CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Description
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85
CVEs mapped to this weakness (23,312)
page 858 of 1,166| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-3869 | 0.00 | — | 0.01 | Nov 5, 2022 | Code Injection in GitHub repository froxlor/froxlor prior to 0.10.38.2. | |||
| CVE-2022-3721 | 0.00 | — | 0.01 | Nov 4, 2022 | Code Injection in GitHub repository froxlor/froxlor prior to 0.10.39. | |||
| CVE-2020-36608 | — | 0.00 | — | 0.00 | Nov 2, 2022 | A vulnerability, which was classified as problematic, has been found in Tribal Systems Zenario CMS. Affected by this issue is some unknown functionality of the file admin_organizer.js of the component Error Log Module. The manipulation leads to cross site scripting. The attack… | ||
| CVE-2022-43982 | 0.00 | — | 0.01 | Nov 2, 2022 | In Apache Airflow versions prior to 2.4.2, the "Trigger DAG with config" screen was susceptible to XSS attacks via the `origin` query argument. | |||
| CVE-2022-43670 | 0.00 | — | 0.01 | Nov 2, 2022 | An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability in Sling App CMS version 1.1.0 and prior may allow an authenticated remote attacker to perform a reflected cross site scripting (XSS) attack in the taxonomy management… | |||
| CVE-2022-3783 | — | 0.00 | — | 0.01 | Oct 31, 2022 | A vulnerability, which was classified as problematic, has been found in node-red-dashboard. This issue affects some unknown processing of the file components/ui-component/ui-component-ctrl.js of the component ui_text Format Handler. The manipulation leads to cross site… | ||
| CVE-2022-3765 | — | 0.00 | — | 0.01 | Oct 31, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.8. | ||
| CVE-2022-3766 | — | 0.00 | — | 0.06 | Oct 31, 2022 | Cross-site Scripting (XSS) - Reflected in GitHub repository thorsten/phpmyfaq prior to 3.1.8. | ||
| CVE-2022-40487 | 0.00 | — | 0.00 | Oct 31, 2022 | ProcessWire v3.0.200 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities via the Search Users and Search Pages function. These vulnerabilities allow attackers to execute arbitrary web scripts or HTML via injection of a crafted payload. | |||
| CVE-2022-25849 | 0.00 | — | 0.00 | Oct 26, 2022 | The package joyqi/hyper-down from 0.0.0 are vulnerable to Cross-site Scripting (XSS) because the module of parse markdown does not filter the href attribute very well. | |||
| CVE-2022-39348 | 0.00 | — | 0.01 | Oct 26, 2022 | Twisted is an event-based framework for internet applications. Started with version 0.9.4, when the host header does not match a configured host `twisted.web.vhost.NameVirtualHost` will return a `NoResource` resource which renders the Host header unescaped into the 404 response… | |||
| CVE-2022-3704 | — | 0.00 | — | 0.01 | Oct 26, 2022 | A vulnerability classified as problematic has been found in Ruby on Rails. This affects an unknown part of the file actionpack/lib/action_dispatch/middleware/templates/routes/_table.html.erb. The manipulation leads to cross site scripting. It is possible to initiate the attack… | ||
| CVE-2022-34870 | — | 0.00 | — | 0.01 | Oct 25, 2022 | Apache Geode versions up to 1.15.0 are vulnerable to a Cross-Site Scripting (XSS) via data injection when using Pulse web application to view Region entries. | ||
| CVE-2022-39350 | — | 0.00 | — | 0.01 | Oct 25, 2022 | @dependencytrack/frontend is a Single Page Application (SPA) used in Dependency-Track, an open source Component Analysis platform that allows organizations to identify and reduce risk in the software supply chain. Due to the common practice of providing vulnerability details in… | ||
| CVE-2022-43425 | 0.00 | — | 0.01 | Oct 19, 2022 | Jenkins Custom Checkbox Parameter Plugin 1.4 and earlier does not escape the name and description of Custom Checkbox Parameter parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure… | |||
| CVE-2022-43420 | 0.00 | — | 0.01 | Oct 19, 2022 | Jenkins Contrast Continuous Application Security Plugin 3.9 and earlier does not escape data returned from the Contrast service when generating a report, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control or modify Contrast… | |||
| CVE-2022-43409 | 0.00 | — | 0.01 | Oct 19, 2022 | Jenkins Pipeline: Supporting APIs Plugin 838.va_3a_087b_4055b and earlier does not sanitize or properly encode URLs of hyperlinks sending POST requests in build logs, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to create Pipelines. | |||
| CVE-2022-42466 | 0.00 | — | 0.01 | Oct 19, 2022 | Prior to 2.0.0-M9, it was possible for an end-user to set the value of an editable string property of a domain object to a value that would be rendered unchanged when the value was saved. In particular, the end-user could enter javascript or similar and this would be executed.… | |||
| CVE-2022-3608 | — | 0.00 | — | 0.01 | Oct 19, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.2.0-alpha. | ||
| CVE-2022-31037 | — | 0.00 | — | 0.00 | Oct 18, 2022 | OroCommerce is an open-source Business to Business Commerce application. Versions between 4.1.0 and 4.1.17 inclusive, 4.2.0 and 4.2.11 inclusive, and between 5.0.0 and 5.0.3 inclusive, are vulnerable to Cross-site Scripting in the UPS Surcharge field of the Shipping rule edit… |
- CVE-2022-3869Nov 5, 2022risk 0.00cvss —epss 0.01
Code Injection in GitHub repository froxlor/froxlor prior to 0.10.38.2.
