VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (46,607)

page 86 of 2,331
  • CVE-2023-38164HigSep 12, 2023
    risk 0.49cvss 7.6epss 0.01

    Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability

  • CVE-2023-36886HigSep 12, 2023
    risk 0.49cvss 7.6epss 0.01

    Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability

  • CVE-2023-36800HigSep 12, 2023
    risk 0.49cvss 7.6epss 0.01

    Dynamics Finance and Operations Cross-site Scripting Vulnerability

  • CVE-2023-40577HigAug 25, 2023
    risk 0.49cvss 7.5epss 0.01

    Alertmanager handles alerts sent by client applications such as the Prometheus server. An attacker with the permission to perform POST requests on the /api/v1/alerts endpoint could be able to execute arbitrary JavaScript code on the users of Prometheus Alertmanager. This issue…

  • CVE-2023-39437HigAug 8, 2023
    risk 0.49cvss 7.6epss 0.00

    SAP business One allows - version 10.0, allows an attacker to insert malicious code into the content of a web page or application and gets it delivered to the client, resulting to Cross-site scripting. This could lead to harmful action affecting the Confidentiality, Integrity…

  • CVE-2023-38138HigAug 2, 2023
    risk 0.49cvss 7.5epss 0.00

    A reflected cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility which allows an attacker to run JavaScript in the context of the currently logged-in user.  Note: Software versions which have reached End of Technical…

  • CVE-2021-37386HigJul 17, 2023
    risk 0.49cvss 7.5epss 0.01

    Furukawa Electric LatAm 423-41W/AC before v1.1.4 and LD421-21W before v1.3.3 were discovered to contain an HTML injection vulnerability via the serial number update function.

  • CVE-2023-28598HigJun 13, 2023
    risk 0.49cvss 7.5epss 0.01

    Zoom for Linux clients prior to 5.13.10 contain an HTML injection vulnerability. If a victim starts a chat with a malicious user it could result in a Zoom application crash.

  • CVE-2023-21516HigMay 26, 2023
    risk 0.49cvss 7.5epss 0.01

    XSS vulnerability from InstantPlay in Galaxy Store prior to version 4.5.49.8 allows attackers to execute javascript API to install APK from Galaxy Store.

  • CVE-2023-30469HigMay 23, 2023
    risk 0.49cvss 7.6epss 0.00

    Cross-site Scripting vulnerability in Hitachi Ops Center Analyzer (Hitachi Ops Center Analyzer detail view component) allows Reflected XSS.This issue affects Hitachi Ops Center Analyzer: from 10.9.1-00 before 10.9.2-00.

  • CVE-2023-2587HigMay 22, 2023
    risk 0.49cvss 7.5epss 0.01

    Teltonika’s Remote Management System versions prior to 4.10.0 contain a cross-site scripting (XSS) vulnerability in the main page of the web interface. An attacker with the MAC address and serial number of a connected device could send a maliciously crafted JSON file with an…

  • CVE-2023-30868HigMay 18, 2023
    risk 0.49cvss 7.1epss 0.04

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Jon Christopher CMS Tree Page View plugin <= 1.6.7 versions.

  • CVE-2023-30777HigMay 10, 2023
    risk 0.49cvss 7.1epss 0.39

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WP Engine Advanced Custom Fields Pro, WP Engine Advanced Custom Fields plugins <= 6.1.5 versions.

  • CVE-2023-27378HigMay 3, 2023
    risk 0.49cvss 7.5epss 0.00

    Multiple reflected cross-site scripting (XSS) vulnerabilities exist in undisclosed pages of the BIG-IP Configuration utility which allow an attacker to run JavaScript in the context of the currently logged-in user.  Note: Software versions which have reached End of Technical…

  • CVE-2023-22921HigMay 1, 2023
    risk 0.49cvss 7.5epss 0.01

    A cross-site scripting (XSS) vulnerability in the Zyxel NBG-418N v2 firmware versions prior to V1.00(AARP.14)C0 could allow a remote authenticated attacker with administrator privileges to store malicious scripts using a web management interface parameter, resulting in…

  • CVE-2022-43376HigApr 18, 2023
    risk 0.49cvss 7.6epss 0.00

    A CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists that could cause code and session manipulation when malicious code is inserted into the browser. Affected Products: NetBotz 4 - 355/450/455/550/570 (V4.7.0 …

  • CVE-2023-28309HigApr 11, 2023
    risk 0.49cvss 7.6epss 0.01

    Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability

  • CVE-2023-28648HigMar 28, 2023
    risk 0.49cvss 7.5epss 0.01

    Osprey Pump Controller version 1.01 inputs passed to a GET parameter are not properly sanitized before being returned to the user. This can be exploited to execute arbitrary HTML/JS code in a user's browser session in context of an affected site.

  • CVE-2022-40676HigMar 7, 2023
    risk 0.49cvss 7.5epss 0.01

    A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiNAC versions 9.4.0, 9.2.0 through 9.2.5, 9.1.0 through 9.1.8, 8.8.0 through 8.8.11, 8.7.0 through 8.7.6, 8.6.0 through 8.6.5, 8.5.0 through 8.5.4, 8.3.7 allows attacker to…

  • CVE-2023-0507HigMar 1, 2023
    risk 0.49cvss 7.3epss 0.15

    Grafana is an open-source platform for monitoring and observability. Starting with the 8.1 branch, Grafana had a stored XSS vulnerability affecting the core plugin GeoMap. The stored XSS vulnerability was possible due to map attributions weren't properly sanitized and…