VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (23,305)

page 899 of 1,166
  • CVE-2020-10776Nov 17, 2020
    risk 0.00cvss epss 0.01

    A flaw was found in Keycloak before version 12.0.0, where it is possible to add unsafe schemes for the redirect_uri parameter. This flaw allows an attacker to perform a Cross-site scripting attack.

  • CVE-2020-26225Nov 16, 2020
    risk 0.00cvss epss 0.01

    In PrestaShop Product Comments before version 4.2.0, an attacker could inject malicious web code into the users' web browsers by creating a malicious link. The problem was introduced in version 4.0.0 and is fixed in 4.2.0

  • CVE-2020-7773Nov 16, 2020
    risk 0.00cvss epss 0.01

    This affects the package markdown-it-highlightjs before 3.3.1. It is possible insert malicious JavaScript as a value of lang in the markdown-it-highlightjs Inline code highlighting feature. const markdownItHighlightjs = require("markdown-it-highlightjs"); const md =…

  • CVE-2020-27193Nov 12, 2020
    risk 0.00cvss epss 0.02

    A cross-site scripting (XSS) vulnerability in the Color Dialog plugin for CKEditor 4.15.0 allows remote attackers to run arbitrary web script after persuading a user to copy and paste crafted HTML code into one of editor inputs.

  • CVE-2020-15275Nov 11, 2020
    risk 0.00cvss epss 0.02

    MoinMoin is a wiki engine. In MoinMoin before version 1.9.11, an attacker with write permissions can upload an SVG file that contains malicious javascript. This javascript will be executed in a user's browser when the user is viewing that SVG file on the wiki. Users are strongly…

  • CVE-2020-28364Nov 9, 2020
    risk 0.00cvss epss 0.01

    A stored cross-site scripting (XSS) vulnerability affects the Web UI in Locust before 1.3.2, if the installation violates the usage expectations by exposing this UI to outside users.

  • CVE-2020-28249Nov 6, 2020
    risk 0.00cvss epss 0.03

    Joplin 1.2.6 for Desktop allows XSS via a LINK element in a note.

  • CVE-2020-2316Nov 4, 2020
    risk 0.00cvss epss 0.01

    Jenkins Static Analysis Utilities Plugin 1.96 and earlier does not escape the annotation message in tooltips, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Job/Configure permission.

  • CVE-2020-2317Nov 4, 2020
    risk 0.00cvss epss 0.01

    Jenkins FindBugs Plugin 5.0.0 and earlier does not escape the annotation message in tooltips, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to provide report files to Jenkins FindBugs Plugin's post build step.

  • CVE-2020-26211Nov 3, 2020
    risk 0.00cvss epss 0.01

    In BookStack before version 0.30.4, a user with permissions to edit a page could insert JavaScript code through the use of `javascript:` URIs within a link or form which would run, within the context of the current page, when clicked or submitted. Additionally, a user with…

  • CVE-2020-15273Oct 30, 2020
    risk 0.00cvss epss 0.01

    baserCMS before version 4.4.1 is vulnerable to Cross-Site Scripting. The issue affects the following components: Edit feed settings, Edit widget area, Sub site new registration, New category registration. Arbitrary JavaScript may be executed by entering specific characters in…

  • CVE-2020-15276Oct 30, 2020
    risk 0.00cvss epss 0.01

    baserCMS before version 4.4.1 is vulnerable to Cross-Site Scripting. Arbitrary JavaScript may be executed by entering a crafted nickname in blog comments. The issue affects the blog comment component. It is fixed in version 4.4.1.

  • CVE-2020-24303Oct 28, 2020
    risk 0.00cvss epss 0.02

    Grafana before 7.1.0-beta 1 allows XSS via a query alias for the ElasticSearch datasource.

  • CVE-2020-27388Oct 23, 2020
    risk 0.00cvss epss 0.01

    Multiple Stored Cross Site Scripting (XSS) vulnerabilities exist in the YOURLS Admin Panel, Versions 1.5 - 1.7.10. An authenticated user must modify a PHP plugin with a malicious payload and upload it, resulting in multiple stored XSS issues.

  • CVE-2020-27666Oct 22, 2020
    risk 0.00cvss epss 0.01

    Strapi before 3.2.5 has stored XSS in the wysiwyg editor's preview feature.

  • CVE-2020-7750Oct 21, 2020
    risk 0.00cvss epss 0.06

    This affects the package scratch-svg-renderer before 0.2.0-prerelease.20201019174008. The loadString function does not escape SVG properly, which can be used to inject arbitrary elements into the DOM via the _transformMeasurements function.

  • CVE-2020-7749Oct 20, 2020
    risk 0.00cvss epss 0.02

    This affects all versions of package osm-static-maps. User input given to the package is passed directly to a template without escaping ({{{ ... }}}). As such, it is possible for an attacker to inject arbitrary HTML/JS code and depending on the context. It will be outputted as…

  • CVE-2020-7747Oct 20, 2020
    risk 0.00cvss epss 0.01

    This affects all versions of package lightning-server. It is possible to inject malicious JavaScript code as part of a session controller.

  • CVE-2020-15245Oct 19, 2020
    risk 0.00cvss epss 0.01

    In Sylius before versions 1.6.9, 1.7.9 and 1.8.3, the user may register in a shop by email mail@example.com, verify it, change it to the mail another@domain.com and stay verified and enabled. This may lead to having accounts addressed to totally different emails, that were…

  • CVE-2020-15263Oct 19, 2020
    risk 0.00cvss epss 0.01

    In platform before version 9.4.4, inline attributes are not properly escaped. If the data that came from users was not escaped, then an XSS vulnerability is possible. The issue was introduced in 9.0.0 and fixed in 9.4.4.