VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (46,607)

page 87 of 2,331
  • CVE-2022-47372HigFeb 15, 2023
    risk 0.49cvss 7.6epss 0.00

    Stored cross-site scripting vulnerability in the Create event section in Pandora FMS Console v766 and lower. An attacker typically exploits this vulnerability by injecting XSS payloads on popular pages of a site or passing a link to a victim, tricking them into viewing the page…

  • CVE-2023-23630HigFeb 1, 2023
    risk 0.49cvss 8.6epss 0.01

    Eta is an embedded JS templating engine that works inside Node, Deno, and the browser. XSS attack - anyone using the Express API is impacted. The problem has been resolved. Users should upgrade to version 2.0.0. As a workaround, don't pass user supplied things directly to…

  • CVE-2023-23637HigJan 17, 2023
    risk 0.49cvss 7.6epss 0.01

    IMPatienT before 1.5.2 allows stored XSS via onmouseover in certain text fields within a PATCH /modify_onto request to the ontology builder. This may allow attackers to steal Protected Health Information.

  • CVE-2022-42967HigJan 11, 2023
    risk 0.49cvss 7.5epss 0.01

    Caret is vulnerable to an XSS attack when the user opens a crafted Markdown file when preview mode is enabled. This directly leads to client-side code execution.

  • CVE-2022-45470HigNov 21, 2022
    risk 0.49cvss 7.5epss 0.01

    missing input validation in Apache Hama may cause information disclosure through path traversal and XSS. Since Apache Hama is EOL, we do not expect these issues to be fixed.

  • CVE-2022-39371HigNov 3, 2022
    risk 0.49cvss 7.5epss 0.00

    GLPI stands for Gestionnaire Libre de Parc Informatique. GLPI is a Free Asset and IT Management Software package that provides ITIL Service Desk features, licenses tracking and software auditing. Script related HTML tags in assets inventory information are not properly…

  • CVE-2022-39020HigOct 31, 2022
    risk 0.49cvss 7.6epss 0.00

    Multiple instances of XSS (stored and reflected) was found in the application. For example, features such as student assessment submission, file upload, news, ePortfolio and calendar event creation were found to be vulnerable to cross-site scripting.

  • CVE-2022-27561HigSep 15, 2022
    risk 0.49cvss 7.5epss 0.00

    There is a reflected Cross-Site Scripting vulnerability in the HCL Traveler web admin (LotusTraveler.nsf).

  • CVE-2022-37317HigAug 25, 2022
    risk 0.49cvss 7.6epss 0.01

    Archer Platform 6.x before 6.11 P3 contain an HTML injection vulnerability. An authenticated remote attacker could potentially exploit this vulnerability by tricking a victim application user to execute malicious code in the context of the web application. 6.10 P4 (6.10.0.4) and…

  • CVE-2022-2362HigAug 22, 2022
    risk 0.49cvss 7.5epss 0.01

    The Download Manager WordPress plugin before 3.2.50 prioritizes getting a visitor's IP from certain HTTP headers over PHP's REMOTE_ADDR, which makes it possible to bypass IP-based download blocking restrictions.

  • CVE-2021-32862HigAug 18, 2022
    risk 0.49cvss 7.5epss 0.01

    The GitHub Security Lab discovered sixteen ways to exploit a cross-site scripting vulnerability in nbconvert. When using nbconvert to generate an HTML version of a user-controllable notebook, it is possible to inject arbitrary HTML which may lead to cross-site scripting (XSS)…

  • CVE-2022-2199HigJul 20, 2022
    risk 0.49cvss 7.5epss 0.01

    The main MiCODUS MV720 GPS tracker web server has a reflected cross-site scripting vulnerability that could allow an attacker to gain control by tricking a user into making a request.

  • CVE-2021-27914HigJun 1, 2022
    risk 0.49cvss 7.6epss 0.00

    A cross-site scripting (XSS) vulnerability in the installer component of Mautic before 4.3.0 allows admins to inject executable javascript

  • CVE-2022-28716HigMay 5, 2022
    risk 0.49cvss 7.5epss 0.01

    On 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all versions of 12.1.x 11.6.x, a DOM-based cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP AFM,…

  • CVE-2022-27230HigMay 5, 2022
    risk 0.49cvss 7.5epss 0.01

    On all versions of 16.1.x, 15.1.x, 14.1.x, 13.1.x, 12.1.x, and 11.6.x of F5 BIG-IP APM, and F5 BIG-IP Guided Configuration (GC) all versions prior to 9.0, a reflected cross-site scripting (XSS) vulnerability exists in an undisclosed page of F5 BIG-IP Guided Configuration that…

  • CVE-2020-25158HigApr 14, 2022
    risk 0.49cvss 7.6epss 0.01

    A reflected cross-site scripting (XSS) vulnerability in the B. Braun Melsungen AG SpaceCom Version L81/U61 and earlier, and the Data module compactplus Versions A10 and A11 allows remote attackers to inject arbitrary web script or HTML into various locations.

  • CVE-2022-21932HigJan 11, 2022
    risk 0.49cvss 7.6epss 0.01

    Microsoft Dynamics 365 Customer Engagement Cross-Site Scripting Vulnerability

  • CVE-2021-44471HigDec 22, 2021
    risk 0.49cvss 7.5epss 0.01

    DIAEnergie Version 1.7.5 and prior is vulnerable to stored cross-site scripting when an unauthenticated user injects arbitrary code into the parameter “name” of the script “DIAE_HandlerAlarmGroup.ashx”.

  • CVE-2021-23228HigDec 22, 2021
    risk 0.49cvss 7.5epss 0.01

    DIAEnergie Version 1.7.5 and prior is vulnerable to a reflected cross-site scripting attack through error pages that are returned by “.NET Request.QueryString”.

  • CVE-2021-42360HigNov 17, 2021
    risk 0.49cvss 7.6epss 0.01

    On sites that also had the Elementor plugin for WordPress installed, it was possible for users with the edit_posts capability, which includes Contributor-level users, to import blocks onto any page using the astra-page-elementor-batch-process AJAX action. An attacker could craft…