CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Description
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85
CVEs mapped to this weakness (23,312)
page 859 of 1,166| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-42112 | 0.00 | — | 0.00 | Oct 18, 2022 | A Cross-site scripting (XSS) vulnerability in the Portal Search module's Sort widget in Liferay Portal 7.2.0 through 7.4.3.24, and Liferay DXP 7.2 before fix pack 19, 7.3 before update 5, and DXP 7.4 before update 25 allows remote attackers to inject arbitrary web script or HTML… | |||
| CVE-2022-42113 | 0.00 | — | 0.01 | Oct 18, 2022 | A Cross-site scripting (XSS) vulnerability in Document Library module in Liferay Portal 7.4.3.30 through 7.4.3.36, and Liferay DXP 7.4 update 30 through update 36 allows remote attackers to inject arbitrary web script or HTML via the `redirect` parameter. | |||
| CVE-2022-42114 | 0.00 | — | 0.00 | Oct 18, 2022 | A Cross-site scripting (XSS) vulnerability in the Role module's edit role assignees page in Liferay Portal 7.4.0 through 7.4.3.36, and Liferay DXP 7.4 before update 37 allows remote attackers to inject arbitrary web script or HTML. | |||
| CVE-2022-42115 | 0.00 | — | 0.00 | Oct 18, 2022 | Cross-site scripting (XSS) vulnerability in the Object module's edit object details page in Liferay Portal 7.4.3.4 through 7.4.3.36 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into the object field's `Label` text field. | |||
| CVE-2022-42117 | 0.00 | — | 0.01 | Oct 18, 2022 | A Cross-site scripting (XSS) vulnerability in the Frontend Taglib module in Liferay Portal 7.3.2 through 7.4.3.16, and Liferay DXP 7.3 before update 6, and 7.4 before update 17 allows remote attackers to inject arbitrary web script or HTML. | |||
| CVE-2022-31037 | — | 0.00 | — | 0.00 | Oct 18, 2022 | OroCommerce is an open-source Business to Business Commerce application. Versions between 4.1.0 and 4.1.17 inclusive, 4.2.0 and 4.2.11 inclusive, and between 5.0.0 and 5.0.3 inclusive, are vulnerable to Cross-site Scripting in the UPS Surcharge field of the Shipping rule edit… | ||
| CVE-2022-35698 | 0.00 | — | 0.10 | Oct 14, 2022 | Adobe Commerce versions 2.4.4-p1 (and earlier) and 2.4.5 (and earlier) are affected by a Stored Cross-site Scripting vulnerability. Exploitation of this issue does not require user interaction and could result in a post-authentication arbitrary code execution. | |||
| CVE-2022-32174 | 0.00 | — | 0.58 | Oct 11, 2022 | In Gogs, versions v0.6.5 through v0.12.10 are vulnerable to Stored Cross-Site Scripting (XSS) that leads to an account takeover. | |||
| CVE-2022-41376 | — | 0.00 | — | 0.00 | Oct 11, 2022 | Metro UI v4.4.0 to v4.5.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the Javascript function. | ||
| CVE-2022-40440 | — | 0.00 | — | 0.01 | Oct 11, 2022 | mxGraph v4.2.2 was discovered to contain a cross-site scripting (XSS) vulnerability via the setTooltips() function. | ||
| CVE-2022-32171 | — | 0.00 | — | 0.01 | Oct 6, 2022 | In Zinc, versions v0.1.9 through v0.3.1 are vulnerable to Stored Cross-Site Scripting when using the delete user functionality. When an authenticated user deletes a user having a XSS payload in the user id field, the javascript payload will be executed and allow an attacker to… | ||
| CVE-2022-32172 | — | 0.00 | — | 0.01 | Oct 6, 2022 | In Zinc, versions v0.1.9 through v0.3.1 are vulnerable to Stored Cross-Site Scripting when using the delete template functionality. When an authenticated user deletes a template with a XSS payload in the name field, the Javascript payload will be executed and allow an attacker… | ||
| CVE-2022-3002 | 0.00 | — | 0.01 | Oct 6, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0. | |||
| CVE-2022-32173 | — | 0.00 | — | 0.01 | Oct 3, 2022 | In OrchardCore rc1-11259 to v1.2.2 vulnerable to HTML injection, allow an authenticated user with an editor security role to inject a persistent HTML modal dialog component into the dashboard that will affect admin users. | ||
| CVE-2022-40313 | — | 0.00 | — | 0.01 | Sep 30, 2022 | Recursive rendering of Mustache template helpers containing user input could, in some cases, result in an XSS risk or a page failing to load. | ||
| CVE-2022-40931 | — | 0.00 | — | 0.01 | Sep 29, 2022 | dutchcoders Transfer.sh 1.4.0 is vulnerable to Cross Site Scripting (XSS). | ||
| CVE-2022-40408 | — | 0.00 | — | 0.00 | Sep 29, 2022 | FeehiCMS v2.1.1 was discovered to contain a cross-site scripting (XSS) vulnerability via a crafted payload injected into the Comment box under the Single Page module. | ||
| CVE-2022-3355 | 0.00 | — | 0.01 | Sep 29, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository inventree/inventree prior to 0.8.3. | |||
| CVE-2022-38975 | 0.00 | — | 0.01 | Sep 27, 2022 | DOM-based cross-site scripting vulnerability in EC-CUBE 4 series (EC-CUBE 4.0.0 to 4.1.2) allows a remote attacker to inject an arbitrary script by having an administrative user of the product to visit a specially crafted page. | |||
| CVE-2022-40044 | 0.00 | — | 0.01 | Sep 26, 2022 | Centreon v20.10.18 was discovered to contain a cross-site scripting (XSS) vulnerability via the esc_name (Escalation Name) parameter at Configuration/Notifications/Escalations. This vulnerability allows attackers to execute arbitrary web scripts or HTML via injecting a crafted… |
- CVE-2022-42112Oct 18, 2022risk 0.00cvss —epss 0.00
A Cross-site scripting (XSS) vulnerability in the Portal Search module's Sort widget in Liferay Portal 7.2.0 through 7.4.3.24, and Liferay DXP 7.2 before fix pack 19, 7.3 before update 5, and DXP 7.4 before update 25 allows remote attackers to inject arbitrary web script or HTML…
- CVE-2022-42113Oct 18, 2022risk 0.00cvss —epss 0.01
A Cross-site scripting (XSS) vulnerability in Document Library module in Liferay Portal 7.4.3.30 through 7.4.3.36, and Liferay DXP 7.4 update 30 through update 36 allows remote attackers to inject arbitrary web script or HTML via the `redirect` parameter.
