CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Description
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85
CVEs mapped to this weakness (23,312)
page 869 of 1,166| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-1928 | 0.00 | — | 0.01 | May 29, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository go-gitea/gitea prior to 1.16.9. | |||
| CVE-2022-30349 | — | 0.00 | — | 0.01 | May 27, 2022 | siteserver SSCMS 6.15.51 is vulnerable to Cross Site Scripting (XSS). | ||
| CVE-2021-4231 | — | 0.00 | — | 0.01 | May 26, 2022 | A vulnerability was found in Angular up to 11.0.4/11.1.0-next.2. It has been classified as problematic. Affected is the handling of comments. The manipulation leads to cross site scripting. It is possible to launch the attack remotely but it might require an authentication… | ||
| CVE-2022-22577 | — | 0.00 | — | 0.02 | May 26, 2022 | An XSS Vulnerability in Action Pack >= 5.2.0 and < 5.2.0 that could allow an attacker to bypass CSP for non HTML like responses. | ||
| CVE-2022-27777 | — | 0.00 | — | 0.01 | May 26, 2022 | A XSS Vulnerability in Action View tag helpers >= 5.2.0 and < 5.2.0 which would allow an attacker to inject content if able to control input into specific attributes. | ||
| CVE-2022-30999 | 0.00 | — | 0.01 | May 25, 2022 | FriendsofFlarum (FoF) Upload is an extension that handles file uploads intelligently for your forum. If FoF Upload prior to version 1.2.3 is configured to allow the uploading of SVG files ('image/svg+xml'), navigating directly to an SVG file URI could execute arbitrary… | |||
| CVE-2022-29251 | 0.00 | — | 0.01 | May 25, 2022 | XWiki Platform Flamingo Theme UI is a tool that allows customization and preview of any Flamingo-based skin. Starting with versions 6.2.4 and 6.3-rc-1, a possible cross-site scripting vector is present in the `FlamingoThemesCode.WebHomeSheet` wiki page related to the… | |||
| CVE-2022-29252 | 0.00 | — | 0.01 | May 25, 2022 | XWiki Platform Wiki UI Main Wiki is a package for managing subwikis. Starting with version 5.3-milestone-2, XWiki Platform Wiki UI Main Wiki contains a possible cross-site scripting vector in the `WikiManager.JoinWiki ` wiki page related to the "requestJoin" field. The issue is… | |||
| CVE-2022-29362 | — | 0.00 | — | 0.00 | May 25, 2022 | A cross-site scripting (XSS) vulnerability in /navigation/create?ParentID=%23 of ZKEACMS v3.5.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the ParentID parameter. | ||
| CVE-2021-42656 | — | 0.00 | — | 0.01 | May 24, 2022 | SiteServer CMS V6.15.51 is affected by a Cross Site Scripting (XSS) vulnerability. | ||
| CVE-2022-1811 | 0.00 | — | 0.01 | May 23, 2022 | Unrestricted Upload of File with Dangerous Type in GitHub repository publify/publify prior to 9.2.9. | |||
| CVE-2022-29230 | 0.00 | — | 0.01 | May 18, 2022 | Hydrogen is a React-based framework for building dynamic, Shopify-powered custom storefronts. There is a potential Cross-Site Scripting (XSS) vulnerability where an arbitrary user is able to execute scripts on pages that are built with Hydrogen. This affects all versions of… | |||
| CVE-2022-30596 | 0.00 | — | 0.01 | May 18, 2022 | A flaw was found in moodle where ID numbers displayed when bulk allocating markers to assignments required additional sanitizing to prevent a stored XSS risk. | |||
| CVE-2022-1432 | 0.00 | — | 0.01 | May 18, 2022 | Cross-site Scripting (XSS) - Generic in GitHub repository octoprint/octoprint prior to 1.8.0. | |||
| CVE-2022-1430 | 0.00 | — | 0.01 | May 18, 2022 | Cross-site Scripting (XSS) - DOM in GitHub repository octoprint/octoprint prior to 1.8.0. | |||
| CVE-2022-1782 | — | 0.00 | — | 0.01 | May 18, 2022 | Cross-site Scripting (XSS) - Generic in GitHub repository erudika/para prior to v1.45.11. | ||
| CVE-2022-30970 | — | 0.00 | — | 0.01 | May 17, 2022 | Jenkins Autocomplete Parameter Plugin 1.1 and earlier references Dropdown Autocomplete parameter and Auto Complete String parameter names in an unsafe manner from Javascript embedded in view definitions, resulting in a stored cross-site scripting (XSS) vulnerability exploitable… | ||
| CVE-2022-30968 | — | 0.00 | — | 0.01 | May 17, 2022 | Jenkins vboxwrapper Plugin 1.3 and earlier does not escape the name and description of VBox node parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission. | ||
| CVE-2022-30967 | 0.00 | — | 0.01 | May 17, 2022 | Jenkins Selection tasks Plugin 1.0 and earlier does not escape the name and description of Script Selection task variable parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure… | |||
| CVE-2022-30966 | — | 0.00 | — | 0.01 | May 17, 2022 | Jenkins Random String Parameter Plugin 1.0 and earlier does not escape the name and description of Random String parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission. |
- CVE-2022-1928May 29, 2022risk 0.00cvss —epss 0.01
Cross-site Scripting (XSS) - Stored in GitHub repository go-gitea/gitea prior to 1.16.9.
