VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (23,312)

page 867 of 1,166
  • CVE-2022-34188Jun 22, 2022
    risk 0.00cvss epss 0.01

    Jenkins Hidden Parameter Plugin 0.0.4 and earlier does not escape the name and description of Hidden Parameter parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.

  • CVE-2022-34185Jun 22, 2022
    risk 0.00cvss epss 0.01

    Jenkins Date Parameter Plugin 0.0.4 and earlier does not escape the name and description of Date parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.

  • CVE-2022-34182Jun 22, 2022
    risk 0.00cvss epss 0.01

    Jenkins Nested View Plugin 1.20 through 1.25 (both inclusive) does not escape search parameters, resulting in a reflected cross-site scripting (XSS) vulnerability.

  • CVE-2022-34178Jun 22, 2022
    risk 0.00cvss epss 0.01

    Jenkins Embeddable Build Status Plugin 2.0.3 allows specifying a 'link' query parameter that build status badges will link to, without restricting possible values, resulting in a reflected cross-site scripting (XSS) vulnerability.

  • CVE-2022-34173Jun 22, 2022
    risk 0.00cvss epss 0.01

    In Jenkins 2.340 through 2.355 (both inclusive) the tooltip of the build button in list views supports HTML without escaping the job display name, resulting in a cross-site scripting (XSS) vulnerability exploitable by attackers with Job/Configure permission.

  • CVE-2022-34172Jun 22, 2022
    risk 0.00cvss epss 0.01

    In Jenkins 2.340 through 2.355 (both inclusive) symbol-based icons unescape previously escaped values of 'tooltip' parameters, resulting in a cross-site scripting (XSS) vulnerability.

  • CVE-2022-34171Jun 22, 2022
    risk 0.00cvss epss 0.01

    In Jenkins 2.321 through 2.355 (both inclusive) and LTS 2.332.1 through LTS 2.332.3 (both inclusive) the HTML output generated for new symbol-based SVG icons includes the 'title' attribute of 'l:ionicon' (until Jenkins 2.334) and 'alt' attribute of 'l:icon' (since Jenkins 2.335)…

  • CVE-2022-34170Jun 22, 2022
    risk 0.00cvss epss 0.01

    In Jenkins 2.320 through 2.355 (both inclusive) and LTS 2.332.1 through LTS 2.332.3 (both inclusive) the help icon does not escape the feature name that is part of its tooltip, effectively undoing the fix for SECURITY-1955, resulting in a cross-site scripting (XSS) vulnerability…

  • CVE-2022-2174Jun 22, 2022
    risk 0.00cvss epss 0.03

    Cross-site Scripting (XSS) - Reflected in GitHub repository microweber/microweber prior to 1.2.18.

  • CVE-2022-34176Jun 22, 2022
    risk 0.00cvss epss 0.77

    Jenkins JUnit Plugin 1119.va_a_5e9068da_d7 and earlier does not escape descriptions of test results, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Run/Update permission.

  • CVE-2022-30874Jun 21, 2022
    risk 0.00cvss epss 0.01

    There is a Cross Site Scripting Stored (XSS) vulnerability in NukeViet CMS before 4.5.02.

  • CVE-2021-41924Jun 21, 2022
    risk 0.00cvss epss 0.01

    Webkul krayin crm before 1.2.2 is vulnerable to Cross Site Scripting (XSS).

  • CVE-2022-2130Jun 20, 2022
    risk 0.00cvss epss 0.03

    Cross-site Scripting (XSS) - Reflected in GitHub repository microweber/microweber prior to 1.2.17.

  • CVE-2017-20061Jun 20, 2022
    risk 0.00cvss epss 0.00

    A vulnerability has been found in Elefant CMS 1.3.12-RC and classified as problematic. This vulnerability affects unknown code of the file /admin/extended. The manipulation of the argument name with the input %3Cimg%20src=no%20onerror=alert(1)%3E leads to basic cross site…

  • CVE-2017-20060Jun 20, 2022
    risk 0.00cvss epss 0.00

    A vulnerability, which was classified as problematic, was found in Elefant CMS 1.3.12-RC. This affects an unknown part of the component Blog Post Handler. The manipulation leads to basic cross site scripting (Persistent). It is possible to initiate the attack remotely. Upgrading…

  • CVE-2017-20059Jun 20, 2022
    risk 0.00cvss epss 0.00

    A vulnerability, which was classified as problematic, has been found in Elefant CMS 1.3.12-RC. Affected by this issue is some unknown functionality of the component Title Handler. The manipulation with the input leads to basic cross site…

  • CVE-2017-20058Jun 20, 2022
    risk 0.00cvss epss 0.01

    A vulnerability classified as problematic was found in Elefant CMS 1.3.12-RC. Affected by this vulnerability is an unknown functionality of the component Version Comparison. The manipulation leads to basic cross site scripting (Persistent). The attack can be launched remotely.…

  • CVE-2017-20057Jun 20, 2022
    risk 0.00cvss epss 0.01

    A vulnerability classified as problematic has been found in Elefant CMS 1.3.12-RC. Affected is an unknown function. The manipulation of the argument username leads to basic cross site scripting (Persistent). It is possible to launch the attack remotely. Upgrading to version…

  • CVE-2022-25772Jun 20, 2022
    risk 0.00cvss epss 0.61

    A cross-site scripting (XSS) vulnerability in the web tracking component of Mautic before 4.3.0 allows remote attackers to inject executable javascript

  • CVE-2021-33295Jun 16, 2022
    risk 0.00cvss epss 0.01

    Cross Site Scripting (XSS) vulnerability in Joplin Desktop App before 1.8.5 allows attackers to execute aribrary code due to improper sanitizing of html.