb 20, 2024
    risk 0.49cvss 7.5epss 0.01

    Pyhtml2pdf version 0.0.6 allows an external attacker to remotely obtain arbitrary local files. This is possible because the application does not validate the HTML content entered by the user.

  • CVE-2023-6123HigFeb 15, 2024
    risk 0.49cvss 7.5epss 0.01

    Improper Neutralization vulnerability affects OpenText ALM Octane version 16.2.100 and above. The vulnerability could result in a remote code execution attack.

  • CVE-2024-21396HigFeb 13, 2024
    risk 0.49cvss 7.6epss 0.01

    Dynamics 365 Sales Spoofing Vulnerability

  • CVE-2024-21394HigFeb 13, 2024
    risk 0.49cvss 7.6epss 0.01

    Dynamics 365 Field Service Spoofing Vulnerability

  • CVE-2024-21393HigFeb 13, 2024
    risk 0.49cvss 7.6epss 0.01

    Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability

  • CVE-2024-21389HigFeb 13, 2024
    risk 0.49cvss 7.6epss 0.01

    Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability