CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Description
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85
CVEs mapped to this weakness (23,312)
page 864 of 1,166| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-35144 | — | 0.00 | — | 0.01 | Aug 4, 2022 | Renato v0.17.0 was discovered to contain a cross-site scripting (XSS) vulnerability. | ||
| CVE-2022-31175 | 0.00 | — | 0.01 | Aug 3, 2022 | CKEditor 5 is a JavaScript rich text editor. A cross-site scripting vulnerability has been discovered affecting three optional CKEditor 5's packages in versions prior to 35.0.1. The vulnerability allowed to trigger a JavaScript code after fulfilling special conditions. The… | |||
| CVE-2022-31192 | 0.00 | — | 0.01 | Aug 1, 2022 | DSpace open source software is a repository application which provides durable access to digital resources. dspace-jspui is a UI component for DSpace. The JSPUI "Request a Copy" feature does not properly escape values submitted and stored from the "Request a Copy" form. This… | |||
| CVE-2022-31191 | 0.00 | — | 0.01 | Aug 1, 2022 | DSpace open source software is a repository application which provides durable access to digital resources. dspace-jspui is a UI component for DSpace. The JSPUI spellcheck "Did you mean" HTML escapes the data-spell attribute in the link, but not the actual displayed text.… | |||
| CVE-2022-31148 | 0.00 | — | 0.01 | Aug 1, 2022 | Shopware is an open source e-commerce software. In versions from 5.7.0 a persistent cross site scripting (XSS) vulnerability exists in the customer module. Users are recommend to update to the current version 5.7.14. You can get the update to 5.7.14 regularly via the… | |||
| CVE-2022-31109 | — | 0.00 | — | 0.01 | Aug 1, 2022 | laminas-diactoros is a PHP package containing implementations of the PSR-7 HTTP message interfaces and PSR-17 HTTP message factory interfaces. Applications that use Diactoros, and are either not behind a proxy, or can be accessed via untrusted proxies, can potentially have the… | ||
| CVE-2022-2589 | — | 0.00 | — | 0.01 | Aug 1, 2022 | Cross-site Scripting (XSS) - Reflected in GitHub repository beancount/fava prior to 1.22.3. | ||
| CVE-2022-36922 | 0.00 | — | 0.01 | Jul 27, 2022 | Jenkins Lucene-Search Plugin 370.v62a5f618cd3a and earlier does not escape the search query parameter displayed on the 'search' result page, resulting in a reflected cross-site scripting (XSS) vulnerability. | |||
| CVE-2022-36905 | — | 0.00 | — | 0.01 | Jul 27, 2022 | Jenkins Maven Metadata Plugin for Jenkins CI server Plugin 2.2 and earlier does not perform URL validation for the Repository Base URL of List maven artifact versions parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with… | ||
| CVE-2022-35131 | 0.00 | — | 0.02 | Jul 25, 2022 | Joplin v2.8.8 allows attackers to execute arbitrary commands via a crafted payload injected into the Node titles. | |||
| CVE-2022-35653 | — | 0.00 | — | 0.04 | Jul 25, 2022 | A reflected XSS issue was identified in the LTI module of Moodle. The vulnerability exists due to insufficient sanitization of user-supplied data in the LTI module. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script… | ||
| CVE-2022-35651 | 0.00 | — | 0.01 | Jul 25, 2022 | A stored XSS and blind SSRF vulnerability was found in Moodle, occurs due to insufficient sanitization of user-supplied data in the SCORM track details. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's… | |||
| CVE-2020-28455 | 0.00 | — | 0.01 | Jul 25, 2022 | This affects all versions of package markdown-it-toc. The title of the generated toc and the contents of the header are not escaped. | |||
| CVE-2020-28459 | — | 0.00 | — | 0.01 | Jul 25, 2022 | This affects all versions of package markdown-it-decorate. An attacker can add an event handler or use javascript:xxx for the link. | ||
| CVE-2022-21802 | 0.00 | — | 0.01 | Jul 25, 2022 | The package grapesjs before 0.19.5 are vulnerable to Cross-site Scripting (XSS) due to an improper sanitization of the class name in Selector Manager. | |||
| CVE-2022-2523 | — | 0.00 | — | 0.01 | Jul 25, 2022 | Cross-site Scripting (XSS) - Reflected in GitHub repository beancount/fava prior to 1.22.2. | ||
| CVE-2022-2514 | 0.00 | — | 0.01 | Jul 25, 2022 | The time and filter parameters in Fava prior to v1.22 are vulnerable to reflected XSS due to the lack of escaping of error messages which contained the parameters in verbatim. | |||
| CVE-2018-25045 | — | 0.00 | — | 0.01 | Jul 23, 2022 | Django REST framework (aka django-rest-framework) before 3.9.1 allows XSS because the default DRF Browsable API view templates disable autoescaping. | ||
| CVE-2022-2470 | 0.00 | — | 0.01 | Jul 22, 2022 | Cross-site Scripting (XSS) - Reflected in GitHub repository microweber/microweber prior to 1.2.21. | |||
| CVE-2022-2495 | 0.00 | — | 0.01 | Jul 22, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 1.2.21. |
- CVE-2022-35144Aug 4, 2022risk 0.00cvss —epss 0.01
Renato v0.17.0 was discovered to contain a cross-site scripting (XSS) vulnerability.