- CVE-2022-42114Oct 18, 2022risk 0.00cvss —epss 0.00
A Cross-site scripting (XSS) vulnerability in the Role module's edit role assignees page in Liferay Portal 7.4.0 through 7.4.3.36, and Liferay DXP 7.4 before update 37 allows remote attackers to inject arbitrary web script or HTML.
- CVE-2022-42115Oct 18, 2022risk 0.00cvss —epss 0.00
Cross-site scripting (XSS) vulnerability in the Object module's edit object details page in Liferay Portal 7.4.3.4 through 7.4.3.36 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into the object field's `Label` text field.
- CVE-2022-42117Oct 18, 2022risk 0.00cvss —epss 0.01
A Cross-site scripting (XSS) vulnerability in the Frontend Taglib module in Liferay Portal 7.3.2 through 7.4.3.16, and Liferay DXP 7.3 before update 6, and 7.4 before update 17 allows remote attackers to inject arbitrary web script or HTML.
- CVE-2022-31037Oct 18, 2022risk 0.00cvss —epss 0.00
OroCommerce is an open-source Business to Business Commerce application. Versions between 4.1.0 and 4.1.17 inclusive, 4.2.0 and 4.2.11 inclusive, and between 5.0.0 and 5.0.3 inclusive, are vulnerable to Cross-site Scripting in the UPS Surcharge field of the Shipping rule edit…
- CVE-2022-35698Oct 14, 2022risk 0.00cvss —epss 0.10
Adobe Commerce versions 2.4.4-p1 (and earlier) and 2.4.5 (and earlier) are affected by a Stored Cross-site Scripting vulnerability. Exploitation of this issue does not require user interaction and could result in a post-authentication arbitrary code execution.
- CVE-2022-32174Oct 11, 2022risk 0.00cvss —epss 0.58
In Gogs, versions v0.6.5 through v0.12.10 are vulnerable to Stored Cross-Site Scripting (XSS) that leads to an account takeover.
- CVE-2022-41376Oct 11, 2022risk 0.00cvss —epss 0.00
Metro UI v4.4.0 to v4.5.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the Javascript function.
- CVE-2022-40440Oct 11, 2022risk 0.00cvss —epss 0.01
mxGraph v4.2.2 was discovered to contain a cross-site scripting (XSS) vulnerability via the setTooltips() function.
- CVE-2022-32171Oct 6, 2022risk 0.00cvss —epss 0.01
In Zinc, versions v0.1.9 through v0.3.1 are vulnerable to Stored Cross-Site Scripting when using the delete user functionality. When an authenticated user deletes a user having a XSS payload in the user id field, the javascript payload will be executed and allow an attacker to…
- CVE-2022-32172Oct 6, 2022risk 0.00cvss —epss 0.01
In Zinc, versions v0.1.9 through v0.3.1 are vulnerable to Stored Cross-Site Scripting when using the delete template functionality. When an authenticated user deletes a template with a XSS payload in the name field, the Javascript payload will be executed and allow an attacker…
- CVE-2022-3002Oct 6, 2022risk 0.00cvss —epss 0.01
Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0.
- CVE-2022-32173Oct 3, 2022risk 0.00cvss —epss 0.01
In OrchardCore rc1-11259 to v1.2.2 vulnerable to HTML injection, allow an authenticated user with an editor security role to inject a persistent HTML modal dialog component into the dashboard that will affect admin users.
- CVE-2022-40313Sep 30, 2022risk 0.00cvss —epss 0.01
Recursive rendering of Mustache template helpers containing user input could, in some cases, result in an XSS risk or a page failing to load.
- CVE-2022-40931Sep 29, 2022risk 0.00cvss —epss 0.01
dutchcoders Transfer.sh 1.4.0 is vulnerable to Cross Site Scripting (XSS).
- CVE-2022-40408Sep 29, 2022risk 0.00cvss —epss 0.00
FeehiCMS v2.1.1 was discovered to contain a cross-site scripting (XSS) vulnerability via a crafted payload injected into the Comment box under the Single Page module.
- CVE-2022-3355Sep 29, 2022risk 0.00cvss —epss 0.01
Cross-site Scripting (XSS) - Stored in GitHub repository inventree/inventree prior to 0.8.3.
- CVE-2022-38975Sep 27, 2022risk 0.00cvss —epss 0.01
DOM-based cross-site scripting vulnerability in EC-CUBE 4 series (EC-CUBE 4.0.0 to 4.1.2) allows a remote attacker to inject an arbitrary script by having an administrative user of the product to visit a specially crafted page.
- CVE-2022-40044Sep 26, 2022risk 0.00cvss —epss 0.01
Centreon v20.10.18 was discovered to contain a cross-site scripting (XSS) vulnerability via the esc_name (Escalation Name) parameter at Configuration/Notifications/Escalations. This vulnerability allows attackers to execute arbitrary web scripts or HTML via injecting a crafted…