- CVE-2022-3721Nov 4, 2022risk 0.00cvss —epss 0.01
Code Injection in GitHub repository froxlor/froxlor prior to 0.10.39.
- CVE-2020-36608Nov 2, 2022risk 0.00cvss —epss 0.00
A vulnerability, which was classified as problematic, has been found in Tribal Systems Zenario CMS. Affected by this issue is some unknown functionality of the file admin_organizer.js of the component Error Log Module. The manipulation leads to cross site scripting. The attack…
- CVE-2022-43982Nov 2, 2022risk 0.00cvss —epss 0.01
In Apache Airflow versions prior to 2.4.2, the "Trigger DAG with config" screen was susceptible to XSS attacks via the `origin` query argument.
- CVE-2022-43670Nov 2, 2022risk 0.00cvss —epss 0.01
An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability in Sling App CMS version 1.1.0 and prior may allow an authenticated remote attacker to perform a reflected cross site scripting (XSS) attack in the taxonomy management…
- CVE-2022-3783Oct 31, 2022risk 0.00cvss —epss 0.01
A vulnerability, which was classified as problematic, has been found in node-red-dashboard. This issue affects some unknown processing of the file components/ui-component/ui-component-ctrl.js of the component ui_text Format Handler. The manipulation leads to cross site…
- CVE-2022-3765Oct 31, 2022risk 0.00cvss —epss 0.01
Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.8.
- CVE-2022-3766Oct 31, 2022risk 0.00cvss —epss 0.06
Cross-site Scripting (XSS) - Reflected in GitHub repository thorsten/phpmyfaq prior to 3.1.8.
- CVE-2022-40487Oct 31, 2022risk 0.00cvss —epss 0.00
ProcessWire v3.0.200 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities via the Search Users and Search Pages function. These vulnerabilities allow attackers to execute arbitrary web scripts or HTML via injection of a crafted payload.
- CVE-2022-25849Oct 26, 2022risk 0.00cvss —epss 0.00
The package joyqi/hyper-down from 0.0.0 are vulnerable to Cross-site Scripting (XSS) because the module of parse markdown does not filter the href attribute very well.
- CVE-2022-39348Oct 26, 2022risk 0.00cvss —epss 0.01
Twisted is an event-based framework for internet applications. Started with version 0.9.4, when the host header does not match a configured host `twisted.web.vhost.NameVirtualHost` will return a `NoResource` resource which renders the Host header unescaped into the 404 response…
- CVE-2022-3704Oct 26, 2022risk 0.00cvss —epss 0.01
A vulnerability classified as problematic has been found in Ruby on Rails. This affects an unknown part of the file actionpack/lib/action_dispatch/middleware/templates/routes/_table.html.erb. The manipulation leads to cross site scripting. It is possible to initiate the attack…
- CVE-2022-34870Oct 25, 2022risk 0.00cvss —epss 0.01
Apache Geode versions up to 1.15.0 are vulnerable to a Cross-Site Scripting (XSS) via data injection when using Pulse web application to view Region entries.
- CVE-2022-39350Oct 25, 2022risk 0.00cvss —epss 0.01
@dependencytrack/frontend is a Single Page Application (SPA) used in Dependency-Track, an open source Component Analysis platform that allows organizations to identify and reduce risk in the software supply chain. Due to the common practice of providing vulnerability details in…
- CVE-2022-43425Oct 19, 2022risk 0.00cvss —epss 0.01
Jenkins Custom Checkbox Parameter Plugin 1.4 and earlier does not escape the name and description of Custom Checkbox Parameter parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure…
- CVE-2022-43420Oct 19, 2022risk 0.00cvss —epss 0.01
Jenkins Contrast Continuous Application Security Plugin 3.9 and earlier does not escape data returned from the Contrast service when generating a report, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control or modify Contrast…
- CVE-2022-43409Oct 19, 2022risk 0.00cvss —epss 0.01
Jenkins Pipeline: Supporting APIs Plugin 838.va_3a_087b_4055b and earlier does not sanitize or properly encode URLs of hyperlinks sending POST requests in build logs, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to create Pipelines.
- CVE-2022-42466Oct 19, 2022risk 0.00cvss —epss 0.01
Prior to 2.0.0-M9, it was possible for an end-user to set the value of an editable string property of a domain object to a value that would be rendered unchanged when the value was saved. In particular, the end-user could enter javascript or similar and this would be executed.…
- CVE-2022-3608Oct 19, 2022risk 0.00cvss —epss 0.01
Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.2.0-alpha.
- CVE-2022-31037Oct 18, 2022risk 0.00cvss —epss 0.00
OroCommerce is an open-source Business to Business Commerce application. Versions between 4.1.0 and 4.1.17 inclusive, 4.2.0 and 4.2.11 inclusive, and between 5.0.0 and 5.0.3 inclusive, are vulnerable to Cross-site Scripting in the UPS Surcharge field of the Shipping rule edit…