CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Description
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85
CVEs mapped to this weakness (23,315)
page 851 of 1,166| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-0310 | — | 0.00 | — | 0.01 | Jan 15, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.10. | ||
| CVE-2023-0313 | — | 0.00 | — | 0.00 | Jan 15, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.10. | ||
| CVE-2023-0312 | — | 0.00 | — | 0.01 | Jan 15, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.10. | ||
| CVE-2023-0314 | — | 0.00 | — | 0.01 | Jan 15, 2023 | Cross-site Scripting (XSS) - Reflected in GitHub repository thorsten/phpmyfaq prior to 3.1.10. | ||
| CVE-2023-22491 | 0.00 | — | 0.01 | Jan 13, 2023 | Gatsby is a free and open source framework based on React that helps developers build websites and apps. The gatsby-transformer-remark plugin prior to versions 5.25.1 and 6.3.2 passes input through to the `gray-matter` npm package, which is vulnerable to JavaScript injection in… | |||
| CVE-2021-46871 | — | 0.00 | — | 0.00 | Jan 10, 2023 | tag.ex in Phoenix Phoenix.HTML (aka phoenix_html) before 3.0.4 allows XSS in HEEx class attributes. | ||
| CVE-2022-46769 | 0.00 | — | 0.01 | Jan 9, 2023 | An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability in Sling App CMS version 1.1.2 and prior may allow an authenticated remote attacker to perform a reflected cross-site scripting (XSS) attack in the site group feature. … | |||
| CVE-2010-10004 | — | 0.00 | — | 0.01 | Jan 9, 2023 | A vulnerability was found in Information Cards Module on simpleSAMLphp and classified as problematic. This issue affects some unknown processing. The manipulation leads to cross site scripting. The attack may be initiated remotely. Upgrading to version 1.0 is able to address… | ||
| CVE-2020-36644 | 0.00 | — | 0.01 | Jan 7, 2023 | A vulnerability has been found in jamesmartin Inline SVG up to 1.7.1 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file lib/inline_svg/action_view/helpers.rb of the component URL Parameter Handler. The manipulation of the… | |||
| CVE-2023-0108 | — | 0.00 | — | 0.01 | Jan 7, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.10.0. | ||
| CVE-2023-0110 | — | 0.00 | — | 0.01 | Jan 7, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.10.0. | ||
| CVE-2023-0106 | — | 0.00 | — | 0.01 | Jan 7, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.10.0. | ||
| CVE-2023-0111 | — | 0.00 | — | 0.01 | Jan 7, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.10.0. | ||
| CVE-2023-0112 | — | 0.00 | — | 0.01 | Jan 7, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.10.0. | ||
| CVE-2023-0107 | — | 0.00 | — | 0.01 | Jan 7, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.10.0. | ||
| CVE-2021-4303 | 0.00 | — | 0.01 | Jan 5, 2023 | A vulnerability, which was classified as problematic, has been found in shannah Xataface up to 2.x. Affected by this issue is the function testftp of the file install/install_form.js.php of the component Installer. The manipulation leads to cross site scripting. The attack may… | |||
| CVE-2016-15010 | 0.00 | — | 0.01 | Jan 5, 2023 | ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability classified as problematic was found in University of Cambridge django-ucamlookup up to 1.9.1. Affected by this vulnerability is an unknown functionality of the component Lookup Handler. The manipulation leads to cross site… | |||
| CVE-2019-25095 | 0.00 | — | 0.01 | Jan 5, 2023 | A vulnerability, which was classified as problematic, was found in kakwa LdapCherry up to 0.x. Affected is an unknown function of the component URL Handler. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. Upgrading to version 1.0.0… | |||
| CVE-2021-32828 | — | 0.00 | — | 0.01 | Jan 5, 2023 | The Nuxeo Platform is an open source content management platform for building business applications. In version 11.5.109, the `oauth2` REST API is vulnerable to Reflected Cross-Site Scripting (XSS). This XSS can be escalated to Remote Code Execution (RCE) by levering the… | ||
| CVE-2023-22461 | — | 0.00 | — | 0.01 | Jan 4, 2023 | The `sanitize-svg` package, a small SVG sanitizer to prevent cross-site scripting attacks, uses a deny-list-pattern to sanitize SVGs to prevent XSS. In doing so, literal ``-tags and on-event handlers were detected in versions prior to 0.4.0. As a result, downstream… |
- CVE-2023-0310Jan 15, 2023risk 0.00cvss —epss 0.01
Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.10.
