VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (23,306)

page 888 of 1,166
  • CVE-2021-32768Aug 10, 2021
    risk 0.00cvss epss 0.01

    TYPO3 is an open source PHP based web content management system released under the GNU GPL. In affected versions failing to properly parse, sanitize and encode malicious rich-text content, the content rendering process in the website frontend is vulnerable to cross-site…

  • CVE-2021-32798Aug 9, 2021
    risk 0.00cvss epss 0.02

    The Jupyter notebook is a web-based notebook environment for interactive computing. In affected versions untrusted notebook can execute code on load. Jupyter Notebook uses a deprecated version of Google Caja to sanitize user inputs. A public Caja bypass can be used to trigger an…

  • CVE-2021-32797Aug 9, 2021
    risk 0.00cvss epss 0.03

    JupyterLab is a user interface for Project Jupyter which will eventually replace the classic Jupyter Notebook. In affected versions untrusted notebook can execute code on load. In particular JupyterLab doesn’t sanitize the action attribute of html ``. Using this it is…

  • CVE-2021-37634Aug 9, 2021
    risk 0.00cvss epss 0.01

    Leafkit is a templating language with Swift-inspired syntax. Versions prior to 1.3.0 are susceptible to Cross-site Scripting (XSS) attacks. This affects anyone passing unsanitised data to Leaf's variable tags. Before this fix, Leaf would not escape any strings passed to tags as…

  • CVE-2021-38186Aug 8, 2021
    risk 0.00cvss epss 0.01

    An issue was discovered in the comrak crate before 0.10.1 for Rust. It mishandles & characters, leading to XSS via &# HTML entities.

  • CVE-2021-38193Aug 8, 2021
    risk 0.00cvss epss 0.01

    An issue was discovered in the ammonia crate before 3.1.0 for Rust. XSS can occur because the parsing differences for HTML, SVG, and MathML are mishandled, a similar issue to CVE-2020-26870.

  • CVE-2020-22330Aug 6, 2021
    risk 0.00cvss epss 0.01

    Cross-Site Scripting (XSS) vulnerability in Subrion 4.2.1 via the title when adding a page.

  • CVE-2020-22392Aug 5, 2021
    risk 0.00cvss epss 0.01

    Cross Site Scripting (XSS) vulnerability exists in Subrion CMS 4.2.2 when adding a blog and then editing an image file.

  • CVE-2021-35463Aug 4, 2021
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in the Frontend Taglib module in Liferay Portal 7.4.0 allows remote attackers to inject arbitrary web script or HTML into the management toolbar search via the `keywords` parameter.

  • CVE-2021-33337Aug 4, 2021
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in the Document Library module's add document menu in Liferay Portal 7.3.0 through 7.3.4, and Liferay DXP 7.1 before fix pack 20, and 7.2 before fix pack 9, allows remote attackers to inject arbitrary web script or HTML via the…

  • CVE-2021-33336Aug 4, 2021
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in the Journal module's add article menu in Liferay Portal 7.3.0 through 7.3.3, and Liferay DXP 7.1 fix pack 18, and 7.2 fix pack 5 through 7, allows remote attackers to inject arbitrary web script or HTML via the…

  • CVE-2021-33339Aug 4, 2021
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in the Fragment module in Liferay Portal 7.2.1 through 7.3.4, and Liferay DXP 7.2 before fix pack 9 allows remote attackers to inject arbitrary web script or HTML via the _com_liferay_site_admin_web_portlet_SiteAdminPortlet_name parameter.

  • CVE-2021-33332Aug 3, 2021
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in the Portlet Configuration module in Liferay Portal 7.1.0 through 7.3.2, and Liferay DXP 7.1 before fix pack 19, and 7.2 before fix pack 7, allows remote attackers to inject arbitrary web script or HTML via the…

  • CVE-2021-33328Aug 3, 2021
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in the Asset module's edit vocabulary page in Liferay Portal 7.0.0 through 7.3.4, and Liferay DXP 7.0 before fix pack 96, 7.1 before fix pack 20, and 7.2 before fix pack 9, allows remote attackers to inject arbitrary web script or HTML…

  • CVE-2021-33326Aug 3, 2021
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in the Frontend JS module in Liferay Portal 7.3.4 and earlier, and Liferay DXP 7.0 before fix pack 96, 7.1 before fix pack 20 and 7.2 before fix pack 9, allows remote attackers to inject arbitrary web script or HTML via the title of a…

  • CVE-2021-37916Aug 2, 2021
    risk 0.00cvss epss 0.01

    Joplin before 2.0.9 allows XSS via button and form in the note body.

  • CVE-2020-22765Jul 29, 2021
    risk 0.00cvss epss 0.01

    Cross Site Scripting (XSS) vulnerability in NukeViet cms 4.4.0 via the editor in the News module.

  • CVE-2021-23416Jul 28, 2021
    risk 0.00cvss epss 0.01

    This affects all versions of package curly-bracket-parser. When used as a template library, it does not properly sanitize the user input.

  • CVE-2021-23414Jul 28, 2021
    risk 0.00cvss epss 0.03

    This affects the package video.js before 7.14.3. The src attribute of track tag allows to bypass HTML escaping and execute arbitrary code.

  • CVE-2020-23234Jul 26, 2021
    risk 0.00cvss epss 0.01

    Cross Site Scripting (XSS) vulnerabiity exists in LavaLite CMS 5.8.0 via the Menu Blocks feature, which can be bypassed by using HTML event handlers, such as "ontoggle,".