CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Description
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85
CVEs mapped to this weakness (23,312)
page 867 of 1,166| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-34188 | 0.00 | — | 0.01 | Jun 22, 2022 | Jenkins Hidden Parameter Plugin 0.0.4 and earlier does not escape the name and description of Hidden Parameter parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission. | |||
| CVE-2022-34185 | 0.00 | — | 0.01 | Jun 22, 2022 | Jenkins Date Parameter Plugin 0.0.4 and earlier does not escape the name and description of Date parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission. | |||
| CVE-2022-34182 | 0.00 | — | 0.01 | Jun 22, 2022 | Jenkins Nested View Plugin 1.20 through 1.25 (both inclusive) does not escape search parameters, resulting in a reflected cross-site scripting (XSS) vulnerability. | |||
| CVE-2022-34178 | 0.00 | — | 0.01 | Jun 22, 2022 | Jenkins Embeddable Build Status Plugin 2.0.3 allows specifying a 'link' query parameter that build status badges will link to, without restricting possible values, resulting in a reflected cross-site scripting (XSS) vulnerability. | |||
| CVE-2022-34173 | 0.00 | — | 0.01 | Jun 22, 2022 | In Jenkins 2.340 through 2.355 (both inclusive) the tooltip of the build button in list views supports HTML without escaping the job display name, resulting in a cross-site scripting (XSS) vulnerability exploitable by attackers with Job/Configure permission. | |||
| CVE-2022-34172 | 0.00 | — | 0.01 | Jun 22, 2022 | In Jenkins 2.340 through 2.355 (both inclusive) symbol-based icons unescape previously escaped values of 'tooltip' parameters, resulting in a cross-site scripting (XSS) vulnerability. | |||
| CVE-2022-34171 | 0.00 | — | 0.01 | Jun 22, 2022 | In Jenkins 2.321 through 2.355 (both inclusive) and LTS 2.332.1 through LTS 2.332.3 (both inclusive) the HTML output generated for new symbol-based SVG icons includes the 'title' attribute of 'l:ionicon' (until Jenkins 2.334) and 'alt' attribute of 'l:icon' (since Jenkins 2.335)… | |||
| CVE-2022-34170 | 0.00 | — | 0.01 | Jun 22, 2022 | In Jenkins 2.320 through 2.355 (both inclusive) and LTS 2.332.1 through LTS 2.332.3 (both inclusive) the help icon does not escape the feature name that is part of its tooltip, effectively undoing the fix for SECURITY-1955, resulting in a cross-site scripting (XSS) vulnerability… | |||
| CVE-2022-2174 | 0.00 | — | 0.03 | Jun 22, 2022 | Cross-site Scripting (XSS) - Reflected in GitHub repository microweber/microweber prior to 1.2.18. | |||
| CVE-2022-34176 | 0.00 | — | 0.77 | Jun 22, 2022 | Jenkins JUnit Plugin 1119.va_a_5e9068da_d7 and earlier does not escape descriptions of test results, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Run/Update permission. | |||
| CVE-2022-30874 | — | 0.00 | — | 0.01 | Jun 21, 2022 | There is a Cross Site Scripting Stored (XSS) vulnerability in NukeViet CMS before 4.5.02. | ||
| CVE-2021-41924 | 0.00 | — | 0.01 | Jun 21, 2022 | Webkul krayin crm before 1.2.2 is vulnerable to Cross Site Scripting (XSS). | |||
| CVE-2022-2130 | 0.00 | — | 0.03 | Jun 20, 2022 | Cross-site Scripting (XSS) - Reflected in GitHub repository microweber/microweber prior to 1.2.17. | |||
| CVE-2017-20061 | — | 0.00 | — | 0.00 | Jun 20, 2022 | A vulnerability has been found in Elefant CMS 1.3.12-RC and classified as problematic. This vulnerability affects unknown code of the file /admin/extended. The manipulation of the argument name with the input %3Cimg%20src=no%20onerror=alert(1)%3E leads to basic cross site… | ||
| CVE-2017-20060 | — | 0.00 | — | 0.00 | Jun 20, 2022 | A vulnerability, which was classified as problematic, was found in Elefant CMS 1.3.12-RC. This affects an unknown part of the component Blog Post Handler. The manipulation leads to basic cross site scripting (Persistent). It is possible to initiate the attack remotely. Upgrading… | ||
| CVE-2017-20059 | — | 0.00 | — | 0.00 | Jun 20, 2022 | A vulnerability, which was classified as problematic, has been found in Elefant CMS 1.3.12-RC. Affected by this issue is some unknown functionality of the component Title Handler. The manipulation with the input leads to basic cross site… | ||
| CVE-2017-20058 | — | 0.00 | — | 0.01 | Jun 20, 2022 | A vulnerability classified as problematic was found in Elefant CMS 1.3.12-RC. Affected by this vulnerability is an unknown functionality of the component Version Comparison. The manipulation leads to basic cross site scripting (Persistent). The attack can be launched remotely.… | ||
| CVE-2017-20057 | — | 0.00 | — | 0.01 | Jun 20, 2022 | A vulnerability classified as problematic has been found in Elefant CMS 1.3.12-RC. Affected is an unknown function. The manipulation of the argument username leads to basic cross site scripting (Persistent). It is possible to launch the attack remotely. Upgrading to version… | ||
| CVE-2022-25772 | 0.00 | — | 0.61 | Jun 20, 2022 | A cross-site scripting (XSS) vulnerability in the web tracking component of Mautic before 4.3.0 allows remote attackers to inject executable javascript | |||
| CVE-2021-33295 | — | 0.00 | — | 0.01 | Jun 16, 2022 | Cross Site Scripting (XSS) vulnerability in Joplin Desktop App before 1.8.5 allows attackers to execute aribrary code due to improper sanitizing of html. |
- CVE-2022-34188Jun 22, 2022risk 0.00cvss —epss 0.01
Jenkins Hidden Parameter Plugin 0.0.4 and earlier does not escape the name and description of Hidden Parameter parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.
