CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Description
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85
CVEs mapped to this weakness (23,312)
page 865 of 1,166| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-31160 | 0.00 | — | 0.02 | Jul 20, 2022 | jQuery UI is a curated set of user interface interactions, effects, widgets, and themes built on top of jQuery. Versions prior to 1.13.2 are potentially vulnerable to cross-site scripting. Initializing a checkboxradio widget on an input enclosed within a label makes that parent… | |||
| CVE-2022-25869 | 0.00 | — | 0.05 | Jul 15, 2022 | All versions of the package angular; all versions of the package angularjs.core; all versions of the package angularjs are vulnerable to Cross-site Scripting (XSS) due to insecure page caching in the Internet Explorer browser, which allows interpolation of elements. | |||
| CVE-2020-35305 | — | 0.00 | — | 0.01 | Jul 15, 2022 | Cross site scripting (XSS) in gollum 5.0 to 5.1.2 via the filename parameter to the 'New Page' dialog. | ||
| CVE-2022-32065 | 0.00 | — | 0.01 | Jul 13, 2022 | An arbitrary file upload vulnerability in the background management module of RuoYi v4.7.3 and below allows attackers to execute arbitrary code via a crafted HTML file. | |||
| CVE-2022-32114 | 0.00 | — | 0.02 | Jul 13, 2022 | An unrestricted file upload vulnerability in the Add New Assets function of Strapi 4.1.12 allows attackers to conduct XSS attacks via a crafted PDF file. NOTE: the project documentation suggests that a user with the Media Library "Create (upload)" permission is supposed to be… | |||
| CVE-2022-33156 | — | 0.00 | — | 0.01 | Jul 12, 2022 | The matomo_integration (aka Matomo Integration) extension before 1.3.2 for TYPO3 allows XSS. | ||
| CVE-2022-33157 | — | 0.00 | — | 0.01 | Jul 12, 2022 | The libconnect extension before 7.0.8 and 8.x before 8.1.0 for TYPO3 allows XSS. | ||
| CVE-2022-31102 | 0.00 | — | 0.01 | Jul 12, 2022 | Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Argo CD starting with 2.3.0 and prior to 2.3.6 and 2.4.5 is vulnerable to a cross-site scripting (XSS) bug which could allow an attacker to inject arbitrary JavaScript in the `/auth/callback` page in a… | |||
| CVE-2022-33155 | — | 0.00 | — | 0.00 | Jul 12, 2022 | The ameos_tarteaucitron (aka AMEOS - TarteAuCitron GDPR cookie banner and tracking management / French RGPD compatible) extension before 1.2.23 for TYPO3 allows XSS. | ||
| CVE-2022-33154 | — | 0.00 | — | 0.00 | Jul 12, 2022 | The schema (aka Embedding schema.org vocabulary) extension before 1.13.1 and 2.x before 2.5.1 for TYPO3 allows XSS. | ||
| CVE-2022-25875 | 0.00 | — | 0.01 | Jul 12, 2022 | The package svelte before 3.49.0 are vulnerable to Cross-site Scripting (XSS) due to improper input sanitization and to improper escape of attributes when using objects during SSR (Server-Side Rendering). Exploiting this vulnerability is possible via objects with a custom… | |||
| CVE-2022-25303 | — | 0.00 | — | 0.01 | Jul 12, 2022 | The package whoogle-search before 0.7.2 are vulnerable to Cross-site Scripting (XSS) via the query string parameter q. In the case where it does not contain the http string, it is used to build the error_message that is then rendered in the error.html template, using the… | ||
| CVE-2022-2353 | 0.00 | — | 0.00 | Jul 9, 2022 | Prior to microweber/microweber v1.2.20, due to improper neutralization of input, an attacker can steal tokens to perform cross-site request forgery, fetch contents from same-site and redirect a user. | |||
| CVE-2022-32115 | 0.00 | — | 0.01 | Jul 8, 2022 | An issue in the isSVG() function of Known v1.2.2+2020061101 allows attackers to execute arbitrary code via a crafted SVG file. | |||
| CVE-2022-31290 | 0.00 | — | 0.01 | Jul 8, 2022 | A cross-site scripting (XSS) vulnerability in Known v1.2.2+2020061101 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Your Name text field. | |||
| CVE-2022-32061 | — | 0.00 | — | 0.01 | Jul 7, 2022 | An arbitrary file upload vulnerability in the Select User function under the People Menu component of Snipe-IT v6.0.2 allows attackers to execute arbitrary code via a crafted file. | ||
| CVE-2021-44791 | — | 0.00 | — | 0.02 | Jul 7, 2022 | In Apache Druid 0.22.1 and earlier, certain specially-crafted links result in unescaped URL parameters being sent back in HTML responses. This makes it possible to execute reflected XSS attacks. | ||
| CVE-2022-32060 | — | 0.00 | — | 0.01 | Jul 7, 2022 | An arbitrary file upload vulnerability in the Update Branding Settings component of Snipe-IT v6.0.2 allows attackers to execute arbitrary code via a crafted file. | ||
| CVE-2022-31127 | 0.00 | — | 0.01 | Jul 6, 2022 | NextAuth.js is a complete open source authentication solution for Next.js applications. An attacker can pass a compromised input to the e-mail [signin endpoint](https://next-auth.js.org/getting-started/rest-api#post-apiauthsigninprovider) that contains some malicious HTML,… | |||
| CVE-2022-2300 | 0.00 | — | 0.00 | Jul 4, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 1.2.19. |
- CVE-2022-31160Jul 20, 2022risk 0.00cvss —epss 0.02
jQuery UI is a curated set of user interface interactions, effects, widgets, and themes built on top of jQuery. Versions prior to 1.13.2 are potentially vulnerable to cross-site scripting. Initializing a checkboxradio widget on an input enclosed within a label makes that parent…
- CVE-2022-25869Jul 15, 2022risk 0.00cvss —epss 0.05
All versions of the package angular; all versions of the package angularjs.core; all versions of the package angularjs are vulnerable to Cross-site Scripting (XSS) due to insecure page caching in the Internet Explorer browser, which allows interpolation of elements.
- CVE-2020-35305Jul 15, 2022risk 0.00cvss —epss 0.01
Cross site scripting (XSS) in gollum 5.0 to 5.1.2 via the filename parameter to the 'New Page' dialog.
- CVE-2022-32065Jul 13, 2022risk 0.00cvss —epss 0.01
An arbitrary file upload vulnerability in the background management module of RuoYi v4.7.3 and below allows attackers to execute arbitrary code via a crafted HTML file.
- CVE-2022-32114Jul 13, 2022risk 0.00cvss —epss 0.02
An unrestricted file upload vulnerability in the Add New Assets function of Strapi 4.1.12 allows attackers to conduct XSS attacks via a crafted PDF file. NOTE: the project documentation suggests that a user with the Media Library "Create (upload)" permission is supposed to be…
- CVE-2022-33156Jul 12, 2022risk 0.00cvss —epss 0.01
The matomo_integration (aka Matomo Integration) extension before 1.3.2 for TYPO3 allows XSS.
- CVE-2022-33157Jul 12, 2022risk 0.00cvss —epss 0.01
The libconnect extension before 7.0.8 and 8.x before 8.1.0 for TYPO3 allows XSS.
- CVE-2022-31102Jul 12, 2022risk 0.00cvss —epss 0.01
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Argo CD starting with 2.3.0 and prior to 2.3.6 and 2.4.5 is vulnerable to a cross-site scripting (XSS) bug which could allow an attacker to inject arbitrary JavaScript in the `/auth/callback` page in a…
- CVE-2022-33155Jul 12, 2022risk 0.00cvss —epss 0.00
The ameos_tarteaucitron (aka AMEOS - TarteAuCitron GDPR cookie banner and tracking management / French RGPD compatible) extension before 1.2.23 for TYPO3 allows XSS.
- CVE-2022-33154Jul 12, 2022risk 0.00cvss —epss 0.00
The schema (aka Embedding schema.org vocabulary) extension before 1.13.1 and 2.x before 2.5.1 for TYPO3 allows XSS.
- CVE-2022-25875Jul 12, 2022risk 0.00cvss —epss 0.01
The package svelte before 3.49.0 are vulnerable to Cross-site Scripting (XSS) due to improper input sanitization and to improper escape of attributes when using objects during SSR (Server-Side Rendering). Exploiting this vulnerability is possible via objects with a custom…
- CVE-2022-25303Jul 12, 2022risk 0.00cvss —epss 0.01
The package whoogle-search before 0.7.2 are vulnerable to Cross-site Scripting (XSS) via the query string parameter q. In the case where it does not contain the http string, it is used to build the error_message that is then rendered in the error.html template, using the…
- CVE-2022-2353Jul 9, 2022risk 0.00cvss —epss 0.00
Prior to microweber/microweber v1.2.20, due to improper neutralization of input, an attacker can steal tokens to perform cross-site request forgery, fetch contents from same-site and redirect a user.
- CVE-2022-32115Jul 8, 2022risk 0.00cvss —epss 0.01
An issue in the isSVG() function of Known v1.2.2+2020061101 allows attackers to execute arbitrary code via a crafted SVG file.
- CVE-2022-31290Jul 8, 2022risk 0.00cvss —epss 0.01
A cross-site scripting (XSS) vulnerability in Known v1.2.2+2020061101 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Your Name text field.
- CVE-2022-32061Jul 7, 2022risk 0.00cvss —epss 0.01
An arbitrary file upload vulnerability in the Select User function under the People Menu component of Snipe-IT v6.0.2 allows attackers to execute arbitrary code via a crafted file.
- CVE-2021-44791Jul 7, 2022risk 0.00cvss —epss 0.02
In Apache Druid 0.22.1 and earlier, certain specially-crafted links result in unescaped URL parameters being sent back in HTML responses. This makes it possible to execute reflected XSS attacks.
- CVE-2022-32060Jul 7, 2022risk 0.00cvss —epss 0.01
An arbitrary file upload vulnerability in the Update Branding Settings component of Snipe-IT v6.0.2 allows attackers to execute arbitrary code via a crafted file.
- CVE-2022-31127Jul 6, 2022risk 0.00cvss —epss 0.01
NextAuth.js is a complete open source authentication solution for Next.js applications. An attacker can pass a compromised input to the e-mail [signin endpoint](https://next-auth.js.org/getting-started/rest-api#post-apiauthsigninprovider) that contains some malicious HTML,…
- CVE-2022-2300Jul 4, 2022risk 0.00cvss —epss 0.00
Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 1.2.19.