CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Description
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85
CVEs mapped to this weakness (23,306)
page 887 of 1,166| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-27910 | 0.00 | — | 0.01 | Aug 30, 2021 | Insufficient sanitization / filtering allows for arbitrary JavaScript Injection in Mautic using the bounce management callback function. The values submitted in the "error" and "error_related_to" parameters of the POST request of the bounce management callback will be… | |||
| CVE-2020-19002 | — | 0.00 | — | 0.01 | Aug 27, 2021 | Cross Site Scripting (XSS) in Mezzanine v4.3.1 allows remote attackers to execute arbitrary code via the 'Description' field of the component 'admin/blog/blogpost/add/'. This issue is different than CVE-2018-16632. | ||
| CVE-2020-19000 | — | 0.00 | — | 0.01 | Aug 27, 2021 | Cross Site Scripting (XSS) in Simiki v1.6.2.1 and prior allows remote attackers to execute arbitrary code via line 54 of the component 'simiki/blob/master/simiki/generators.py'. | ||
| CVE-2020-19709 | — | 0.00 | — | 0.01 | Aug 26, 2021 | Insufficient filtering of the tag parameters in feehicms 0.1.3 allows attackers to execute arbitrary web or HTML via a crafted payload. | ||
| CVE-2021-39136 | 0.00 | — | 0.01 | Aug 25, 2021 | baserCMS is an open source content management system with a focus on Japanese language support. In affected versions there is a cross-site scripting vulnerability in the file upload function of the management system of baserCMS. Users are advised to update as soon as possible.… | |||
| CVE-2021-39286 | — | 0.00 | — | 0.01 | Aug 18, 2021 | Webrecorder pywb before 2.6.0 allows XSS because it does not ensure that Jinja2 templates are autoescaped. | ||
| CVE-2021-37710 | — | 0.00 | — | 0.01 | Aug 16, 2021 | Shopware is an open source eCommerce platform. Versions prior to 6.4.3.1 contain a Cross-Site Scripting vulnerability via SVG media files. Version 6.4.3.1 contains a patch. As workarounds for older versions of 6.1, 6.2, and 6.3, corresponding security measures are also available… | ||
| CVE-2021-32827 | 0.00 | — | 0.02 | Aug 16, 2021 | MockServer is open source software which enables easy mocking of any system you integrate with via HTTP or HTTPS. An attacker that can trick a victim into visiting a malicious site while running MockServer locally, will be able to run arbitrary code on the MockServer machine.… | |||
| CVE-2020-18702 | — | 0.00 | — | 0.01 | Aug 16, 2021 | Cross Site Scripting (XSS) in Quokka v0.4.0 allows remote attackers to execute arbitrary code via the 'Username' parameter in the component 'quokka/admin/actions.py'. | ||
| CVE-2020-18699 | — | 0.00 | — | 0.01 | Aug 16, 2021 | Cross Site Scripting (XSS) in Lin-CMS-Flask v0.1.1 allows remote attackers to execute arbitrary code by entering scripts in the the 'Username' parameter of the in component 'app/api/cms/user.py'. | ||
| CVE-2021-38713 | — | 0.00 | — | 0.01 | Aug 16, 2021 | imgURL 2.31 allows XSS via an X-Forwarded-For HTTP header. | ||
| CVE-2021-25955 | 0.00 | — | 0.01 | Aug 15, 2021 | In “Dolibarr ERP CRM”, WYSIWYG Editor module, v2.8.1 to v13.0.2 are affected by a stored XSS vulnerability that allows low privileged application users to store malicious scripts in the “Private Note” field at “/adherents/note.php?id=1” endpoint. These scripts are… | |||