- CVE-2023-0313Jan 15, 2023risk 0.00cvss —epss 0.00
Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.10.
- CVE-2023-0312Jan 15, 2023risk 0.00cvss —epss 0.01
Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.10.
- CVE-2023-0314Jan 15, 2023risk 0.00cvss —epss 0.01
Cross-site Scripting (XSS) - Reflected in GitHub repository thorsten/phpmyfaq prior to 3.1.10.
- CVE-2023-22491Jan 13, 2023risk 0.00cvss —epss 0.01
Gatsby is a free and open source framework based on React that helps developers build websites and apps. The gatsby-transformer-remark plugin prior to versions 5.25.1 and 6.3.2 passes input through to the `gray-matter` npm package, which is vulnerable to JavaScript injection in…
- CVE-2021-46871Jan 10, 2023risk 0.00cvss —epss 0.00
tag.ex in Phoenix Phoenix.HTML (aka phoenix_html) before 3.0.4 allows XSS in HEEx class attributes.
- CVE-2022-46769Jan 9, 2023risk 0.00cvss —epss 0.01
An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability in Sling App CMS version 1.1.2 and prior may allow an authenticated remote attacker to perform a reflected cross-site scripting (XSS) attack in the site group feature. …
- CVE-2010-10004Jan 9, 2023risk 0.00cvss —epss 0.01
A vulnerability was found in Information Cards Module on simpleSAMLphp and classified as problematic. This issue affects some unknown processing. The manipulation leads to cross site scripting. The attack may be initiated remotely. Upgrading to version 1.0 is able to address…
- CVE-2020-36644Jan 7, 2023risk 0.00cvss —epss 0.01
A vulnerability has been found in jamesmartin Inline SVG up to 1.7.1 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file lib/inline_svg/action_view/helpers.rb of the component URL Parameter Handler. The manipulation of the…
- CVE-2023-0108Jan 7, 2023risk 0.00cvss —epss 0.01
Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.10.0.
- CVE-2023-0110Jan 7, 2023risk 0.00cvss —epss 0.01
Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.10.0.
- CVE-2023-0106Jan 7, 2023risk 0.00cvss —epss 0.01
Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.10.0.
- CVE-2023-0111Jan 7, 2023risk 0.00cvss —epss 0.01
Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.10.0.
- CVE-2023-0112Jan 7, 2023risk 0.00cvss —epss 0.01
Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.10.0.
- CVE-2023-0107Jan 7, 2023risk 0.00cvss —epss 0.01
Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.10.0.
- CVE-2021-4303Jan 5, 2023risk 0.00cvss —epss 0.01
A vulnerability, which was classified as problematic, has been found in shannah Xataface up to 2.x. Affected by this issue is the function testftp of the file install/install_form.js.php of the component Installer. The manipulation leads to cross site scripting. The attack may…
- CVE-2016-15010Jan 5, 2023risk 0.00cvss —epss 0.01
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability classified as problematic was found in University of Cambridge django-ucamlookup up to 1.9.1. Affected by this vulnerability is an unknown functionality of the component Lookup Handler. The manipulation leads to cross site…
- CVE-2019-25095Jan 5, 2023risk 0.00cvss —epss 0.01
A vulnerability, which was classified as problematic, was found in kakwa LdapCherry up to 0.x. Affected is an unknown function of the component URL Handler. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. Upgrading to version 1.0.0…
- CVE-2021-32828Jan 5, 2023risk 0.00cvss —epss 0.01
The Nuxeo Platform is an open source content management platform for building business applications. In version 11.5.109, the `oauth2` REST API is vulnerable to Reflected Cross-Site Scripting (XSS). This XSS can be escalated to Remote Code Execution (RCE) by levering the…
- CVE-2023-22461Jan 4, 2023risk 0.00cvss —epss 0.01
The `sanitize-svg` package, a small SVG sanitizer to prevent cross-site scripting attacks, uses a deny-list-pattern to sanitize SVGs to prevent XSS. In doing so, literal ``-tags and on-event handlers were detected in versions prior to 0.4.0. As a result, downstream…