CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Description
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85
CVEs mapped to this weakness (23,312)
page 861 of 1,166| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-3000 | 0.00 | — | 0.01 | Sep 20, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0. | |||
| CVE-2022-2924 | 0.00 | — | 0.01 | Sep 20, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.3. | |||
| CVE-2022-38545 | — | 0.00 | — | 0.33 | Sep 19, 2022 | Valine v1.4.18 was discovered to contain a remote code execution (RCE) vulnerability which allows attackers to execute arbitrary code via a crafted POST request. | ||
| CVE-2022-25873 | — | 0.00 | — | 0.01 | Sep 18, 2022 | The package vuetify from 2.0.0-beta.4 and before 2.6.10 are vulnerable to Cross-site Scripting (XSS) due to improper input sanitization in the 'eventName' function within the VCalendar component. | ||
| CVE-2022-3231 | 0.00 | — | 0.01 | Sep 17, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository librenms/librenms prior to 22.9.0. | |||
| CVE-2022-37251 | 0.00 | — | 0.00 | Sep 16, 2022 | Craft CMS 4.2.0.1 is vulnerable to Cross Site Scripting (XSS) via Drafts. | |||
| CVE-2022-37247 | 0.00 | — | 0.00 | Sep 16, 2022 | Craft CMS 4.2.0.1 is vulnerable to stored a cross-site scripting (XSS) via /admin/settings/fields page. | |||
| CVE-2022-37248 | 0.00 | — | 0.01 | Sep 16, 2022 | Craft CMS 4.2.0.1 is vulnerable to Cross Site Scripting (XSS) via src/helpers/Cp.php. | |||
| CVE-2022-37250 | 0.00 | — | 0.01 | Sep 16, 2022 | Craft CMS 4.2.0.1 suffers from Stored Cross Site Scripting (XSS) in /admin/myaccount. | |||
| CVE-2022-3211 | 0.00 | — | 0.00 | Sep 15, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.5.6. | |||
| CVE-2022-37724 | — | 0.00 | — | 0.01 | Sep 14, 2022 | Project Wonder WebObjects 1.0 through 5.4.3 is vulnerable to Arbitrary HTTP Header injection and URL- or Header-based XSS reflection in all web-server adaptor interfaces. | ||
| CVE-2022-40365 | — | 0.00 | — | 0.00 | Sep 14, 2022 | Cross site scripting (XSS) vulnerability in ouqiang gocron through 1.5.3, allows attackers to execute arbitrary code via scope.row.hostname in web/vue/src/pages/taskLog/list.vue. | ||
| CVE-2018-25047 | 0.00 | — | 0.01 | Sep 14, 2022 | In Smarty before 3.1.47 and 4.x before 4.2.1, libs/plugins/function.mailto.php allows XSS. A web page that uses smarty_function_mailto, and that could be parameterized using GET or POST input parameters, could allow injection of JavaScript code by a user. | |||
| CVE-2021-36568 | 0.00 | — | 0.01 | Sep 13, 2022 | In certain Moodle products after creating a course, it is possible to add in a arbitrary "Topic" a resource, in this case a "Database" with the type "Text" where its values "Field name" and "Field description" are vulnerable to Cross Site Scripting Stored(XSS). This affects… | |||
| CVE-2022-36107 | 0.00 | — | 0.01 | Sep 13, 2022 | TYPO3 is an open source PHP based web content management system released under the GNU GPL. It has been discovered that the `FileDumpController` (backend and frontend context) is vulnerable to cross-site scripting when malicious files are displayed using this component. A valid… | |||
| CVE-2022-36108 | 0.00 | — | 0.01 | Sep 13, 2022 | TYPO3 is an open source PHP based web content management system released under the GNU GPL. It has been discovered that the `f:asset.css` view helper is vulnerable to cross-site scripting when user input is passed as variables to the CSS. Update to TYPO3 version 10.4.32 or… | |||
| CVE-2022-36020 | — | 0.00 | — | 0.01 | Sep 13, 2022 | The typo3/html-sanitizer package is an HTML sanitizer, written in PHP, aiming to provide XSS-safe markup based on explicitly allowed tags, attributes and values. Due to a parsing issue in the upstream package `masterminds/html5`, malicious markup used in a sequence with special… | ||
| CVE-2022-38639 | — | 0.00 | — | 0.00 | Sep 9, 2022 | A cross-site scripting (XSS) vulnerability in Markdown-Nice v1.8.22 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Community Posting field. | ||
| CVE-2022-2925 | 0.00 | — | 0.01 | Sep 9, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository appwrite/appwrite prior to 1.0.0-RC1. | |||
| CVE-2022-36098 | 0.00 | — | 0.71 | Sep 8, 2022 | XWiki Platform Mentions UI is a user interface for mentioning users in wiki content for XWiki Platform, a generic wiki platform. Starting in version 12.5-rc-1 and prior to versions 13.10.6 and 14.4, it's possible to store Javascript or groovy scripts in a mention, macro anchor,… |
- CVE-2022-3000Sep 20, 2022risk 0.00cvss —epss 0.01
Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0.
