CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Description
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85
CVEs mapped to this weakness (23,315)
page 852 of 1,166| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-25094 | 0.00 | — | 0.01 | Jan 4, 2023 | A vulnerability, which was classified as problematic, was found in innologi appointments Extension up to 2.0.5 on TYPO3. This affects an unknown part of the component Appointment Handler. The manipulation of the argument formfield leads to cross site scripting. It is possible to… | |||
| CVE-2022-38723 | — | 0.00 | — | 0.01 | Jan 3, 2023 | Gravitee API Management before 3.15.13 allows path traversal through HTML injection. | ||
| CVE-2010-10002 | 0.00 | — | 0.01 | Jan 1, 2023 | ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability classified as problematic has been found in SimpleSAMLphp simplesamlphp-module-openid. Affected is an unknown function of the file templates/consumer.php of the component OpenID Handler. The manipulation of the argument AuthState… | |||
| CVE-2017-20159 | — | 0.00 | — | 0.01 | Dec 31, 2022 | A vulnerability was found in rf Keynote up to 0.x on Rails. It has been rated as problematic. Affected by this issue is some unknown functionality of the file lib/keynote/rumble.rb. The manipulation of the argument value leads to cross site scripting. The attack may be launched… | ||
| CVE-2017-20158 | 0.00 | — | 0.01 | Dec 31, 2022 | ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in vova07 Yii2 FileAPI Widget up to 0.1.8. It has been declared as problematic. Affected by this vulnerability is the function run of the file actions/UploadAction.php. The manipulation of the argument file leads to cross… | |||
| CVE-2022-4865 | — | 0.00 | — | 0.01 | Dec 31, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.9.1. | ||
| CVE-2022-4866 | — | 0.00 | — | 0.01 | Dec 31, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.9.1. | ||
| CVE-2022-46181 | 0.00 | — | 0.01 | Dec 29, 2022 | Gotify server is a simple server for sending and receiving messages in real-time per WebSocket. Versions prior to 2.2.2 contain an XSS vulnerability that allows authenticated users to upload .html files. An attacker could execute client side scripts **if** another user opened a… | |||
| CVE-2022-4839 | — | 0.00 | — | 0.01 | Dec 29, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.9.1. | ||
| CVE-2022-4841 | — | 0.00 | — | 0.01 | Dec 29, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.9.1. | ||
| CVE-2022-4840 | — | 0.00 | — | 0.01 | Dec 29, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.9.1. | ||
| CVE-2018-25053 | 0.00 | — | 0.01 | Dec 28, 2022 | A vulnerability was found in moappi Json2html up to 1.1.x and classified as problematic. This issue affects some unknown processing of the file json2html.js. The manipulation leads to cross site scripting. The attack may be initiated remotely. Upgrading to version 1.2.0 is able… | |||
| CVE-2018-25050 | — | 0.00 | — | 0.01 | Dec 28, 2022 | A vulnerability, which was classified as problematic, has been found in Harvest Chosen up to 1.8.6. Affected by this issue is the function AbstractChosen of the file coffee/lib/abstract-chosen.coffee. The manipulation of the argument group_label leads to cross site scripting.… | ||
| CVE-2019-25088 | 0.00 | — | 0.01 | Dec 27, 2022 | A vulnerability was found in ytti Oxidized Web. It has been classified as problematic. Affected is an unknown function of the file lib/oxidized/web/views/conf_search.haml. The manipulation of the argument to_research leads to cross site scripting. It is possible to launch the… | |||
| CVE-2021-30134 | — | 0.00 | — | 0.01 | Dec 26, 2022 | php-mod/curl (a wrapper of the PHP cURL extension) before 2.3.2 allows XSS via the post_file_path_upload.php key parameter and the POST data to post_multidimensional.php. | ||
| CVE-2022-44380 | — | 0.00 | — | 0.00 | Dec 25, 2022 | Snipe-IT before 6.0.14 is vulnerable to Cross Site Scripting (XSS) for View Assigned Assets. | ||
| CVE-2022-4729 | — | 0.00 | — | 0.01 | Dec 24, 2022 | A vulnerability was found in Graphite Web and classified as problematic. This issue affects some unknown processing of the component Template Name Handler. The manipulation leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the… | ||
| CVE-2022-4730 | — | 0.00 | — | 0.01 | Dec 24, 2022 | A vulnerability was found in Graphite Web. It has been classified as problematic. Affected is an unknown function of the component Absolute Time Range Handler. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been… | ||
| CVE-2022-4728 | — | 0.00 | — | 0.01 | Dec 24, 2022 | A vulnerability has been found in Graphite Web and classified as problematic. This vulnerability affects unknown code of the component Cookie Handler. The manipulation leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the… | ||
| CVE-2022-4695 | — | 0.00 | — | 0.01 | Dec 23, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.9.0. |
- CVE-2019-25094Jan 4, 2023risk 0.00cvss —epss 0.01
A vulnerability, which was classified as problematic, was found in innologi appointments Extension up to 2.0.5 on TYPO3. This affects an unknown part of the component Appointment Handler. The manipulation of the argument formfield leads to cross site scripting. It is possible to…
- CVE-2022-38723Jan 3, 2023risk 0.00cvss —epss 0.01
Gravitee API Management before 3.15.13 allows path traversal through HTML injection.
