VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (23,314)

page 855 of 1,166
  • CVE-2022-23494Dec 8, 2022
    risk 0.00cvss epss 0.01

    tinymce is an open source rich text editor. A cross-site scripting (XSS) vulnerability was discovered in the alert and confirm dialogs when these dialogs were provided with malicious HTML content. This can occur in plugins that use the alert or confirm dialogs, such as in the…

  • CVE-2022-4350Dec 8, 2022
    risk 0.00cvss epss 0.00

    A vulnerability, which was classified as problematic, was found in Mingsoft MCMS 5.2.8. Affected is an unknown function of the file search.do. The manipulation of the argument content_title leads to cross site scripting. It is possible to launch the attack remotely. The exploit…

  • CVE-2022-4348Dec 8, 2022
    risk 0.00cvss epss 0.00

    A vulnerability was found in y_project RuoYi-Cloud. It has been rated as problematic. Affected by this issue is some unknown functionality of the component JSON Handler. The manipulation leads to cross site scripting. The attack may be launched remotely. The exploit has been…

  • CVE-2022-41994Dec 7, 2022
    risk 0.00cvss epss 0.01

    Stored cross-site scripting vulnerability in Permission Settings of baserCMS versions prior to 4.7.2 allows a remote authenticated attacker with an administrative privilege to inject an arbitrary script.

  • CVE-2022-46687Dec 7, 2022
    risk 0.00cvss epss 0.00

    Jenkins Spring Config Plugin 2.0.0 and earlier does not escape build display names shown on the Spring Config view, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to change build display names.

  • CVE-2022-46686Dec 7, 2022
    risk 0.00cvss epss 0.00

    Jenkins Custom Build Properties Plugin 2.79.vc095ccc85094 and earlier does not escape property values and build display names on the Custom Build Properties and Build Summary pages, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to…

  • CVE-2022-42486Dec 7, 2022
    risk 0.00cvss epss 0.01

    Stored cross-site scripting vulnerability in User group management of baserCMS versions prior to 4.7.2 allows a remote authenticated attacker with an administrative privilege to inject an arbitrary script.

  • CVE-2022-23466Dec 6, 2022
    risk 0.00cvss epss 0.00

    teler is an real-time intrusion detection and threat alert dashboard. teler prior to version 2.0.0-rc.4 is vulnerable to DOM-based cross-site scripting (XSS) in the teler dashboard. When teler requests messages from the event stream on the `/events` endpoint, the log data…

  • CVE-2022-43556Dec 5, 2022
    risk 0.00cvss epss 0.01

    Concrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2 is vulnerable to XSS in the text input field since the result dashboard page output is not sanitized. The Concrete CMS security team has ranked this 4.2 with CVSS v3.1 vector…

  • CVE-2022-40849Dec 1, 2022
    risk 0.00cvss epss 0.00

    ThinkCMF version 6.0.7 is affected by Stored Cross-Site Scripting (XSS). An attacker who successfully exploited this vulnerability could inject a Persistent XSS payload in the Slideshow Management section that execute arbitrary JavaScript code on the client side, e.g., to steal…

  • CVE-2022-46147Nov 28, 2022
    risk 0.00cvss epss 0.01

    Drag and Drop XBlock v2 implements a drag-and-drop style problem, where a learner has to drag items to zones on a target image. Versions prior to 3.0.0 are vulnerable to cross-site scripting in multiple XBlock Fields. Any platform that has deployed the XBlock may be impacted.…

  • CVE-2022-0698Nov 25, 2022
    risk 0.00cvss epss 0.01

    Microweber version 1.3.1 allows an unauthenticated user to perform an account takeover via an XSS on the 'select-file' parameter.

  • CVE-2022-39325Nov 25, 2022
    risk 0.00cvss epss 0.01

    BaserCMS is a content management system with a japanese language focus. In affected versions there is a cross-site scripting vulnerability on the management system of baserCMS. This is a vulnerability that needs to be addressed when the management system is used by an…

  • CVE-2022-37721Nov 25, 2022
    risk 0.00cvss epss 0.01

    PyroCMS 3.9 is vulnerable to a stored Cross Site Scripting (XSS_ when a low privileged user such as an author, injects a crafted html and javascript payload in a blog post, leading to full admin account takeover or privilege escalation.

  • CVE-2022-41706Nov 25, 2022
    risk 0.00cvss epss 0.01

    Browsershot version 3.57.2 allows an external attacker to remotely obtain arbitrary local files. This is possible because the application does not validate the URL protocol passed to the Browsershot::url method.

  • CVE-2022-43983Nov 25, 2022
    risk 0.00cvss epss 0.01

    Browsershot version 3.57.2 allows an external attacker to remotely obtain arbitrary local files. This is possible because the application does not validate that the HTML content passed to the Browsershot::html method does not contain URL's that use the file:// protocol.

  • CVE-2022-43984Nov 25, 2022
    risk 0.00cvss epss 0.01

    Browsershot version 3.57.3 allows an external attacker to remotely obtain arbitrary local files. This is possible because the application does not validate that the JS content imported from an external source passed to the Browsershot::html method does not contain URLs that use…

  • CVE-2022-42095Nov 23, 2022
    risk 0.00cvss epss 0.02

    Backdrop CMS version 1.23.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Page content.

  • CVE-2022-37430Nov 23, 2022
    risk 0.00cvss epss 0.01

    Silverstripe silverstripe/framework through 4.11 allows XSS vulnerability via href attribute of a link (issue 2 of 2).

  • CVE-2022-45151Nov 23, 2022
    risk 0.00cvss epss 0.01

    The stored-XSS vulnerability was discovered in Moodle which exists due to insufficient sanitization of user-supplied data in several "social" user profile fields. An attacker could inject and execute arbitrary HTML and script code in user's browser in context of vulnerable…