- CVE-2022-31175Aug 3, 2022risk 0.00cvss —epss 0.01
CKEditor 5 is a JavaScript rich text editor. A cross-site scripting vulnerability has been discovered affecting three optional CKEditor 5's packages in versions prior to 35.0.1. The vulnerability allowed to trigger a JavaScript code after fulfilling special conditions. The…
- CVE-2022-31192Aug 1, 2022risk 0.00cvss —epss 0.01
DSpace open source software is a repository application which provides durable access to digital resources. dspace-jspui is a UI component for DSpace. The JSPUI "Request a Copy" feature does not properly escape values submitted and stored from the "Request a Copy" form. This…
- CVE-2022-31191Aug 1, 2022risk 0.00cvss —epss 0.01
DSpace open source software is a repository application which provides durable access to digital resources. dspace-jspui is a UI component for DSpace. The JSPUI spellcheck "Did you mean" HTML escapes the data-spell attribute in the link, but not the actual displayed text.…
- CVE-2022-31148Aug 1, 2022risk 0.00cvss —epss 0.01
Shopware is an open source e-commerce software. In versions from 5.7.0 a persistent cross site scripting (XSS) vulnerability exists in the customer module. Users are recommend to update to the current version 5.7.14. You can get the update to 5.7.14 regularly via the…
- CVE-2022-31109Aug 1, 2022risk 0.00cvss —epss 0.01
laminas-diactoros is a PHP package containing implementations of the PSR-7 HTTP message interfaces and PSR-17 HTTP message factory interfaces. Applications that use Diactoros, and are either not behind a proxy, or can be accessed via untrusted proxies, can potentially have the…
- CVE-2022-2589Aug 1, 2022risk 0.00cvss —epss 0.01
Cross-site Scripting (XSS) - Reflected in GitHub repository beancount/fava prior to 1.22.3.
- CVE-2022-36922Jul 27, 2022risk 0.00cvss —epss 0.01
Jenkins Lucene-Search Plugin 370.v62a5f618cd3a and earlier does not escape the search query parameter displayed on the 'search' result page, resulting in a reflected cross-site scripting (XSS) vulnerability.
- CVE-2022-36905Jul 27, 2022risk 0.00cvss —epss 0.01
Jenkins Maven Metadata Plugin for Jenkins CI server Plugin 2.2 and earlier does not perform URL validation for the Repository Base URL of List maven artifact versions parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with…
- CVE-2022-35131Jul 25, 2022risk 0.00cvss —epss 0.02
Joplin v2.8.8 allows attackers to execute arbitrary commands via a crafted payload injected into the Node titles.
- CVE-2022-35653Jul 25, 2022risk 0.00cvss —epss 0.04
A reflected XSS issue was identified in the LTI module of Moodle. The vulnerability exists due to insufficient sanitization of user-supplied data in the LTI module. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script…
- CVE-2022-35651Jul 25, 2022risk 0.00cvss —epss 0.01
A stored XSS and blind SSRF vulnerability was found in Moodle, occurs due to insufficient sanitization of user-supplied data in the SCORM track details. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's…
- CVE-2020-28455Jul 25, 2022risk 0.00cvss —epss 0.01
This affects all versions of package markdown-it-toc. The title of the generated toc and the contents of the header are not escaped.
- CVE-2020-28459Jul 25, 2022risk 0.00cvss —epss 0.01
This affects all versions of package markdown-it-decorate. An attacker can add an event handler or use javascript:xxx for the link.
- CVE-2022-21802Jul 25, 2022risk 0.00cvss —epss 0.01
The package grapesjs before 0.19.5 are vulnerable to Cross-site Scripting (XSS) due to an improper sanitization of the class name in Selector Manager.
- CVE-2022-2523Jul 25, 2022risk 0.00cvss —epss 0.01
Cross-site Scripting (XSS) - Reflected in GitHub repository beancount/fava prior to 1.22.2.
- CVE-2022-2514Jul 25, 2022risk 0.00cvss —epss 0.01
The time and filter parameters in Fava prior to v1.22 are vulnerable to reflected XSS due to the lack of escaping of error messages which contained the parameters in verbatim.
- CVE-2018-25045Jul 23, 2022risk 0.00cvss —epss 0.01
Django REST framework (aka django-rest-framework) before 3.9.1 allows XSS because the default DRF Browsable API view templates disable autoescaping.
- CVE-2022-2470Jul 22, 2022risk 0.00cvss —epss 0.01
Cross-site Scripting (XSS) - Reflected in GitHub repository microweber/microweber prior to 1.2.21.
- CVE-2022-2495Jul 22, 2022risk 0.00cvss —epss 0.01
Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 1.2.21.