CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Description
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85
CVEs mapped to this weakness (23,306)
page 885 of 1,166| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-25969 | — | 0.00 | — | 0.01 | Oct 20, 2021 | In Camaleon CMS application, versions 0.0.1 to 2.6.0 are vulnerable to stored XSS, that allows an unauthenticated attacker to store malicious scripts in the comments section of the post. These scripts are executed in a victim’s browser when they open the page containing the… | ||
| CVE-2021-33988 | — | 0.00 | — | 0.01 | Oct 19, 2021 | Cross Site Scripting (XSS). vulnerability exists in Microweber CMS 1.2.7 via the Login form, which could let a malicious user execute Javascript by Inserting code in the request form. | ||
| CVE-2011-1497 | — | 0.00 | — | 0.01 | Oct 19, 2021 | A cross-site scripting vulnerability flaw was found in the auto_link function in Rails before version 3.0.6. | ||
| CVE-2021-3879 | 0.00 | — | 0.01 | Oct 19, 2021 | snipe-it is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | |||
| CVE-2021-3863 | 0.00 | — | 0.01 | Oct 19, 2021 | snipe-it is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | |||
| CVE-2021-32609 | 0.00 | — | 0.02 | Oct 18, 2021 | Apache Superset up to and including 1.1 does not sanitize titles correctly on the Explore page. This allows an attacker with Explore access to save a chart with a malicious title, injecting html (including scripts) into the page. | |||
| CVE-2021-42227 | — | 0.00 | — | 0.01 | Oct 14, 2021 | Cross SIte Scripting (XSS) vulnerability exists in KindEditor 4.1.x via a Google search inurl:/examples/uploadbutton.html and then the .html file on the website that uses this editor (the file suffix is allowed). | ||
| CVE-2021-41132 | 0.00 | — | 0.01 | Oct 14, 2021 | OMERO.web provides a web based client and plugin infrastructure. In versions prior to 5.11.0, a variety of templates do not perform proper sanitization through HTML escaping. Due to the lack of sanitization and use of ``jQuery.html()``, there are a whole host of cross-site… | |||
| CVE-2021-42134 | — | 0.00 | — | 0.01 | Oct 11, 2021 | The Unicorn framework before 0.36.1 for Django allows XSS via a component. NOTE: this issue exists because of an incomplete fix for CVE-2021-42053. | ||
| CVE-2021-42112 | — | 0.00 | — | 0.01 | Oct 8, 2021 | The "File upload question" functionality in LimeSurvey 3.x-LTS through 3.27.18 allows XSS in assets/scripts/modaldialog.js and assets/scripts/uploader.js. | ||
| CVE-2021-23447 | 0.00 | — | 0.01 | Oct 7, 2021 | This affects the package teddy before 0.5.9. A type confusion vulnerability can be used to bypass input sanitization when the model content is an array (instead of a string). | |||
| CVE-2021-36150 | — | 0.00 | — | 0.01 | Oct 7, 2021 | SilverStripe Framework through 4.8.1 allows XSS. | ||
| CVE-2021-42053 | — | 0.00 | — | 0.03 | Oct 7, 2021 | The Unicorn framework through 0.35.3 for Django allows XSS via component.name. | ||
| CVE-2021-21684 | 0.00 | — | 0.01 | Oct 6, 2021 | Jenkins Git Plugin 4.8.2 and earlier does not escape the Git SHA-1 checksum parameters provided to commit notifications when displaying them in a build cause, resulting in a stored cross-site scripting (XSS) vulnerability. | |||
| CVE-2021-40926 | — | 0.00 | — | 0.01 | Oct 1, 2021 | Cross-site scripting (XSS) vulnerability in demos/demo.mysqli.php in getID3 1.X and v2.0.0-beta allows remote attackers to inject arbitrary web script or HTML via the showtagfiles parameter. | ||
| CVE-2021-25963 | 0.00 | — | 0.01 | Sep 30, 2021 | In Shuup, versions 1.6.0 through 2.10.8 are vulnerable to reflected Cross-Site Scripting (XSS) that allows execution of arbitrary javascript code on a victim browser. This vulnerability exists due to the error page contents not escaped. | |||
| CVE-2020-20129 | — | 0.00 | — | 0.01 | Sep 29, 2021 | LaraCMS v1.0.1 contains a stored cross-site scripting (XSS) vulnerability which allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the content editor. | ||
| CVE-2021-25959 | — | 0.00 | — | 0.01 | Sep 29, 2021 | In OpenCRX, versions v4.0.0 through v5.1.0 are vulnerable to reflected Cross-site Scripting (XSS), due to unsanitized parameters in the password reset functionality. This allows execution of external javascript files on any user of the openCRX instance. | ||
| CVE-2020-20696 | — | 0.00 | — | 0.00 | Sep 27, 2021 | A cross-site scripting (XSS) vulnerability in /admin/content/post of GilaCMS v1.11.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the Tags field. | ||
| CVE-2020-20695 | — | 0.00 | — | 0.01 | Sep 27, 2021 | A stored cross-site scripting (XSS) vulnerability in GilaCMS v1.11.4 allows attackers to execute arbitrary web scripts or HTML via a crafted SVG file. |
- CVE-2021-25969Oct 20, 2021risk 0.00cvss —epss 0.01
In Camaleon CMS application, versions 0.0.1 to 2.6.0 are vulnerable to stored XSS, that allows an unauthenticated attacker to store malicious scripts in the comments section of the post. These scripts are executed in a victim’s browser when they open the page containing the…
- CVE-2021-33988Oct 19, 2021risk 0.00cvss —epss 0.01
Cross Site Scripting (XSS). vulnerability exists in Microweber CMS 1.2.7 via the Login form, which could let a malicious user execute Javascript by Inserting code in the request form.
