VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (46,607)

page 88 of 2,331
  • CVE-2021-41372HigNov 10, 2021
    risk 0.49cvss 7.6epss 0.01

    A Cross-Site Scripting (XSS) and Cross-Site Request Forgery (CSRF) vulnerability exists when Power BI Report Server Template file (pbix) containing HTML files is uploaded to the server and HTML files are accessed directly by the victim. Combining these 2 vulnerabilities…

  • CVE-2021-34356HigOct 1, 2021
    risk 0.49cvss 7.6epss 0.01

    A cross-site scripting (XSS) vulnerability has been reported to affect QNAP device running Photo Station. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this vulnerability in the following versions of Photo Station: Photo…

  • CVE-2021-34355HigOct 1, 2021
    risk 0.49cvss 7.6epss 0.01

    A cross-site scripting (XSS) vulnerability has been reported to affect QNAP NAS running Photo Station. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this vulnerability in the following versions of Photo Station: Photo…

  • CVE-2021-34354HigOct 1, 2021
    risk 0.49cvss 7.6epss 0.01

    A cross-site scripting (XSS) vulnerability has been reported to affect QNAP device running Photo Station. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this vulnerability in the following versions of Photo Station: Photo…

  • CVE-2021-39202HigSep 9, 2021
    risk 0.49cvss 7.6epss 0.01

    WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database. In affected versions the widgets editor introduced in WordPress 5.8 beta 1 has improper handling of HTML input in the Custom HTML feature. This leads to…

  • CVE-2021-35239HigAug 31, 2021
    risk 0.49cvss 7.5epss 0.01

    A security researcher found a user with Orion map manage rights could store XSS through via text box hyperlink.

  • CVE-2021-32808HigAug 12, 2021
    risk 0.49cvss 7.6epss 0.01

    ckeditor is an open source WYSIWYG HTML editor with rich content support. A vulnerability has been discovered in the clipboard Widget plugin if used alongside the undo feature. The vulnerability allows a user to abuse undo functionality using malformed widget HTML, which could…

  • CVE-2021-3043HigJul 15, 2021
    risk 0.49cvss 7.5epss 0.01

    A reflected cross-site scripting (XSS) vulnerability exists in the Prisma Cloud Compute web console that enables a remote attacker to execute arbitrary JavaScript code in the browser-based web console while an authenticated administrator is using that web interface. Prisma Cloud…

  • CVE-2021-21441HigJun 16, 2021
    risk 0.49cvss 7.5epss 0.01

    There is a XSS vulnerability in the ticket overview screens. It's possible to collect various information by having an e-mail shown in the overview screen. Attack can be performed by sending specially crafted e-mail to the system and it doesn't require any user intraction. This…

  • CVE-2021-29489HigMay 5, 2021
    risk 0.49cvss 7.6epss 0.01

    Highcharts JS is a JavaScript charting library based on SVG. In Highcharts versions 8 and earlier, the chart options structure was not systematically filtered for XSS vectors. The potential impact was that content from untrusted sources could execute code in the end user's…

  • CVE-2021-29448HigApr 15, 2021
    risk 0.49cvss 7.6epss 0.01

    Pi-hole is a Linux network-level advertisement and Internet tracker blocking application. The Stored XSS exists in the Pi-hole Admin portal, which can be exploited by the malicious actor with the network access to DNS server. See the referenced GitHub security advisory for patch…

  • CVE-2021-23342HigFeb 19, 2021
    risk 0.49cvss 8.6epss 0.02

    This affects the package docsify before 4.12.0. It is possible to bypass the remediation done by CVE-2020-7680 and execute malicious JavaScript through the following methods 1) When parsing HTML from remote URLs, the HTML code on the main page is sanitized, but this sanitization…

  • CVE-2020-12512HigJan 22, 2021
    risk 0.49cvss 7.5epss 0.01

    Pepperl+Fuchs Comtrol IO-Link Master in Version 1.5.48 and below is prone to an authenticated reflected POST Cross-Site Scripting

  • CVE-2021-21260HigJan 22, 2021
    risk 0.49cvss 7.6epss 0.01

    Online Invoicing System (OIS) is open source software which is a lean invoicing system for small businesses, consultants and freelancers created using AppGini. In OIS version 4.0 there is a stored XSS which can enables an attacker takeover of the admin account through a payload…

  • CVE-2020-35937HigJan 1, 2021
    risk 0.49cvss 7.5epss 0.02

    Stored Cross-Site Scripting (XSS) vulnerabilities in the Team Showcase plugin before 1.22.16 for WordPress allow remote authenticated attackers to import layouts including JavaScript supplied via a remotely hosted crafted payload in the source parameter via AJAX. The action must…

  • CVE-2020-35936HigJan 1, 2021
    risk 0.49cvss 7.5epss 0.02

    Stored Cross-Site Scripting (XSS) vulnerabilities in the Post Grid plugin before 2.0.73 for WordPress allow remote authenticated attackers to import layouts including JavaScript supplied via a remotely hosted crafted payload in the source parameter via AJAX. The action must be…

  • CVE-2020-35475HigDec 18, 2020
    risk 0.49cvss 7.5epss 0.02

    In MediaWiki before 1.35.1, the messages userrights-expiry-current and userrights-expiry-none can contain raw HTML. XSS can happen when a user visits Special:UserRights but does not have rights to change all userrights, and the table on the left side has unchangeable groups in…

  • CVE-2020-14610HigJul 15, 2020
    risk 0.49cvss 7.6epss 0.01

    Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Attachments / File Upload). The supported version that is affected is 12.2.9. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to…

  • CVE-2020-11036HigMay 5, 2020
    risk 0.49cvss 7.6epss 0.01

    In GLPI before version 9.4.6 there are multiple related stored XSS vulnerabilities. The package is vulnerable to Stored XSS in the comments of items in the Knowledge base. Adding a comment with content "" reproduces the attack. This can be exploited by a…

  • CVE-2020-11022MedApr 29, 2020
    risk 0.49cvss 6.9epss 0.99

    In jQuery starting with 1.12.0 and before 3.5.0, passing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.