VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (46,607)

page 89 of 2,331
  • CVE-2019-19223HigMar 4, 2020
    risk 0.49cvss 7.5epss 0.04

    A Broken Access Control vulnerability in the D-Link DSL-2680 web administration interface (Firmware EU_1.03) allows an attacker to reboot the router by submitting a reboot.html GET request without being authenticated on the admin interface.

  • CVE-2020-5398HigJan 17, 2020
    risk 0.49cvss 7.5epss 0.88

    In Spring Framework, versions 5.2.x prior to 5.2.3, versions 5.1.x prior to 5.1.13, and versions 5.0.x prior to 5.0.16, an application is vulnerable to a reflected file download (RFD) attack when it sets a "Content-Disposition" header in the response where the filename attribute…

  • CVE-2020-1607HigJan 15, 2020
    risk 0.49cvss 7.5epss 0.01

    Insufficient Cross-Site Scripting (XSS) protection in J-Web may potentially allow a remote attacker to inject web script or HTML, hijack the target user's J-Web session and perform administrative actions on the Junos device as the targeted user. This issue affects Juniper…

  • CVE-2019-20209HigJan 13, 2020
    risk 0.49cvss 7.5epss 0.03

    The CTHthemes CityBook before 2.3.4, TownHub before 1.0.6, and EasyBook before 1.2.2 themes for WordPress allow nsecure Direct Object Reference (IDOR) via wp-admin/admin-ajax.php to delete any page/post/listing.

  • CVE-2019-17214HigOct 6, 2019
    risk 0.49cvss 7.5epss 0.02

    The WebARX plugin 1.3.0 for WordPress allows firewall bypass by appending &cc=1 to a URI.

  • CVE-2019-10092MedSep 26, 2019
    risk 0.49cvss 6.1epss 0.81

    In Apache HTTP Server 2.4.0-2.4.39, a limited cross-site scripting issue was reported affecting the mod_proxy error page. An attacker could cause the link on the error page to be malformed and instead point to a page of their choice. This would only be exploitable where a server…

  • CVE-2019-14470MedSep 4, 2019
    risk 0.49cvss 6.1epss 0.83

    cosenary Instagram-PHP-API (aka Instagram PHP API V2), as used in the UserPro plugin through 4.9.32 for WordPress, has XSS via the example/success.php error_description parameter.

  • CVE-2019-15816HigAug 30, 2019
    risk 0.49cvss 7.5epss 0.02

    The wp-private-content-plus plugin before 2.0 for WordPress has no protection against option changes via save_settings_page and other save_ functions.

  • CVE-2019-6969HigAug 2, 2019
    risk 0.49cvss 7.5epss 0.03

    The web interface of the D-Link DVA-5592 20180823 is vulnerable to an authentication bypass that allows an unauthenticated user to have access to sensitive information such as the Wi-Fi password and the phone number (if VoIP is in use).

  • CVE-2019-0319HigJul 10, 2019
    risk 0.49cvss 7.5epss 0.03

    The SAP Gateway, versions 7.5, 7.51, 7.52 and 7.53, allows an attacker to inject content which is displayed in the form of an error message. An attacker could thus mislead a user to believe this information is from the legitimate service when it's not.

  • CVE-2018-16861HigDec 7, 2018
    risk 0.49cvss 7.6epss 0.01

    A cross-site scripting (XSS) flaw was found in the foreman component of satellite. An attacker with privilege to create entries using the Hosts, Monitor, Infrastructure, or Administer Menus is able to execute a XSS attacks against other users, possibly leading to malicious code…

  • CVE-2018-12319HigDec 4, 2018
    risk 0.49cvss 7.5epss 0.01

    Denial-of-service in the login page of ASUSTOR ADM 3.1.1 allows attackers to prevent users from signing in by placing malformed text in the title.

  • CVE-2018-18807HigNov 26, 2018
    risk 0.49cvss 7.6epss 0.01

    The web application of the TIBCO Statistica component of TIBCO Software Inc.'s TIBCO Statistica Server contains vulnerabilities which may allow an authenticated user to perform cross-site scripting (XSS) attacks. Affected releases are TIBCO Software Inc.'s TIBCO Statistica…

  • CVE-2017-7425HigNov 6, 2017
    risk 0.49cvss 7.6epss 0.01

    Multiple potential reflected XSS issues exist in NetIQ iManager versions before 2.7.7 Patch 10 HF2 and 3.0.3.2.

  • CVE-2017-9062HigMay 18, 2017
    risk 0.49cvss 8.6epss 0.02

    In WordPress before 4.7.5, there is improper handling of post meta data values in the XML-RPC API.

  • CVE-2016-6641HigSep 18, 2016
    risk 0.49cvss 7.6epss 0.01

    Cross-site scripting (XSS) vulnerability in EMC ViPR SRM before 3.7.2 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2026-63360HigAug 26, 2026
    risk 0.48cvss epss 0.00

    LimeSurvey Community Edition 7.0.5+260623 contains an authenticated reflected Cross-Site Scripting vulnerability in the user activation confirmation endpoint. The action query parameter is copied into the response and inserted into a hidden input attribute without HTML…

  • CVE-2026-54606HigAug 26, 2026
    risk 0.48cvss epss 0.00

    SunEditor is a lightweight and powerful WYSIWYG editor in vanilla JavaScript with no dependencies. Prior to 3.1.4, the SunEditor Embed plugin in src/plugins/modal/embed.js parses attacker-controlled raw embed HTML with DOMParser and processes the resulting DOM nodes. When an…

  • CVE-2026-64851HigAug 19, 2026
    risk 0.48cvss epss 0.00

    Grav Shortcode Core Plugin allows for the development shortcode plugins that utilize the common format utilized by WordPress and BBCode. Prior to 6.2.2, Grav Shortcode Core passes shortcode syntax through Security::detectXss() because it contains no literal less-than character,…

  • CVE-2026-63361HigAug 14, 2026
    risk 0.48cvss epss 0.00

    LimeSurvey Community Edition 7.0.5 contains an authenticated reflected cross-site scripting vulnerability in the HTML editor popup endpoint. The text and name query parameters are passed through a blacklist sanitizer and then rendered without context-appropriate output encoding.