| CVE-2021-36787 | — | 0.00 | — | 0.01 | Aug 13, 2021 | The femanager extension before 5.5.1 and 6.x before 6.3.1 for TYPO3 allows XSS via a crafted SVG document. | ||
| CVE-2021-36785 | — | 0.00 | — | 0.01 | Aug 13, 2021 | The miniorange_saml (aka Miniorange Saml) extension before 1.4.3 for TYPO3 allows XSS. | ||
| CVE-2021-36788 | — | 0.00 | — | 0.00 | Aug 13, 2021 | The yoast_seo (aka Yoast SEO) extension before 7.2.3 for TYPO3 allows XSS. | ||
| CVE-2021-37695 | 0.00 | — | 0.01 | Aug 12, 2021 | ckeditor is an open source WYSIWYG HTML editor with rich content support. A potential vulnerability has been discovered in CKEditor 4 [Fake Objects](https://ckeditor.com/cke4/addon/fakeobjects) package. The vulnerability allowed to inject malformed Fake Objects HTML, which could… | |||
| CVE-2021-37700 | 0.00 | — | 0.02 | Aug 12, 2021 | @github/paste-markdown is an npm package for pasting markdown objects. A self Cross-Site Scripting vulnerability exists in the @github/paste-markdown before version 0.3.4. If the clipboard data contains the string ``, a **div** is dynamically created, and the clipboard… | |||
| CVE-2021-32809 | 0.00 | — | 0.01 | Aug 12, 2021 | ckeditor is an open source WYSIWYG HTML editor with rich content support. A potential vulnerability has been discovered in CKEditor 4 [Clipboard](https://ckeditor.com/cke4/addon/clipboard) package. The vulnerability allowed to abuse paste functionality using malformed HTML,… | |||
| CVE-2021-32808 | 0.00 | — | 0.01 | Aug 12, 2021 | ckeditor is an open source WYSIWYG HTML editor with rich content support. A vulnerability has been discovered in the clipboard Widget plugin if used alongside the undo feature. The vulnerability allows a user to abuse undo functionality using malformed widget HTML, which could… | |||
| CVE-2021-35955 | — | 0.00 | — | 0.01 | Aug 12, 2021 | Contao >=4.0.0 allows backend XSS via HTML attributes to an HTML field. Fixed in 4.4.56, 4.9.18, 4.11.7. |
- CVE-2021-27910Aug 30, 2021risk 0.00cvss —epss 0.01
Insufficient sanitization / filtering allows for arbitrary JavaScript Injection in Mautic using the bounce management callback function. The values submitted in the "error" and "error_related_to" parameters of the POST request of the bounce management callback will be…
- CVE-2020-19002Aug 27, 2021risk 0.00cvss —epss 0.01
Cross Site Scripting (XSS) in Mezzanine v4.3.1 allows remote attackers to execute arbitrary code via the 'Description' field of the component 'admin/blog/blogpost/add/'. This issue is different than CVE-2018-16632.
- CVE-2020-19000Aug 27, 2021risk 0.00cvss —epss 0.01
Cross Site Scripting (XSS) in Simiki v1.6.2.1 and prior allows remote attackers to execute arbitrary code via line 54 of the component 'simiki/blob/master/simiki/generators.py'.
- CVE-2020-19709Aug 26, 2021risk 0.00cvss —epss 0.01
Insufficient filtering of the tag parameters in feehicms 0.1.3 allows attackers to execute arbitrary web or HTML via a crafted payload.
- CVE-2021-39136Aug 25, 2021risk 0.00cvss —epss 0.01
baserCMS is an open source content management system with a focus on Japanese language support. In affected versions there is a cross-site scripting vulnerability in the file upload function of the management system of baserCMS. Users are advised to update as soon as possible.…
- CVE-2021-39286Aug 18, 2021risk 0.00cvss —epss 0.01
Webrecorder pywb before 2.6.0 allows XSS because it does not ensure that Jinja2 templates are autoescaped.