- CVE-2022-2924Sep 20, 2022risk 0.00cvss —epss 0.01
Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.3.
- CVE-2022-38545Sep 19, 2022risk 0.00cvss —epss 0.33
Valine v1.4.18 was discovered to contain a remote code execution (RCE) vulnerability which allows attackers to execute arbitrary code via a crafted POST request.
- CVE-2022-25873Sep 18, 2022risk 0.00cvss —epss 0.01
The package vuetify from 2.0.0-beta.4 and before 2.6.10 are vulnerable to Cross-site Scripting (XSS) due to improper input sanitization in the 'eventName' function within the VCalendar component.
- CVE-2022-3231Sep 17, 2022risk 0.00cvss —epss 0.01
Cross-site Scripting (XSS) - Stored in GitHub repository librenms/librenms prior to 22.9.0.
- CVE-2022-37251Sep 16, 2022risk 0.00cvss —epss 0.00
Craft CMS 4.2.0.1 is vulnerable to Cross Site Scripting (XSS) via Drafts.
- CVE-2022-37247Sep 16, 2022risk 0.00cvss —epss 0.00
Craft CMS 4.2.0.1 is vulnerable to stored a cross-site scripting (XSS) via /admin/settings/fields page.
- CVE-2022-37248Sep 16, 2022risk 0.00cvss —epss 0.01
Craft CMS 4.2.0.1 is vulnerable to Cross Site Scripting (XSS) via src/helpers/Cp.php.
- CVE-2022-37250Sep 16, 2022risk 0.00cvss —epss 0.01
Craft CMS 4.2.0.1 suffers from Stored Cross Site Scripting (XSS) in /admin/myaccount.
- CVE-2022-3211Sep 15, 2022risk 0.00cvss —epss 0.00
Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.5.6.
- CVE-2022-37724Sep 14, 2022risk 0.00cvss —epss 0.01
Project Wonder WebObjects 1.0 through 5.4.3 is vulnerable to Arbitrary HTTP Header injection and URL- or Header-based XSS reflection in all web-server adaptor interfaces.
- CVE-2022-40365Sep 14, 2022risk 0.00cvss —epss 0.00
Cross site scripting (XSS) vulnerability in ouqiang gocron through 1.5.3, allows attackers to execute arbitrary code via scope.row.hostname in web/vue/src/pages/taskLog/list.vue.
- CVE-2018-25047Sep 14, 2022risk 0.00cvss —epss 0.01
In Smarty before 3.1.47 and 4.x before 4.2.1, libs/plugins/function.mailto.php allows XSS. A web page that uses smarty_function_mailto, and that could be parameterized using GET or POST input parameters, could allow injection of JavaScript code by a user.
- CVE-2021-36568Sep 13, 2022risk 0.00cvss —epss 0.01
In certain Moodle products after creating a course, it is possible to add in a arbitrary "Topic" a resource, in this case a "Database" with the type "Text" where its values "Field name" and "Field description" are vulnerable to Cross Site Scripting Stored(XSS). This affects…
- CVE-2022-36107Sep 13, 2022risk 0.00cvss —epss 0.01
TYPO3 is an open source PHP based web content management system released under the GNU GPL. It has been discovered that the `FileDumpController` (backend and frontend context) is vulnerable to cross-site scripting when malicious files are displayed using this component. A valid…
- CVE-2022-36108Sep 13, 2022risk 0.00cvss —epss 0.01
TYPO3 is an open source PHP based web content management system released under the GNU GPL. It has been discovered that the `f:asset.css` view helper is vulnerable to cross-site scripting when user input is passed as variables to the CSS. Update to TYPO3 version 10.4.32 or…
- CVE-2022-36020Sep 13, 2022risk 0.00cvss —epss 0.01
The typo3/html-sanitizer package is an HTML sanitizer, written in PHP, aiming to provide XSS-safe markup based on explicitly allowed tags, attributes and values. Due to a parsing issue in the upstream package `masterminds/html5`, malicious markup used in a sequence with special…
- CVE-2022-38639Sep 9, 2022risk 0.00cvss —epss 0.00
A cross-site scripting (XSS) vulnerability in Markdown-Nice v1.8.22 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Community Posting field.
- CVE-2022-2925Sep 9, 2022risk 0.00cvss —epss 0.01
Cross-site Scripting (XSS) - Stored in GitHub repository appwrite/appwrite prior to 1.0.0-RC1.
- CVE-2022-36098Sep 8, 2022risk 0.00cvss —epss 0.71
XWiki Platform Mentions UI is a user interface for mentioning users in wiki content for XWiki Platform, a generic wiki platform. Starting in version 12.5-rc-1 and prior to versions 13.10.6 and 14.4, it's possible to store Javascript or groovy scripts in a mention, macro anchor,…