- CVE-2011-1497Oct 19, 2021risk 0.00cvss —epss 0.01
A cross-site scripting vulnerability flaw was found in the auto_link function in Rails before version 3.0.6.
- CVE-2021-3879Oct 19, 2021risk 0.00cvss —epss 0.01
snipe-it is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- CVE-2021-3863Oct 19, 2021risk 0.00cvss —epss 0.01
snipe-it is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- CVE-2021-32609Oct 18, 2021risk 0.00cvss —epss 0.02
Apache Superset up to and including 1.1 does not sanitize titles correctly on the Explore page. This allows an attacker with Explore access to save a chart with a malicious title, injecting html (including scripts) into the page.
- CVE-2021-42227Oct 14, 2021risk 0.00cvss —epss 0.01
Cross SIte Scripting (XSS) vulnerability exists in KindEditor 4.1.x via a Google search inurl:/examples/uploadbutton.html and then the .html file on the website that uses this editor (the file suffix is allowed).
- CVE-2021-41132Oct 14, 2021risk 0.00cvss —epss 0.01
OMERO.web provides a web based client and plugin infrastructure. In versions prior to 5.11.0, a variety of templates do not perform proper sanitization through HTML escaping. Due to the lack of sanitization and use of ``jQuery.html()``, there are a whole host of cross-site…
- CVE-2021-42134Oct 11, 2021risk 0.00cvss —epss 0.01
The Unicorn framework before 0.36.1 for Django allows XSS via a component. NOTE: this issue exists because of an incomplete fix for CVE-2021-42053.
- CVE-2021-42112Oct 8, 2021risk 0.00cvss —epss 0.01
The "File upload question" functionality in LimeSurvey 3.x-LTS through 3.27.18 allows XSS in assets/scripts/modaldialog.js and assets/scripts/uploader.js.
- CVE-2021-23447Oct 7, 2021risk 0.00cvss —epss 0.01
This affects the package teddy before 0.5.9. A type confusion vulnerability can be used to bypass input sanitization when the model content is an array (instead of a string).
- CVE-2021-36150Oct 7, 2021risk 0.00cvss —epss 0.01
SilverStripe Framework through 4.8.1 allows XSS.
- CVE-2021-42053Oct 7, 2021risk 0.00cvss —epss 0.03
The Unicorn framework through 0.35.3 for Django allows XSS via component.name.
- CVE-2021-21684Oct 6, 2021risk 0.00cvss —epss 0.01
Jenkins Git Plugin 4.8.2 and earlier does not escape the Git SHA-1 checksum parameters provided to commit notifications when displaying them in a build cause, resulting in a stored cross-site scripting (XSS) vulnerability.
- CVE-2021-40926Oct 1, 2021risk 0.00cvss —epss 0.01
Cross-site scripting (XSS) vulnerability in demos/demo.mysqli.php in getID3 1.X and v2.0.0-beta allows remote attackers to inject arbitrary web script or HTML via the showtagfiles parameter.
- CVE-2021-25963Sep 30, 2021risk 0.00cvss —epss 0.01
In Shuup, versions 1.6.0 through 2.10.8 are vulnerable to reflected Cross-Site Scripting (XSS) that allows execution of arbitrary javascript code on a victim browser. This vulnerability exists due to the error page contents not escaped.
- CVE-2020-20129Sep 29, 2021risk 0.00cvss —epss 0.01
LaraCMS v1.0.1 contains a stored cross-site scripting (XSS) vulnerability which allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the content editor.
- CVE-2021-25959Sep 29, 2021risk 0.00cvss —epss 0.01
In OpenCRX, versions v4.0.0 through v5.1.0 are vulnerable to reflected Cross-site Scripting (XSS), due to unsanitized parameters in the password reset functionality. This allows execution of external javascript files on any user of the openCRX instance.
- CVE-2020-20696Sep 27, 2021risk 0.00cvss —epss 0.00
A cross-site scripting (XSS) vulnerability in /admin/content/post of GilaCMS v1.11.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the Tags field.
- CVE-2020-20695Sep 27, 2021risk 0.00cvss —epss 0.01
A stored cross-site scripting (XSS) vulnerability in GilaCMS v1.11.4 allows attackers to execute arbitrary web scripts or HTML via a crafted SVG file.