- CVE-2022-30349May 27, 2022risk 0.00cvss —epss 0.01
siteserver SSCMS 6.15.51 is vulnerable to Cross Site Scripting (XSS).
- CVE-2021-4231May 26, 2022risk 0.00cvss —epss 0.01
A vulnerability was found in Angular up to 11.0.4/11.1.0-next.2. It has been classified as problematic. Affected is the handling of comments. The manipulation leads to cross site scripting. It is possible to launch the attack remotely but it might require an authentication…
- CVE-2022-22577May 26, 2022risk 0.00cvss —epss 0.02
An XSS Vulnerability in Action Pack >= 5.2.0 and < 5.2.0 that could allow an attacker to bypass CSP for non HTML like responses.
- CVE-2022-27777May 26, 2022risk 0.00cvss —epss 0.01
A XSS Vulnerability in Action View tag helpers >= 5.2.0 and < 5.2.0 which would allow an attacker to inject content if able to control input into specific attributes.
- CVE-2022-30999May 25, 2022risk 0.00cvss —epss 0.01
FriendsofFlarum (FoF) Upload is an extension that handles file uploads intelligently for your forum. If FoF Upload prior to version 1.2.3 is configured to allow the uploading of SVG files ('image/svg+xml'), navigating directly to an SVG file URI could execute arbitrary…
- CVE-2022-29251May 25, 2022risk 0.00cvss —epss 0.01
XWiki Platform Flamingo Theme UI is a tool that allows customization and preview of any Flamingo-based skin. Starting with versions 6.2.4 and 6.3-rc-1, a possible cross-site scripting vector is present in the `FlamingoThemesCode.WebHomeSheet` wiki page related to the…
- CVE-2022-29252May 25, 2022risk 0.00cvss —epss 0.01
XWiki Platform Wiki UI Main Wiki is a package for managing subwikis. Starting with version 5.3-milestone-2, XWiki Platform Wiki UI Main Wiki contains a possible cross-site scripting vector in the `WikiManager.JoinWiki ` wiki page related to the "requestJoin" field. The issue is…
- CVE-2022-29362May 25, 2022risk 0.00cvss —epss 0.00
A cross-site scripting (XSS) vulnerability in /navigation/create?ParentID=%23 of ZKEACMS v3.5.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the ParentID parameter.
- CVE-2021-42656May 24, 2022risk 0.00cvss —epss 0.01
SiteServer CMS V6.15.51 is affected by a Cross Site Scripting (XSS) vulnerability.
- CVE-2022-1811May 23, 2022risk 0.00cvss —epss 0.01
Unrestricted Upload of File with Dangerous Type in GitHub repository publify/publify prior to 9.2.9.
- CVE-2022-29230May 18, 2022risk 0.00cvss —epss 0.01
Hydrogen is a React-based framework for building dynamic, Shopify-powered custom storefronts. There is a potential Cross-Site Scripting (XSS) vulnerability where an arbitrary user is able to execute scripts on pages that are built with Hydrogen. This affects all versions of…
- CVE-2022-30596May 18, 2022risk 0.00cvss —epss 0.01
A flaw was found in moodle where ID numbers displayed when bulk allocating markers to assignments required additional sanitizing to prevent a stored XSS risk.
- CVE-2022-1432May 18, 2022risk 0.00cvss —epss 0.01
Cross-site Scripting (XSS) - Generic in GitHub repository octoprint/octoprint prior to 1.8.0.
- CVE-2022-1430May 18, 2022risk 0.00cvss —epss 0.01
Cross-site Scripting (XSS) - DOM in GitHub repository octoprint/octoprint prior to 1.8.0.
- CVE-2022-1782May 18, 2022risk 0.00cvss —epss 0.01
Cross-site Scripting (XSS) - Generic in GitHub repository erudika/para prior to v1.45.11.
- CVE-2022-30970May 17, 2022risk 0.00cvss —epss 0.01
Jenkins Autocomplete Parameter Plugin 1.1 and earlier references Dropdown Autocomplete parameter and Auto Complete String parameter names in an unsafe manner from Javascript embedded in view definitions, resulting in a stored cross-site scripting (XSS) vulnerability exploitable…
- CVE-2022-30968May 17, 2022risk 0.00cvss —epss 0.01
Jenkins vboxwrapper Plugin 1.3 and earlier does not escape the name and description of VBox node parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.
- CVE-2022-30967May 17, 2022risk 0.00cvss —epss 0.01
Jenkins Selection tasks Plugin 1.0 and earlier does not escape the name and description of Script Selection task variable parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure…
- CVE-2022-30966May 17, 2022risk 0.00cvss —epss 0.01
Jenkins Random String Parameter Plugin 1.0 and earlier does not escape the name and description of Random String parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.