- CVE-2010-10002Jan 1, 2023risk 0.00cvss —epss 0.01
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability classified as problematic has been found in SimpleSAMLphp simplesamlphp-module-openid. Affected is an unknown function of the file templates/consumer.php of the component OpenID Handler. The manipulation of the argument AuthState…
- CVE-2017-20159Dec 31, 2022risk 0.00cvss —epss 0.01
A vulnerability was found in rf Keynote up to 0.x on Rails. It has been rated as problematic. Affected by this issue is some unknown functionality of the file lib/keynote/rumble.rb. The manipulation of the argument value leads to cross site scripting. The attack may be launched…
- CVE-2017-20158Dec 31, 2022risk 0.00cvss —epss 0.01
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in vova07 Yii2 FileAPI Widget up to 0.1.8. It has been declared as problematic. Affected by this vulnerability is the function run of the file actions/UploadAction.php. The manipulation of the argument file leads to cross…
- CVE-2022-4865Dec 31, 2022risk 0.00cvss —epss 0.01
Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.9.1.
- CVE-2022-4866Dec 31, 2022risk 0.00cvss —epss 0.01
Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.9.1.
- CVE-2022-46181Dec 29, 2022risk 0.00cvss —epss 0.01
Gotify server is a simple server for sending and receiving messages in real-time per WebSocket. Versions prior to 2.2.2 contain an XSS vulnerability that allows authenticated users to upload .html files. An attacker could execute client side scripts **if** another user opened a…
- CVE-2022-4839Dec 29, 2022risk 0.00cvss —epss 0.01
Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.9.1.
- CVE-2022-4841Dec 29, 2022risk 0.00cvss —epss 0.01
Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.9.1.
- CVE-2022-4840Dec 29, 2022risk 0.00cvss —epss 0.01
Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.9.1.
- CVE-2018-25053Dec 28, 2022risk 0.00cvss —epss 0.01
A vulnerability was found in moappi Json2html up to 1.1.x and classified as problematic. This issue affects some unknown processing of the file json2html.js. The manipulation leads to cross site scripting. The attack may be initiated remotely. Upgrading to version 1.2.0 is able…
- CVE-2018-25050Dec 28, 2022risk 0.00cvss —epss 0.01
A vulnerability, which was classified as problematic, has been found in Harvest Chosen up to 1.8.6. Affected by this issue is the function AbstractChosen of the file coffee/lib/abstract-chosen.coffee. The manipulation of the argument group_label leads to cross site scripting.…
- CVE-2019-25088Dec 27, 2022risk 0.00cvss —epss 0.01
A vulnerability was found in ytti Oxidized Web. It has been classified as problematic. Affected is an unknown function of the file lib/oxidized/web/views/conf_search.haml. The manipulation of the argument to_research leads to cross site scripting. It is possible to launch the…
- CVE-2021-30134Dec 26, 2022risk 0.00cvss —epss 0.01
php-mod/curl (a wrapper of the PHP cURL extension) before 2.3.2 allows XSS via the post_file_path_upload.php key parameter and the POST data to post_multidimensional.php.
- CVE-2022-44380Dec 25, 2022risk 0.00cvss —epss 0.00
Snipe-IT before 6.0.14 is vulnerable to Cross Site Scripting (XSS) for View Assigned Assets.
- CVE-2022-4729Dec 24, 2022risk 0.00cvss —epss 0.01
A vulnerability was found in Graphite Web and classified as problematic. This issue affects some unknown processing of the component Template Name Handler. The manipulation leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the…
- CVE-2022-4730Dec 24, 2022risk 0.00cvss —epss 0.01
A vulnerability was found in Graphite Web. It has been classified as problematic. Affected is an unknown function of the component Absolute Time Range Handler. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been…
- CVE-2022-4728Dec 24, 2022risk 0.00cvss —epss 0.01
A vulnerability has been found in Graphite Web and classified as problematic. This vulnerability affects unknown code of the component Cookie Handler. The manipulation leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the…
- CVE-2022-4695Dec 23, 2022risk 0.00cvss —epss 0.01
Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.9.0.