VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (23,306)

page 885 of 1,166
  • CVE-2021-25969Oct 20, 2021
    risk 0.00cvss epss 0.01

    In Camaleon CMS application, versions 0.0.1 to 2.6.0 are vulnerable to stored XSS, that allows an unauthenticated attacker to store malicious scripts in the comments section of the post. These scripts are executed in a victim’s browser when they open the page containing the…

  • CVE-2021-33988Oct 19, 2021
    risk 0.00cvss epss 0.01

    Cross Site Scripting (XSS). vulnerability exists in Microweber CMS 1.2.7 via the Login form, which could let a malicious user execute Javascript by Inserting code in the request form.

  • CVE-2011-1497Oct 19, 2021
    risk 0.00cvss epss 0.01

    A cross-site scripting vulnerability flaw was found in the auto_link function in Rails before version 3.0.6.

  • CVE-2021-3879Oct 19, 2021
    risk 0.00cvss epss 0.01

    snipe-it is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

  • CVE-2021-3863Oct 19, 2021
    risk 0.00cvss epss 0.01

    snipe-it is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

  • CVE-2021-32609Oct 18, 2021
    risk 0.00cvss epss 0.02

    Apache Superset up to and including 1.1 does not sanitize titles correctly on the Explore page. This allows an attacker with Explore access to save a chart with a malicious title, injecting html (including scripts) into the page.

  • CVE-2021-42227Oct 14, 2021
    risk 0.00cvss epss 0.01

    Cross SIte Scripting (XSS) vulnerability exists in KindEditor 4.1.x via a Google search inurl:/examples/uploadbutton.html and then the .html file on the website that uses this editor (the file suffix is allowed).

  • CVE-2021-41132Oct 14, 2021
    risk 0.00cvss epss 0.01

    OMERO.web provides a web based client and plugin infrastructure. In versions prior to 5.11.0, a variety of templates do not perform proper sanitization through HTML escaping. Due to the lack of sanitization and use of ``jQuery.html()``, there are a whole host of cross-site…

  • CVE-2021-42134Oct 11, 2021
    risk 0.00cvss epss 0.01

    The Unicorn framework before 0.36.1 for Django allows XSS via a component. NOTE: this issue exists because of an incomplete fix for CVE-2021-42053.

  • CVE-2021-42112Oct 8, 2021
    risk 0.00cvss epss 0.01

    The "File upload question" functionality in LimeSurvey 3.x-LTS through 3.27.18 allows XSS in assets/scripts/modaldialog.js and assets/scripts/uploader.js.

  • CVE-2021-23447Oct 7, 2021
    risk 0.00cvss epss 0.01

    This affects the package teddy before 0.5.9. A type confusion vulnerability can be used to bypass input sanitization when the model content is an array (instead of a string).

  • CVE-2021-36150Oct 7, 2021
    risk 0.00cvss epss 0.01

    SilverStripe Framework through 4.8.1 allows XSS.

  • CVE-2021-42053Oct 7, 2021
    risk 0.00cvss epss 0.03

    The Unicorn framework through 0.35.3 for Django allows XSS via component.name.

  • CVE-2021-21684Oct 6, 2021
    risk 0.00cvss epss 0.01

    Jenkins Git Plugin 4.8.2 and earlier does not escape the Git SHA-1 checksum parameters provided to commit notifications when displaying them in a build cause, resulting in a stored cross-site scripting (XSS) vulnerability.

  • CVE-2021-40926Oct 1, 2021
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in demos/demo.mysqli.php in getID3 1.X and v2.0.0-beta allows remote attackers to inject arbitrary web script or HTML via the showtagfiles parameter.

  • CVE-2021-25963Sep 30, 2021
    risk 0.00cvss epss 0.01

    In Shuup, versions 1.6.0 through 2.10.8 are vulnerable to reflected Cross-Site Scripting (XSS) that allows execution of arbitrary javascript code on a victim browser. This vulnerability exists due to the error page contents not escaped.

  • CVE-2020-20129Sep 29, 2021
    risk 0.00cvss epss 0.01

    LaraCMS v1.0.1 contains a stored cross-site scripting (XSS) vulnerability which allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the content editor.

  • CVE-2021-25959Sep 29, 2021
    risk 0.00cvss epss 0.01

    In OpenCRX, versions v4.0.0 through v5.1.0 are vulnerable to reflected Cross-site Scripting (XSS), due to unsanitized parameters in the password reset functionality. This allows execution of external javascript files on any user of the openCRX instance.

  • CVE-2020-20696Sep 27, 2021
    risk 0.00cvss epss 0.00

    A cross-site scripting (XSS) vulnerability in /admin/content/post of GilaCMS v1.11.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the Tags field.

  • CVE-2020-20695Sep 27, 2021
    risk 0.00cvss epss 0.01

    A stored cross-site scripting (XSS) vulnerability in GilaCMS v1.11.4 allows attackers to execute arbitrary web scripts or HTML via a crafted SVG file.