VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (23,312)

page 865 of 1,166
  • CVE-2022-31160Jul 20, 2022
    risk 0.00cvss epss 0.02

    jQuery UI is a curated set of user interface interactions, effects, widgets, and themes built on top of jQuery. Versions prior to 1.13.2 are potentially vulnerable to cross-site scripting. Initializing a checkboxradio widget on an input enclosed within a label makes that parent…

  • CVE-2022-25869Jul 15, 2022
    risk 0.00cvss epss 0.05

    All versions of the package angular; all versions of the package angularjs.core; all versions of the package angularjs are vulnerable to Cross-site Scripting (XSS) due to insecure page caching in the Internet Explorer browser, which allows interpolation of elements.

  • CVE-2020-35305Jul 15, 2022
    risk 0.00cvss epss 0.01

    Cross site scripting (XSS) in gollum 5.0 to 5.1.2 via the filename parameter to the 'New Page' dialog.

  • CVE-2022-32065Jul 13, 2022
    risk 0.00cvss epss 0.01

    An arbitrary file upload vulnerability in the background management module of RuoYi v4.7.3 and below allows attackers to execute arbitrary code via a crafted HTML file.

  • CVE-2022-32114Jul 13, 2022
    risk 0.00cvss epss 0.02

    An unrestricted file upload vulnerability in the Add New Assets function of Strapi 4.1.12 allows attackers to conduct XSS attacks via a crafted PDF file. NOTE: the project documentation suggests that a user with the Media Library "Create (upload)" permission is supposed to be…

  • CVE-2022-33156Jul 12, 2022
    risk 0.00cvss epss 0.01

    The matomo_integration (aka Matomo Integration) extension before 1.3.2 for TYPO3 allows XSS.

  • CVE-2022-33157Jul 12, 2022
    risk 0.00cvss epss 0.01

    The libconnect extension before 7.0.8 and 8.x before 8.1.0 for TYPO3 allows XSS.

  • CVE-2022-31102Jul 12, 2022
    risk 0.00cvss epss 0.01

    Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Argo CD starting with 2.3.0 and prior to 2.3.6 and 2.4.5 is vulnerable to a cross-site scripting (XSS) bug which could allow an attacker to inject arbitrary JavaScript in the `/auth/callback` page in a…

  • CVE-2022-33155Jul 12, 2022
    risk 0.00cvss epss 0.00

    The ameos_tarteaucitron (aka AMEOS - TarteAuCitron GDPR cookie banner and tracking management / French RGPD compatible) extension before 1.2.23 for TYPO3 allows XSS.

  • CVE-2022-33154Jul 12, 2022
    risk 0.00cvss epss 0.00

    The schema (aka Embedding schema.org vocabulary) extension before 1.13.1 and 2.x before 2.5.1 for TYPO3 allows XSS.

  • CVE-2022-25875Jul 12, 2022
    risk 0.00cvss epss 0.01

    The package svelte before 3.49.0 are vulnerable to Cross-site Scripting (XSS) due to improper input sanitization and to improper escape of attributes when using objects during SSR (Server-Side Rendering). Exploiting this vulnerability is possible via objects with a custom…

  • CVE-2022-25303Jul 12, 2022
    risk 0.00cvss epss 0.01

    The package whoogle-search before 0.7.2 are vulnerable to Cross-site Scripting (XSS) via the query string parameter q. In the case where it does not contain the http string, it is used to build the error_message that is then rendered in the error.html template, using the…

  • CVE-2022-2353Jul 9, 2022
    risk 0.00cvss epss 0.00

    Prior to microweber/microweber v1.2.20, due to improper neutralization of input, an attacker can steal tokens to perform cross-site request forgery, fetch contents from same-site and redirect a user.

  • CVE-2022-32115Jul 8, 2022
    risk 0.00cvss epss 0.01

    An issue in the isSVG() function of Known v1.2.2+2020061101 allows attackers to execute arbitrary code via a crafted SVG file.

  • CVE-2022-31290Jul 8, 2022
    risk 0.00cvss epss 0.01

    A cross-site scripting (XSS) vulnerability in Known v1.2.2+2020061101 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Your Name text field.

  • CVE-2022-32061Jul 7, 2022
    risk 0.00cvss epss 0.01

    An arbitrary file upload vulnerability in the Select User function under the People Menu component of Snipe-IT v6.0.2 allows attackers to execute arbitrary code via a crafted file.

  • CVE-2021-44791Jul 7, 2022
    risk 0.00cvss epss 0.02

    In Apache Druid 0.22.1 and earlier, certain specially-crafted links result in unescaped URL parameters being sent back in HTML responses. This makes it possible to execute reflected XSS attacks.

  • CVE-2022-32060Jul 7, 2022
    risk 0.00cvss epss 0.01

    An arbitrary file upload vulnerability in the Update Branding Settings component of Snipe-IT v6.0.2 allows attackers to execute arbitrary code via a crafted file.

  • CVE-2022-31127Jul 6, 2022
    risk 0.00cvss epss 0.01

    NextAuth.js is a complete open source authentication solution for Next.js applications. An attacker can pass a compromised input to the e-mail [signin endpoint](https://next-auth.js.org/getting-started/rest-api#post-apiauthsigninprovider) that contains some malicious HTML,…

  • CVE-2022-2300Jul 4, 2022
    risk 0.00cvss epss 0.00

    Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 1.2.19.