VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (23,306)

page 895 of 1,166
  • CVE-2021-27938Mar 16, 2021
    risk 0.00cvss epss 0.01

    A vulnerability has been identified in the Silverstripe CMS 3 and 4 version of the symbiote/silverstripe-queuedjobs module. A Cross Site Scripting vulnerability allows an attacker to inject an arbitrary payload in the CreateQueuedJobTask dev task via a specially crafted URL.

  • CVE-2021-20280Mar 15, 2021
    risk 0.00cvss epss 0.01

    Text-based feedback answers required additional sanitizing to prevent stored XSS and blind SSRF risks in moodle before 3.10.2, 3.9.5, 3.8.8, 3.5.17.

  • CVE-2021-20279Mar 15, 2021
    risk 0.00cvss epss 0.01

    The ID number user profile field required additional sanitizing to prevent a stored XSS risk in moodle before 3.10.2, 3.9.5, 3.8.8, 3.5.17.

  • CVE-2021-28161Mar 12, 2021
    risk 0.00cvss epss 0.01

    In Eclipse Theia versions up to and including 1.8.0, in the debug console there is no HTML escaping, so arbitrary Javascript code can be injected.

  • CVE-2021-28088Mar 11, 2021
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) in modules/content/admin/content.php in ImpressCMS profile 1.4.2 allows remote attackers to inject arbitrary web script or HTML parameters through the "Display Name" field.

  • CVE-2020-13959Mar 10, 2021
    risk 0.00cvss epss 0.06

    The default error page for VelocityView in Apache Velocity Tools prior to 3.1 reflects back the vm file that was entered as part of the URL. An attacker can set an XSS payload file as this vm file in the URL which results in this payload being executed. XSS vulnerabilities allow…

  • CVE-2021-3377Mar 5, 2021
    risk 0.00cvss epss 0.08

    The npm package ansi_up converts ANSI escape codes into HTML. In ansi_up v4, ANSI escape codes can be used to create HTML hyperlinks. Due to insufficient URL sanitization, this feature is affected by a cross-site scripting (XSS) vulnerability. This issue is fixed in v5.0.0.

  • CVE-2021-27907Mar 5, 2021
    risk 0.00cvss epss 0.86

    Apache Superset up to and including 0.38.0 allowed the creation of a Markdown component on a Dashboard page for describing chart's related information. Abusing this functionality, a malicious user could inject javascript code executing unwanted action in the context of the…

  • CVE-2021-25313Mar 5, 2021
    risk 0.00cvss epss 0.01

    A Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rancher allows remote attackers to execute JavaScript via malicious links. This issue affects: SUSE Rancher Rancher versions prior to 2.5.6.

  • CVE-2021-27940Mar 3, 2021
    risk 0.00cvss epss 0.01

    resources/public/js/orchestrator.js in openark orchestrator before 3.2.4 allows XSS via the orchestrator-msg parameter.

  • CVE-2021-23347Mar 3, 2021
    risk 0.00cvss epss 0.01

    The package github.com/argoproj/argo-cd/cmd before 1.7.13, from 1.8.0 and before 1.8.6 are vulnerable to Cross-site Scripting (XSS) the SSO provider connected to Argo CD would have to send back a malicious error message containing JavaScript to the user.

  • CVE-2020-1936Mar 2, 2021
    risk 0.00cvss epss 0.03

    A cross-site scripting issue was found in Apache Ambari Views. This was addressed in Apache Ambari 2.7.4.

  • CVE-2021-27671Feb 25, 2021
    risk 0.00cvss epss 0.01

    An issue was discovered in the comrak crate before 0.9.1 for Rust. XSS can occur because the protection mechanism for data: and javascript: URIs is case-sensitive, allowing (for example) Data: to be used in an attack.

  • CVE-2020-27224Feb 24, 2021
    risk 0.00cvss epss 0.02

    In Eclipse Theia versions up to and including 1.2.0, the Markdown Preview (@theia/preview), can be exploited to execute arbitrary code.

  • CVE-2021-21622Feb 24, 2021
    risk 0.00cvss epss 0.09

    Jenkins Artifact Repository Parameter Plugin 1.0.0 and earlier does not escape parameter names and descriptions, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Job/Configure permission.

  • CVE-2021-21618Feb 24, 2021
    risk 0.00cvss epss 0.82

    Jenkins Repository Connector Plugin 2.0.2 and earlier does not escape parameter names and descriptions for past builds, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.

  • CVE-2021-21616Feb 24, 2021
    risk 0.00cvss epss 0.79

    Jenkins Active Choices Plugin 2.5.2 and earlier does not escape reference parameter values, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Job/Configure permission.

  • CVE-2020-13697Feb 23, 2021
    risk 0.00cvss epss 0.01

    An issue was discovered in RouterNanoHTTPD.java in NanoHTTPD through 2.3.1. The GeneralHandler class implements a basic GET handler that prints debug information as an HTML page. Any web server that extends this class without implementing its own GET handler is vulnerable to…

  • CVE-2020-35571Feb 22, 2021
    risk 0.00cvss epss 0.01

    An issue was discovered in MantisBT through 2.24.3. In the helper_ensure_confirmed call in manage_custom_field_update.php, the custom field name is not sanitized. This may be problematic depending on CSP settings.

  • CVE-2021-26544Feb 20, 2021
    risk 0.00cvss epss 0.03

    Livy server version 0.7.0-incubating (only) is vulnerable to a cross site scripting issue in the session name. A malicious user could use this flaw to access logs and results of other users' sessions and run jobs with their privileges. This issue is fixed in Livy…