- CVE-2021-37710Aug 16, 2021risk 0.00cvss —epss 0.01
Shopware is an open source eCommerce platform. Versions prior to 6.4.3.1 contain a Cross-Site Scripting vulnerability via SVG media files. Version 6.4.3.1 contains a patch. As workarounds for older versions of 6.1, 6.2, and 6.3, corresponding security measures are also available…
- CVE-2021-32827Aug 16, 2021risk 0.00cvss —epss 0.02
MockServer is open source software which enables easy mocking of any system you integrate with via HTTP or HTTPS. An attacker that can trick a victim into visiting a malicious site while running MockServer locally, will be able to run arbitrary code on the MockServer machine.…
- CVE-2020-18702Aug 16, 2021risk 0.00cvss —epss 0.01
Cross Site Scripting (XSS) in Quokka v0.4.0 allows remote attackers to execute arbitrary code via the 'Username' parameter in the component 'quokka/admin/actions.py'.
- CVE-2020-18699Aug 16, 2021risk 0.00cvss —epss 0.01
Cross Site Scripting (XSS) in Lin-CMS-Flask v0.1.1 allows remote attackers to execute arbitrary code by entering scripts in the the 'Username' parameter of the in component 'app/api/cms/user.py'.
- CVE-2021-38713Aug 16, 2021risk 0.00cvss —epss 0.01
imgURL 2.31 allows XSS via an X-Forwarded-For HTTP header.
- CVE-2021-25955Aug 15, 2021risk 0.00cvss —epss 0.01
In “Dolibarr ERP CRM”, WYSIWYG Editor module, v2.8.1 to v13.0.2 are affected by a stored XSS vulnerability that allows low privileged application users to store malicious scripts in the “Private Note” field at “/adherents/note.php?id=1” endpoint. These scripts are…
- CVE-2021-36787Aug 13, 2021risk 0.00cvss —epss 0.01
The femanager extension before 5.5.1 and 6.x before 6.3.1 for TYPO3 allows XSS via a crafted SVG document.
- CVE-2021-36785Aug 13, 2021risk 0.00cvss —epss 0.01
The miniorange_saml (aka Miniorange Saml) extension before 1.4.3 for TYPO3 allows XSS.
- CVE-2021-36788Aug 13, 2021risk 0.00cvss —epss 0.00
The yoast_seo (aka Yoast SEO) extension before 7.2.3 for TYPO3 allows XSS.
- CVE-2021-37695Aug 12, 2021risk 0.00cvss —epss 0.01
ckeditor is an open source WYSIWYG HTML editor with rich content support. A potential vulnerability has been discovered in CKEditor 4 [Fake Objects](https://ckeditor.com/cke4/addon/fakeobjects) package. The vulnerability allowed to inject malformed Fake Objects HTML, which could…
- CVE-2021-37700Aug 12, 2021risk 0.00cvss —epss 0.02
@github/paste-markdown is an npm package for pasting markdown objects. A self Cross-Site Scripting vulnerability exists in the @github/paste-markdown before version 0.3.4. If the clipboard data contains the string ``, a **div** is dynamically created, and the clipboard…
- CVE-2021-32809Aug 12, 2021risk 0.00cvss —epss 0.01
ckeditor is an open source WYSIWYG HTML editor with rich content support. A potential vulnerability has been discovered in CKEditor 4 [Clipboard](https://ckeditor.com/cke4/addon/clipboard) package. The vulnerability allowed to abuse paste functionality using malformed HTML,…
- CVE-2021-32808Aug 12, 2021risk 0.00cvss —epss 0.01
ckeditor is an open source WYSIWYG HTML editor with rich content support. A vulnerability has been discovered in the clipboard Widget plugin if used alongside the undo feature. The vulnerability allows a user to abuse undo functionality using malformed widget HTML, which could…
- CVE-2021-35955Aug 12, 2021risk 0.00cvss —epss 0.01
Contao >=4.0.0 allows backend XSS via HTML attributes to an HTML field. Fixed in 4.4.56, 4.9.18, 4.11.7.