- CVE-2022-34185Jun 22, 2022risk 0.00cvss —epss 0.01
Jenkins Date Parameter Plugin 0.0.4 and earlier does not escape the name and description of Date parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.
- CVE-2022-34182Jun 22, 2022risk 0.00cvss —epss 0.01
Jenkins Nested View Plugin 1.20 through 1.25 (both inclusive) does not escape search parameters, resulting in a reflected cross-site scripting (XSS) vulnerability.
- CVE-2022-34178Jun 22, 2022risk 0.00cvss —epss 0.01
Jenkins Embeddable Build Status Plugin 2.0.3 allows specifying a 'link' query parameter that build status badges will link to, without restricting possible values, resulting in a reflected cross-site scripting (XSS) vulnerability.
- CVE-2022-34173Jun 22, 2022risk 0.00cvss —epss 0.01
In Jenkins 2.340 through 2.355 (both inclusive) the tooltip of the build button in list views supports HTML without escaping the job display name, resulting in a cross-site scripting (XSS) vulnerability exploitable by attackers with Job/Configure permission.
- CVE-2022-34172Jun 22, 2022risk 0.00cvss —epss 0.01
In Jenkins 2.340 through 2.355 (both inclusive) symbol-based icons unescape previously escaped values of 'tooltip' parameters, resulting in a cross-site scripting (XSS) vulnerability.
- CVE-2022-34171Jun 22, 2022risk 0.00cvss —epss 0.01
In Jenkins 2.321 through 2.355 (both inclusive) and LTS 2.332.1 through LTS 2.332.3 (both inclusive) the HTML output generated for new symbol-based SVG icons includes the 'title' attribute of 'l:ionicon' (until Jenkins 2.334) and 'alt' attribute of 'l:icon' (since Jenkins 2.335)…
- CVE-2022-34170Jun 22, 2022risk 0.00cvss —epss 0.01
In Jenkins 2.320 through 2.355 (both inclusive) and LTS 2.332.1 through LTS 2.332.3 (both inclusive) the help icon does not escape the feature name that is part of its tooltip, effectively undoing the fix for SECURITY-1955, resulting in a cross-site scripting (XSS) vulnerability…
- CVE-2022-2174Jun 22, 2022risk 0.00cvss —epss 0.03
Cross-site Scripting (XSS) - Reflected in GitHub repository microweber/microweber prior to 1.2.18.
- CVE-2022-34176Jun 22, 2022risk 0.00cvss —epss 0.77
Jenkins JUnit Plugin 1119.va_a_5e9068da_d7 and earlier does not escape descriptions of test results, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Run/Update permission.
- CVE-2022-30874Jun 21, 2022risk 0.00cvss —epss 0.01
There is a Cross Site Scripting Stored (XSS) vulnerability in NukeViet CMS before 4.5.02.
- CVE-2021-41924Jun 21, 2022risk 0.00cvss —epss 0.01
Webkul krayin crm before 1.2.2 is vulnerable to Cross Site Scripting (XSS).
- CVE-2022-2130Jun 20, 2022risk 0.00cvss —epss 0.03
Cross-site Scripting (XSS) - Reflected in GitHub repository microweber/microweber prior to 1.2.17.
- CVE-2017-20061Jun 20, 2022risk 0.00cvss —epss 0.00
A vulnerability has been found in Elefant CMS 1.3.12-RC and classified as problematic. This vulnerability affects unknown code of the file /admin/extended. The manipulation of the argument name with the input %3Cimg%20src=no%20onerror=alert(1)%3E leads to basic cross site…
- CVE-2017-20060Jun 20, 2022risk 0.00cvss —epss 0.00
A vulnerability, which was classified as problematic, was found in Elefant CMS 1.3.12-RC. This affects an unknown part of the component Blog Post Handler. The manipulation leads to basic cross site scripting (Persistent). It is possible to initiate the attack remotely. Upgrading…
- CVE-2017-20059Jun 20, 2022risk 0.00cvss —epss 0.00
A vulnerability, which was classified as problematic, has been found in Elefant CMS 1.3.12-RC. Affected by this issue is some unknown functionality of the component Title Handler. The manipulation with the input leads to basic cross site…
- CVE-2017-20058Jun 20, 2022risk 0.00cvss —epss 0.01
A vulnerability classified as problematic was found in Elefant CMS 1.3.12-RC. Affected by this vulnerability is an unknown functionality of the component Version Comparison. The manipulation leads to basic cross site scripting (Persistent). The attack can be launched remotely.…
- CVE-2017-20057Jun 20, 2022risk 0.00cvss —epss 0.01
A vulnerability classified as problematic has been found in Elefant CMS 1.3.12-RC. Affected is an unknown function. The manipulation of the argument username leads to basic cross site scripting (Persistent). It is possible to launch the attack remotely. Upgrading to version…
- CVE-2022-25772Jun 20, 2022risk 0.00cvss —epss 0.61
A cross-site scripting (XSS) vulnerability in the web tracking component of Mautic before 4.3.0 allows remote attackers to inject executable javascript
- CVE-2021-33295Jun 16, 2022risk 0.00cvss —epss 0.01
Cross Site Scripting (XSS) vulnerability in Joplin Desktop App before 1.8.5 allows attackers to execute aribrary code due to improper sanitizing of html.