VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (23,306)

page 896 of 1,166
  • CVE-2021-23342Feb 19, 2021
    risk 0.00cvss epss 0.02

    This affects the package docsify before 4.12.0. It is possible to bypass the remediation done by CVE-2020-7680 and execute malicious JavaScript through the following methods 1) When parsing HTML from remote URLs, the HTML code on the main page is sanitized, but this sanitization…

  • CVE-2021-21028Feb 11, 2021
    risk 0.00cvss epss 0.04

    Acrobat Reader DC versions versions 2020.013.20074 (and earlier), 2020.001.30018 (and earlier) and 2017.011.30188 (and earlier) are affected by a Use After Free vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in…

  • CVE-2021-21029Feb 11, 2021
    risk 0.00cvss epss 0.85

    Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are affected by a Reflected Cross-site Scripting vulnerability via 'file' parameter. Successful exploitation could lead to arbitrary JavaScript execution in the victim's browser. Access to the…

  • CVE-2021-21023Feb 11, 2021
    risk 0.00cvss epss 0.02

    Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to a stored cross-site scripting vulnerability in the admin console. Successful exploitation could lead to arbitrary JavaScript execution in the victim's browser. Access to the…

  • CVE-2020-35125Feb 9, 2021
    risk 0.00cvss epss 0.03

    A cross-site scripting (XSS) vulnerability in the forms component of Mautic before 3.2.4 allows remote attackers to inject executable JavaScript via mautic[return] (a different attack method than CVE-2020-35124, but also related to the Referer concept).

  • CVE-2020-35572Feb 9, 2021
    risk 0.00cvss epss 0.02

    Adminer through 4.7.8 allows XSS via the history parameter to the default URI.

  • CVE-2021-23327Feb 9, 2021
    risk 0.00cvss epss 0.01

    The package apexcharts before 3.24.0 are vulnerable to Cross-site Scripting (XSS) via lack of sanitization of graph legend fields.

  • CVE-2020-13947Feb 8, 2021
    risk 0.00cvss epss 0.79

    An instance of a cross-site scripting vulnerability was identified to be present in the web based administration console on the message.jsp page of Apache ActiveMQ versions 5.15.12 through 5.16.0.

  • CVE-2021-26722Feb 5, 2021
    risk 0.00cvss epss 0.03

    LinkedIn Oncall through 1.4.0 allows reflected XSS via /query because of mishandling of the "No results found for" message in the search bar.

  • CVE-2021-21043Feb 2, 2021
    risk 0.00cvss epss 0.03

    ACS Commons version 4.9.2 (and earlier) suffers from a Reflected Cross-site Scripting (XSS) vulnerability in version-compare and page-compare due to invalid JCR characters that are not handled correctly. An attacker could potentially exploit this vulnerability to inject…

  • CVE-2021-20186Jan 28, 2021
    risk 0.00cvss epss 0.01

    It was found in Moodle before version 3.10.1, 3.9.4, 3.8.7 and 3.5.16 that if the TeX notation filter was enabled, additional sanitizing of TeX content was required to prevent the risk of stored XSS.

  • CVE-2021-20183Jan 28, 2021
    risk 0.00cvss epss 0.01

    It was found in Moodle before version 3.10.1 that some search inputs were vulnerable to reflected XSS due to insufficient escaping of search queries.

  • CVE-2020-35124Jan 28, 2021
    risk 0.00cvss epss 0.02

    A cross-site scripting (XSS) vulnerability in the assets component of Mautic before 3.2.4 allows remote attackers to inject executable JavaScript through the Referer header of asset downloads.

  • CVE-2021-21283Jan 26, 2021
    risk 0.00cvss epss 0.01

    Flarum is an open source discussion platform for websites. The "Flarum Sticky" extension versions 0.1.0-beta.14 and 0.1.0-beta.15 has a cross-site scripting vulnerability. A change in release beta 14 of the Sticky extension caused the plain text content of the first post of a…

  • CVE-2020-28487Jan 22, 2021
    risk 0.00cvss epss 0.01

    This affects the package vis-timeline before 7.4.4. An attacker with the ability to control the items of a Timeline element can inject additional script code into the generated application.

  • CVE-2021-3271Jan 22, 2021
    risk 0.00cvss epss 0.01

    PressBooks 5.17.3 contains a cross-site scripting (XSS). Stored XSS can be submitted via the Book Info's Long Description Body, and all actions to open or preview the books page will result in the triggering the stored XSS.

  • CVE-2020-36202Jan 22, 2021
    risk 0.00cvss epss 0.01

    An issue was discovered in the async-h1 crate before 2.3.0 for Rust. Request smuggling can occur when used behind a reverse proxy.

  • CVE-2020-21146Jan 21, 2021
    risk 0.00cvss epss 0.01

    Feehi CMS 2.0.8 is affected by a cross-site scripting (XSS) vulnerability. When the user name is inserted as JavaScript code, browsing the post will trigger the XSS.

  • CVE-2021-3137Jan 20, 2021
    risk 0.00cvss epss 0.01

    XWiki 12.10.2 allows XSS via an SVG document to the upload feature of the comment section.

  • CVE-2020-27851Jan 20, 2021
    risk 0.00cvss epss 0.01

    Multiple stored HTML injection vulnerabilities in the "poll" and "quiz" features in an additional paid add-on of Rocketgenius Gravity Forms before 2.4.21 allows remote attackers to inject arbitrary HTML code via poll or quiz answers. This code is interpreted by users in a…