VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (23,312)

page 864 of 1,166
  • CVE-2022-35144Aug 4, 2022
    risk 0.00cvss epss 0.01

    Renato v0.17.0 was discovered to contain a cross-site scripting (XSS) vulnerability.

  • CVE-2022-31175Aug 3, 2022
    risk 0.00cvss epss 0.01

    CKEditor 5 is a JavaScript rich text editor. A cross-site scripting vulnerability has been discovered affecting three optional CKEditor 5's packages in versions prior to 35.0.1. The vulnerability allowed to trigger a JavaScript code after fulfilling special conditions. The…

  • CVE-2022-31192Aug 1, 2022
    risk 0.00cvss epss 0.01

    DSpace open source software is a repository application which provides durable access to digital resources. dspace-jspui is a UI component for DSpace. The JSPUI "Request a Copy" feature does not properly escape values submitted and stored from the "Request a Copy" form. This…

  • CVE-2022-31191Aug 1, 2022
    risk 0.00cvss epss 0.01

    DSpace open source software is a repository application which provides durable access to digital resources. dspace-jspui is a UI component for DSpace. The JSPUI spellcheck "Did you mean" HTML escapes the data-spell attribute in the link, but not the actual displayed text.…

  • CVE-2022-31148Aug 1, 2022
    risk 0.00cvss epss 0.01

    Shopware is an open source e-commerce software. In versions from 5.7.0 a persistent cross site scripting (XSS) vulnerability exists in the customer module. Users are recommend to update to the current version 5.7.14. You can get the update to 5.7.14 regularly via the…

  • CVE-2022-31109Aug 1, 2022
    risk 0.00cvss epss 0.01

    laminas-diactoros is a PHP package containing implementations of the PSR-7 HTTP message interfaces and PSR-17 HTTP message factory interfaces. Applications that use Diactoros, and are either not behind a proxy, or can be accessed via untrusted proxies, can potentially have the…

  • CVE-2022-2589Aug 1, 2022
    risk 0.00cvss epss 0.01

    Cross-site Scripting (XSS) - Reflected in GitHub repository beancount/fava prior to 1.22.3.

  • CVE-2022-36922Jul 27, 2022
    risk 0.00cvss epss 0.01

    Jenkins Lucene-Search Plugin 370.v62a5f618cd3a and earlier does not escape the search query parameter displayed on the 'search' result page, resulting in a reflected cross-site scripting (XSS) vulnerability.

  • CVE-2022-36905Jul 27, 2022
    risk 0.00cvss epss 0.01

    Jenkins Maven Metadata Plugin for Jenkins CI server Plugin 2.2 and earlier does not perform URL validation for the Repository Base URL of List maven artifact versions parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with…

  • CVE-2022-35131Jul 25, 2022
    risk 0.00cvss epss 0.02

    Joplin v2.8.8 allows attackers to execute arbitrary commands via a crafted payload injected into the Node titles.

  • CVE-2022-35653Jul 25, 2022
    risk 0.00cvss epss 0.04

    A reflected XSS issue was identified in the LTI module of Moodle. The vulnerability exists due to insufficient sanitization of user-supplied data in the LTI module. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script…

  • CVE-2022-35651Jul 25, 2022
    risk 0.00cvss epss 0.01

    A stored XSS and blind SSRF vulnerability was found in Moodle, occurs due to insufficient sanitization of user-supplied data in the SCORM track details. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's…

  • CVE-2020-28455Jul 25, 2022
    risk 0.00cvss epss 0.01

    This affects all versions of package markdown-it-toc. The title of the generated toc and the contents of the header are not escaped.

  • CVE-2020-28459Jul 25, 2022
    risk 0.00cvss epss 0.01

    This affects all versions of package markdown-it-decorate. An attacker can add an event handler or use javascript:xxx for the link.

  • CVE-2022-21802Jul 25, 2022
    risk 0.00cvss epss 0.01

    The package grapesjs before 0.19.5 are vulnerable to Cross-site Scripting (XSS) due to an improper sanitization of the class name in Selector Manager.

  • CVE-2022-2523Jul 25, 2022
    risk 0.00cvss epss 0.01

    Cross-site Scripting (XSS) - Reflected in GitHub repository beancount/fava prior to 1.22.2.

  • CVE-2022-2514Jul 25, 2022
    risk 0.00cvss epss 0.01

    The time and filter parameters in Fava prior to v1.22 are vulnerable to reflected XSS due to the lack of escaping of error messages which contained the parameters in verbatim.

  • CVE-2018-25045Jul 23, 2022
    risk 0.00cvss epss 0.01

    Django REST framework (aka django-rest-framework) before 3.9.1 allows XSS because the default DRF Browsable API view templates disable autoescaping.

  • CVE-2022-2470Jul 22, 2022
    risk 0.00cvss epss 0.01

    Cross-site Scripting (XSS) - Reflected in GitHub repository microweber/microweber prior to 1.2.21.

  • CVE-2022-2495Jul 22, 2022
    risk 0.00cvss epss 0.01

    Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 1.2.21.