VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (23,306)

page 887 of 1,166
  • CVE-2021-27910Aug 30, 2021
    risk 0.00cvss epss 0.01

    Insufficient sanitization / filtering allows for arbitrary JavaScript Injection in Mautic using the bounce management callback function. The values submitted in the "error" and "error_related_to" parameters of the POST request of the bounce management callback will be…

  • CVE-2020-19002Aug 27, 2021
    risk 0.00cvss epss 0.01

    Cross Site Scripting (XSS) in Mezzanine v4.3.1 allows remote attackers to execute arbitrary code via the 'Description' field of the component 'admin/blog/blogpost/add/'. This issue is different than CVE-2018-16632.

  • CVE-2020-19000Aug 27, 2021
    risk 0.00cvss epss 0.01

    Cross Site Scripting (XSS) in Simiki v1.6.2.1 and prior allows remote attackers to execute arbitrary code via line 54 of the component 'simiki/blob/master/simiki/generators.py'.

  • CVE-2020-19709Aug 26, 2021
    risk 0.00cvss epss 0.01

    Insufficient filtering of the tag parameters in feehicms 0.1.3 allows attackers to execute arbitrary web or HTML via a crafted payload.

  • CVE-2021-39136Aug 25, 2021
    risk 0.00cvss epss 0.01

    baserCMS is an open source content management system with a focus on Japanese language support. In affected versions there is a cross-site scripting vulnerability in the file upload function of the management system of baserCMS. Users are advised to update as soon as possible.…

  • CVE-2021-39286Aug 18, 2021
    risk 0.00cvss epss 0.01

    Webrecorder pywb before 2.6.0 allows XSS because it does not ensure that Jinja2 templates are autoescaped.

  • CVE-2021-37710Aug 16, 2021
    risk 0.00cvss epss 0.01

    Shopware is an open source eCommerce platform. Versions prior to 6.4.3.1 contain a Cross-Site Scripting vulnerability via SVG media files. Version 6.4.3.1 contains a patch. As workarounds for older versions of 6.1, 6.2, and 6.3, corresponding security measures are also available…

  • CVE-2021-32827Aug 16, 2021
    risk 0.00cvss epss 0.02

    MockServer is open source software which enables easy mocking of any system you integrate with via HTTP or HTTPS. An attacker that can trick a victim into visiting a malicious site while running MockServer locally, will be able to run arbitrary code on the MockServer machine.…

  • CVE-2020-18702Aug 16, 2021
    risk 0.00cvss epss 0.01

    Cross Site Scripting (XSS) in Quokka v0.4.0 allows remote attackers to execute arbitrary code via the 'Username' parameter in the component 'quokka/admin/actions.py'.

  • CVE-2020-18699Aug 16, 2021
    risk 0.00cvss epss 0.01

    Cross Site Scripting (XSS) in Lin-CMS-Flask v0.1.1 allows remote attackers to execute arbitrary code by entering scripts in the the 'Username' parameter of the in component 'app/api/cms/user.py'.

  • CVE-2021-38713Aug 16, 2021
    risk 0.00cvss epss 0.01

    imgURL 2.31 allows XSS via an X-Forwarded-For HTTP header.

  • CVE-2021-25955Aug 15, 2021
    risk 0.00cvss epss 0.01

    In “Dolibarr ERP CRM”, WYSIWYG Editor module, v2.8.1 to v13.0.2 are affected by a stored XSS vulnerability that allows low privileged application users to store malicious scripts in the “Private Note” field at “/adherents/note.php?id=1” endpoint. These scripts are…

  • CVE-2021-36787Aug 13, 2021
    risk 0.00cvss epss 0.01

    The femanager extension before 5.5.1 and 6.x before 6.3.1 for TYPO3 allows XSS via a crafted SVG document.

  • CVE-2021-36785Aug 13, 2021
    risk 0.00cvss epss 0.01

    The miniorange_saml (aka Miniorange Saml) extension before 1.4.3 for TYPO3 allows XSS.

  • CVE-2021-36788Aug 13, 2021
    risk 0.00cvss epss 0.00

    The yoast_seo (aka Yoast SEO) extension before 7.2.3 for TYPO3 allows XSS.

  • CVE-2021-37695Aug 12, 2021
    risk 0.00cvss epss 0.01

    ckeditor is an open source WYSIWYG HTML editor with rich content support. A potential vulnerability has been discovered in CKEditor 4 [Fake Objects](https://ckeditor.com/cke4/addon/fakeobjects) package. The vulnerability allowed to inject malformed Fake Objects HTML, which could…

  • CVE-2021-37700Aug 12, 2021
    risk 0.00cvss epss 0.02

    @github/paste-markdown is an npm package for pasting markdown objects. A self Cross-Site Scripting vulnerability exists in the @github/paste-markdown before version 0.3.4. If the clipboard data contains the string ``, a **div** is dynamically created, and the clipboard…

  • CVE-2021-32809Aug 12, 2021
    risk 0.00cvss epss 0.01

    ckeditor is an open source WYSIWYG HTML editor with rich content support. A potential vulnerability has been discovered in CKEditor 4 [Clipboard](https://ckeditor.com/cke4/addon/clipboard) package. The vulnerability allowed to abuse paste functionality using malformed HTML,…

  • CVE-2021-32808Aug 12, 2021
    risk 0.00cvss epss 0.01

    ckeditor is an open source WYSIWYG HTML editor with rich content support. A vulnerability has been discovered in the clipboard Widget plugin if used alongside the undo feature. The vulnerability allows a user to abuse undo functionality using malformed widget HTML, which could…

  • CVE-2021-35955Aug 12, 2021
    risk 0.00cvss epss 0.01

    Contao >=4.0.0 allows backend XSS via HTML attributes to an HTML field. Fixed in 4.4.56, 4.9.18, 4.11.7.