VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (23,312)

page 861 of 1,166
  • CVE-2022-3000Sep 20, 2022
    risk 0.00cvss epss 0.01

    Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0.

  • CVE-2022-2924Sep 20, 2022
    risk 0.00cvss epss 0.01

    Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.3.

  • CVE-2022-38545Sep 19, 2022
    risk 0.00cvss epss 0.33

    Valine v1.4.18 was discovered to contain a remote code execution (RCE) vulnerability which allows attackers to execute arbitrary code via a crafted POST request.

  • CVE-2022-25873Sep 18, 2022
    risk 0.00cvss epss 0.01

    The package vuetify from 2.0.0-beta.4 and before 2.6.10 are vulnerable to Cross-site Scripting (XSS) due to improper input sanitization in the 'eventName' function within the VCalendar component.

  • CVE-2022-3231Sep 17, 2022
    risk 0.00cvss epss 0.01

    Cross-site Scripting (XSS) - Stored in GitHub repository librenms/librenms prior to 22.9.0.

  • CVE-2022-37251Sep 16, 2022
    risk 0.00cvss epss 0.00

    Craft CMS 4.2.0.1 is vulnerable to Cross Site Scripting (XSS) via Drafts.

  • CVE-2022-37247Sep 16, 2022
    risk 0.00cvss epss 0.00

    Craft CMS 4.2.0.1 is vulnerable to stored a cross-site scripting (XSS) via /admin/settings/fields page.

  • CVE-2022-37248Sep 16, 2022
    risk 0.00cvss epss 0.01

    Craft CMS 4.2.0.1 is vulnerable to Cross Site Scripting (XSS) via src/helpers/Cp.php.

  • CVE-2022-37250Sep 16, 2022
    risk 0.00cvss epss 0.01

    Craft CMS 4.2.0.1 suffers from Stored Cross Site Scripting (XSS) in /admin/myaccount.

  • CVE-2022-3211Sep 15, 2022
    risk 0.00cvss epss 0.00

    Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.5.6.

  • CVE-2022-37724Sep 14, 2022
    risk 0.00cvss epss 0.01

    Project Wonder WebObjects 1.0 through 5.4.3 is vulnerable to Arbitrary HTTP Header injection and URL- or Header-based XSS reflection in all web-server adaptor interfaces.

  • CVE-2022-40365Sep 14, 2022
    risk 0.00cvss epss 0.00

    Cross site scripting (XSS) vulnerability in ouqiang gocron through 1.5.3, allows attackers to execute arbitrary code via scope.row.hostname in web/vue/src/pages/taskLog/list.vue.

  • CVE-2018-25047Sep 14, 2022
    risk 0.00cvss epss 0.01

    In Smarty before 3.1.47 and 4.x before 4.2.1, libs/plugins/function.mailto.php allows XSS. A web page that uses smarty_function_mailto, and that could be parameterized using GET or POST input parameters, could allow injection of JavaScript code by a user.

  • CVE-2021-36568Sep 13, 2022
    risk 0.00cvss epss 0.01

    In certain Moodle products after creating a course, it is possible to add in a arbitrary "Topic" a resource, in this case a "Database" with the type "Text" where its values "Field name" and "Field description" are vulnerable to Cross Site Scripting Stored(XSS). This affects…

  • CVE-2022-36107Sep 13, 2022
    risk 0.00cvss epss 0.01

    TYPO3 is an open source PHP based web content management system released under the GNU GPL. It has been discovered that the `FileDumpController` (backend and frontend context) is vulnerable to cross-site scripting when malicious files are displayed using this component. A valid…

  • CVE-2022-36108Sep 13, 2022
    risk 0.00cvss epss 0.01

    TYPO3 is an open source PHP based web content management system released under the GNU GPL. It has been discovered that the `f:asset.css` view helper is vulnerable to cross-site scripting when user input is passed as variables to the CSS. Update to TYPO3 version 10.4.32 or…

  • CVE-2022-36020Sep 13, 2022
    risk 0.00cvss epss 0.01

    The typo3/html-sanitizer package is an HTML sanitizer, written in PHP, aiming to provide XSS-safe markup based on explicitly allowed tags, attributes and values. Due to a parsing issue in the upstream package `masterminds/html5`, malicious markup used in a sequence with special…

  • CVE-2022-38639Sep 9, 2022
    risk 0.00cvss epss 0.00

    A cross-site scripting (XSS) vulnerability in Markdown-Nice v1.8.22 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Community Posting field.

  • CVE-2022-2925Sep 9, 2022
    risk 0.00cvss epss 0.01

    Cross-site Scripting (XSS) - Stored in GitHub repository appwrite/appwrite prior to 1.0.0-RC1.

  • CVE-2022-36098Sep 8, 2022
    risk 0.00cvss epss 0.71

    XWiki Platform Mentions UI is a user interface for mentioning users in wiki content for XWiki Platform, a generic wiki platform. Starting in version 12.5-rc-1 and prior to versions 13.10.6 and 14.4, it's possible to store Javascript or groovy scripts in a mention, macro anchor,…